ODMR 2425-0006 EQRO Attachment F - Data Security and Privacy Terms.pdf

PDF 179 KB Posted

Attached to
External Quality Review Organization State and local contract opportunity
Solicitation number
SRC0000026668
Issued by
Ohio

About this file

This is a Data Security and Privacy Terms document (Attachment F) for ODMR 2425-0006 from the State of Ohio that outlines security and privacy requirements for contractors handling state information and data. The document establishes comprehensive requirements for data protection across all environments (cloud, on-premises, or hybrid) and applies to all work, services, system development, maintenance activities, and contractor access to state resources. The terms cover major and minor projects, upgrades, fixes, patches, and other software systems, as well as any authorized changes or amendments to the contract.

The document requires contractors to comply with State IT Security Policies and Standards, maintain NIST 800-53 security controls, obtain annual SSAE 18 SOC 1 Type 2 and SOC 2 Type 2 audits, and implement robust incident reporting procedures. Contractors must protect sensitive data including PII, HIPAA, FTI, CJI, and SSA data through encryption, access controls, and strict handling procedures. Security incidents must be reported within 24 hours, with detailed follow-up reports required within 5 business days. The contractor is responsible for all costs associated with security incidents, including notification and credit monitoring services if required. The document mandates multifactor authentication for systems containing sensitive data and requires all state data to be stored within the contiguous United States across a minimum of two geographically distant data centers.

View the file

Other files for this state and local contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ODMR 2425-0006

ATTACHMENT F

DATA SECURITY AND PRIVACY TERMS

These Data Security and Privacy Terms (“Terms”) describe the responsibilities for the Contractor relating to State information security and privacy standards and requirements for all proposed solutions, whether cloud, on-premises, or hybrid based. These Terms apply to all work and services across all environments, and State of Ohio (“State”) and Contractor locations (e.g., cloud (Software as a Service, Platform as a Service, or Infrastructure as a Service), on-premises, or hybrid) along with the computing elements that the Contractor will perform, provide, occupy, or utilize in performing the work, and any Contractor access to State resources in conjunction with the delivery of work.

The Contractor must comply with the State IT Security Policies and Standards and these Terms and must accept the security and privacy requirements outlined in these Terms in their entirety, as they apply to the services being provided to the State. The Contractor will be responsible for maintaining information security in any environments under the Contractor’s management in accordance with State IT Security Policies and Standards.

These Terms apply to the following:

A. Major and minor projects, upgrades, updates, fixes, patches, and other software and systems inclusive of all State elements or elements under the Contractor’s responsibility utilized by the State.

B. Any systems development, integration, operations, and maintenance activities performed by the Contractor.

C. Any authorized change orders, statements of work, renewals, or amendments to the Contract.

D. Contractor locations, equipment, and personnel that access State systems, networks, or State Data directly or indirectly.

E. Any Contractor personnel that have access to State Data.

These Terms are in addition to the Contract terms and conditions. In the event of a conflict between the Contract and these Terms, the most stringent standard will prevail.

Definitions

1. Contractor for purposes of these Terms, includes subcontractors or other personnel under the authority or control of the Contractor performing the work or providing the services under this Contract.

2. Personally Identifiable Information means information that can be used directly or in combination with other information to identify a particular individual. It includes:

A. A name, identifying number, symbol, or other identifier assigned to a person, B. Any information that describes anything about a person, C. Any information that indicates actions done by or to a person, D. Any information that indicates that a person possesses certain personal characteristics, E. The definitions of “personal information” in Revised Code chapters 1347.01, 1347.04 through

1347.99, and F. The various other definitions of “personal information” throughout the Ohio Revised Code.

3. Security Event has the meaning set forth in Section 7 of these Terms.

4. Security Incident has the meaning set forth in Section 7 of these Terms.

5. State Data means all data and information provided by, created by, created for, or related to the activities of the State and any information from, to, or related to all persons that conduct business or personal activities with the State, including, but not limited to Sensitive Data.

6. Sensitive Data means any type of data that presents a high or moderate degree of risk if released, disclosed, modified, or deleted without authorization. There is a high degree of risk when unauthorized

Data Security and Privacy Terms Page 2 of 8

Version 1.0 - 03/24 release or disclosure is contrary to a legally mandated confidentiality requirement. There may be a moderate risk and potentially a high risk in cases of information for which an agency has discretion under the law to release data, particularly when the release must be made only according to agency policy or procedure.

Sensitive Data includes, but is not limited to:

A. Personally Identifiable Information (PII);

B. Family Educational Rights and Privacy Act (20 U.S.C. § 1232g);

C. Federal Tax Information (FTI) under IRS Publication 1075 - Tax Information Security Guidelines for federal, state, and local agencies;

D. Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act

(45 CFR Part 160 and Subparts A, C, and E of Part 164); United States Code 42 U.S.C. 1320d through 1320d-9 (HIPAA); and Code of Federal Regulations for Public Health and Public Welfare:

42 C.F.R. 431.300, 431.302, 431.305, 431.306, 435.945, 45 C.F.R. 164.502(e) and 164.504(e);

E. Criminal Justice Information (CJI) under the Federal Bureau of Investigation’s Criminal Justice Information Services (CJIS) Security Policy available at https://le.fbi.gov/cjis-division/cjis-security-policy-resource-center;

F. Payment Card Industry Data Security Standards;

G. Social Security Administration (SSA) Data which is data received by the State from the Social

Security Administration in accordance with the current Computer Matching and Privacy Protection Act between the State of Ohio and the Social Security Administration; and

H. Other types of information not associated with an individual such as security and infrastructure records, trade secrets, and business bank account information.

7. State IT Security Policies and Standards means the policies and standards available at https://das.ohio.gov/technology-and-strategy/information-security-privacy/information-security-governance.

Requirements

1. The Contractor’s Responsibilities Generally

The Contractor is responsible for maintaining the security of information in accordance with the applicable security baseline of the current published version of the National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations,” (“NIST 800-53”) commensurate with the type of State Data involved in the Contract as communicated by the State. If the State is providing the network layer, the Contractor must be responsible for maintaining the security of the information in environment elements that are accessed, utilized, developed, or managed by the Contractor. In either scenario, the Contractor must implement information security policies, standards, and capabilities as set forth in the Contract, adhere to State IT Security Policies and Standards, and use procedures in a manner that does not diminish established State capabilities and standards. All work performed by the Contractor, all deliverables provided by the Contractor, and all environments utilized to perform the Contractor’s work must comply with State IT Security Policies and Standards. The Contractor’s information security and technology responsibilities with respect to the work and services the Contractor is providing to the State include the following, where applicable:

A. Support State IT security policies, standards and procedures development and maintenance activities. Assist in the implementation of associated security procedures with the State’s review and approval, including physical access requirements, User ID approval procedures, and a Security Incident action and response plan.

B. Support implementation and compliance monitoring as per State IT Security Policies and Standards.

https://le.fbi.gov/cjis-division/cjis-security-policy-resource-center https://le.fbi.gov/cjis-division/cjis-security-policy-resource-center https://das.ohio.gov/technology-and-strategy/information-security-privacy/information-security-governance https://das.ohio.gov/technology-and-strategy/information-security-privacy/information-security-governance

Data Security and Privacy Terms Page 3 of 8

C. Upon identification of a potential issue with maintaining an “as provided” State infrastructure element in accordance with a more stringent State level security policy, the Contractor must identify and communicate the nature of the issue to the State, and, if possible, outline potential remedies for consideration by the State.

2. Protection and Handling of State Data

Contractor shall maintain an Information Security Program (“ISP”) made up of policies, procedures, technical and organizational safeguards, and training designed to protect State Data against unauthorized loss, destruction, alteration, access, or disclosure. To protect State Data, the Contractor must use due diligence to ensure computer and telecommunications systems and services involved in storing, using, or transmitting State Data are secure and to protect State Data from unauthorized disclosure, modification, use or destruction. To accomplish this, the Contractor must adhere to the following requirements regarding State Data in addition to the confidentiality requirements in the Contract:

A. Assume all State Data is both confidential and critical for State operations.

B. Maintain, in confidence, State Data it may obtain, maintain, process, or otherwise receive from or through the State during, and pursuant to, the provisions of the Contract and these Terms.

C. Use and permit its employees, officers, agents, and subcontractors to use any State Data received from the State solely to perform its obligations under the Contract.

D. Not sell, rent, lease, disclose, or permit its employees, officers, agents, and sub-contractors to sell, rent, lease, or disclose, any such State Data to any third party, except as permitted under the Contract or required by applicable law, regulation, or court order.

E. Take all commercially reasonable steps to (a) protect the confidentiality of State Data received from the State and (b) establish and maintain physical, technical, and administrative safeguards to prevent unauthorized access by third parties to State Data received by the Contractor from the State.

F. Apply appropriate risk management techniques to balance the need for security measures against the sensitivity of State Data.

G. Ensure that internal security policies, plans, and procedures address the basic security elements of confidentiality, integrity, and availability of State Data, and periodically review and update these policies, plans, and procedures as needed.

All State Data at rest in systems supporting the Contractor’s services must reside within the contiguous United States with a minimum of two data center facilities at two different and distant geographic locations and be handled in accordance with the requirements of these Terms at all Contractor locations.

If the Contractor will be handling Sensitive Data, the State may require additional documentation such as the Contractor’s information security policies and procedures, contingency plans, or incident response plans, a Privacy Impact Assessment (PIA), FIPS-199 compliance documentation, a NIST-compliant System Security Plan (SSP), and Plans of Action and Milestones (POA&M) documentation.

3. Security Standards and Warranties

All solutions shall operate at the moderate level baseline as defined in the current published version of NIST 800-53, be consistent with Federal Information Security Management Act, 44 U.S.C. § 3551 et seq.

(“FISMA 2014”) requirements, and offer a customizable and extendable capability based on open-standards APIs that enable integration with third party applications.

Data Security and Privacy Terms Page 4 of 8

Contractor’s information security program protects State Data by aligning with NIST 800-53 to implement an industry security and privacy standard including, at a minimum:

A. Security and confidentiality of State Data.

B. Protection against anticipated threats or hazards to the security or integrity of State Data.

C. Protection against the unauthorized access to, disclosure of, or use of State Data.

D. Give access to State Data only to those individual employees, officers, agents, and sub-contractors who need to know such information in connection with the performance of the obligations under the Contract.

E. Cooperate with any attempt by the State to monitor compliance with the foregoing obligations as reasonably requested by the State.

F. Promptly destroy or return to the State, in a format designated by the State, all State Data received from or through the State upon completion of the work under the Contract or upon termination or expiration of the Contract.

G. Maintain appropriate and effective business continuity and disaster recovery plans to ensure resiliency of State Data and business operations.

H. Maintain a privacy policy that includes, at a minimum, processes for the State to obtain individual privacy consent for the use of PII, at the determination of the State, and to respond to individuals’ requests to access, correct, and delete their PII unless otherwise expressly agreed to in the Contract. All PII, including PII that has been de-identified, is considered State Data and Confidential Information under this Contract.

Contractor must scan all source code for vulnerabilities, including before and after any source code changes are made, and must promptly remediate any and all vulnerabilities and provide the State with patches to address the vulnerabilities at no cost to the State. Contractor must follow best practices for application code review and the most current version of the Open Source Foundation for Application Security (OWASP) top 10.

In addition to the warranties provided and pursuant to the terms of the warranties section of the Contract (i.e., notification, correction, and indemnification), Contractor warrants that its software and/or service are free from any and all defects in materials, workmanship, and design. Contractor warrants that the software is free from any and all viruses, malware, and other harmful or malicious code.

4. Permitted Disclosure to Third Parties

Disclosure of State Data is permitted as set forth in the Contract. Additionally, disclosure of State Data is also permitted when required by applicable law, regulation, court order or subpoena. If the Contractor or any of its representatives are ordered or requested to disclose any information provided by the State, whether Sensitive Data or otherwise, pursuant to court or administrative order, subpoena, summons, or other legal process or otherwise believes that disclosure is required by any law, ordinance, rule or regulation, the Contractor must notify the State within 24 hours of receipt of the order or request in order for the State to seek a protective order or take other appropriate action, as desired. The Contractor must also cooperate in the State’s efforts to obtain a protective order or other reasonable assurance that confidential treatment will be accorded the information provided by the State.

If, in the absence of a protective order, the Contractor is compelled as a matter of law to disclose the information provided by the State, the Contractor may disclose to the party compelling disclosure only the part of such information as is required by law to be disclosed (in which case, prior to such disclosure, the

Data Security and Privacy Terms Page 5 of 8

Contractor must advise and consult with the State and its counsel as to the scope of such disclosure and the nature of wording of such disclosure) and must use commercially reasonable efforts to obtain confidential treatment for the information disclosed.

The Contractor may disclose Confidential Information to the following people, subject to the requirements of the Contract and these Terms:

A. To State or Federal auditors or regulators.

B. To service providers and agents of either party as permitted by law, provided that such service providers and agents are subject to binding confidentiality obligations.

C. To the professional advisors of either party, provided that such advisors are obligated to maintain the confidentiality of the information they receive.

5. Auditing

A. The Contractor must obtain an annual audit of the services being provided under this Contract that meets the American Institute of Certified Public Accountants (AICPA) Statements on Standards for Attestation Engagements (SSAE) No. 18, Service Organization Control 1 Type 2 and Service Organization Control 2 Type 2. The audit must cover all operations pertaining to the services covered by this Contract. The audit will be at the sole expense of the Contractor and the results must be provided to the State within 30 days of Contractor’s receipt of its audit results each year.

B. The State may, at any time in its sole discretion, elect to perform a Security and Data Protection Audit. This includes a thorough review of Contractor controls, security and privacy functions and procedures, data storage and encryption methods, and backup and restoration processes. The State may utilize a third-party contractor to perform such activities to demonstrate that all security, privacy, and encryption requirements are met. The State will provide its request in writing and will work with the Contractor to schedule time to conduct the audit.

C. At no cost to the State, the Contractor must immediately remedy any issues, material weaknesses, or other items identified in each audit as they pertain to the services provided under this Contract.

6. Background Investigations of Contractor Personnel

The State of Ohio may conduct background investigations on Contractor personnel that may have access to State Data or as otherwise deemed necessary by the State. Any person who (a) has been convicted at any time of any criminal offense involving dishonesty, a breach of trust, money laundering, or who has entered into a pre-trial diversion or similar program in connection with a prosecution for such offense, (b) is named by the Office of Foreign Asset Control (OFAC) as a Specially Designated National, or (c) has been convicted of a felony may not perform certain services under the Contract. Contractor personnel who will have access to FTI or CJI must complete required background investigations that are favorably determined prior to being permitted to access the information. In addition, existing Contractors whose personnel already have access to FTI or CJI that have not completed the required background investigations within the last five years must complete the required background investigations that are favorably adjudicated prior to being permitted continued access to the information. If any Contractor personnel with existing access to the information have an unfavorably adjudicated background investigation completed, the State may terminate that personnel’s access to the information.

7. Security Incidents

A. Definitions. A security incident threatens the confidentiality, integrity, or availability of State information resources. A “Security Incident” means there is a successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an

Data Security and Privacy Terms Page 6 of 8 information system. A “Security Event” is any observable occurrence that is relevant to information security within normal operational noise levels and below pre-defined incident thresholds.

Security Incidents may fall into one or more of, but are not limited to, the following categories:

i. Loss or Theft

ii. Denial of Service (DoS)

iii. Improper Usage or Access

iv. Information Spillage

v. Malicious Code

vi. Phishing Messages

vii. Scans/Probes/Attempted Access

viii. Social Engineering

ix. Unauthorized Access

Security Events may fall into one or more of, but are not limited to, the following:

i. unsuccessful log-on attempts,

ii. unsuccessful denial of service attacks,

iii. unsuccessful phishing attacks, and

iv. unsuccessful network attacks such as pings, probes of firewalls, and port scans.

B. Security Incident Response and Reporting

The Contractor is responsible for Security Incident response, including containment, eradication, and recovery, to minimize the impact to the State. In addition to the requirements in the Contract, the Contractor must perform the following in response to a Security Incident involving State Data.

The Contractor is not required to report Security Events which do not adversely impact or potentially impact State Data or information systems unless a pattern of attacks significantly increases the risk of impact. Contractor must report in writing to the State within 24 hours of the Contractor becoming aware of any Security Incident and/or use or disclosure of State Data not authorized by the Contract, including any reasonable belief that unauthorized access to or acquisition of the State Data has occurred, and fully cooperate with the State to mitigate the consequences of the Security Incident. Within five business days of the initial Security Incident report to the State, the Contractor must document and begin providing follow-up reports for all Security Incidents to the State. The Contractor must provide updates to the follow-up reports until the investigation is complete. At a minimum, the Security Incident reports will include:

i. Data elements involved, the extent of the State Data involved in the Security Incident, and the identification of affected individuals, if applicable.

ii. A description of the unauthorized persons known or reasonably believed to have improperly used or disclosed State Data, or to have been responsible for the Security Incident.

iii. A description of where the State Data is believed to have been improperly transmitted, sent, or utilized, if applicable.

iv. A description of the probable causes of the Security Incident and, in the final report, the root cause.

v. A description of the proposed plan for preventing similar future Security Incidents, including a recommended risk remediation plan.

Data Security and Privacy Terms Page 7 of 8

vi. A description of the corrective actions taken, including repair (elimination of a defect or incident and/or restoration of system functionality requirements according to the Contract) and resolution (a temporary workaround to enable system function).

vii. Whether the Contractor believes any federal or state laws requiring notifications to individuals are triggered.

The Contractor must comply with all applicable laws that require the notification of individuals, or with other reasonable direction of the State for notification, in the event of a Security Incident involving personally identifiable information, or any other event requiring such notification. The State may, in its sole discretion, choose to provide notice to any or all parties affected by a Security Incident, but the Contractor shall reimburse the State for the cost of providing such notification.

Contractor further agrees to provide, or to reimburse the State for its costs in providing, any credit monitoring or similar services that are necessary as a result of Contractor’s Security Incident. Under Ohio law, State Data is State property and any illegal activity involving State property is subject to a criminal investigation. The Contractor shall preserve sufficient evidence to ensure accurate Security Incident records, facilitate an investigation, and determine the extent of the Security Incident.

The Contractor shall work with the customer State agency to establish a Security Incident reporting communications procedure including Contractor and customer State agency contacts, communication methods and tools. If there is no procedure established, the Contractor must report Security Incidents to the primary contact listed in the Contract or that contact’s successor and Contractor must report the Security Incident to the State via email at Enterprise.SIRT@das.ohio.gov or call 614.728.7448.

The State reserves the right to conduct an independent investigation of the Security Incident, and the Contractor shall cooperate with the investigation. The independent investigation may be conducted by a State agency or a third party acting on behalf of the State.

8. Contractor Access

When the Contractor accesses State network systems and data, including remotely, the Contractor must maintain a robust security capability that incorporates generally recognized system hardening techniques.

The Contractor must use appropriate measures to ensure that State Data is secure before transferring control of any systems or media on which State Data is stored. The method of securing the State Data must be in alignment with the required data classification. The Contractor may permit State Data to be loaded onto portable computing devices or portable storage components or media only if adequate security measures are in place to ensure the integrity and security of State Data. The transfer of any such system or media must be reasonably necessary for the performance of the Contractor’s obligations under the Contract. The Contractor shall use multifactor authentication to limit access to systems that contain Sensitive Data.

State Data must be encrypted when stored on any portable computing or storage device or media or when transmitted across any data network. Contractors must also maintain an accurate inventory of all such devices and the individuals to whom they are assigned. The Contractor must have reporting requirements for lost or stolen portable computing devices authorized for use with State Data and must report any loss or theft of such devices to the State in writing as defined in Section 7.

9. HIPAA Compliance

When the Contractor is handling State Data that includes health or medical data, the Contractor must comply with the data handling and privacy requirements of HIPAA and its associated regulations.

Additionally, some or all of the State Data may be client identifying information covered by 42 C.F.R. Part

Data Security and Privacy Terms Page 8 of 8

2. Contractor may only disclose such client identifying information back to the State and is bound in all respects by the regulations of 42 C.F.R. Part 2.

Attachment F
DATA SECURITY AND PRIVACY TERMS
Definitions
Requirements
1. The Contractor’s Responsibilities Generally
2. Protection and Handling of State Data
3. Security Standards and Warranties
4. Permitted Disclosure to Third Parties
5. Auditing
6. Background Investigations of Contractor Personnel
7. Security Incidents
8. Contractor Access
9. HIPAA Compliance

File details come from the government source that posted it. Updated .