Yale University

ITS Information Technology Services

Yale ITS Home

Help Desk
203.432.9000
203.785.3200

ITS Office
Yale University
25 Science Park
P.O. Box 208276
New Haven, CT
06520-8276
USA

Regulatory and organizational requirements

In the course of carrying out its academic, research and clinical missions, faculty, staff and students at Yale collect many different types of information, including financial, academic, health, human resources information, and personally identifiable information. Federal and state laws impose many obligations on Yale to protect the confidentiality of information about students, employees, and patients.

In addition to regulatory requirements, there are also requirements stipulated by other organizations when the University requests use of those organizations’ data sets.  In turn, every member of the University has the obligation to implement appropriate safeguards to meet these requirements. These requirements include:

Appropriate protections (security controls) for the confidentiality, integrity and availability of data must be implemented to comply with regulations, contracts and other agreements. Implementation of required administrative, technical & physical security controls varies, but implementation may involve substantial resources – including financial, IT and human resources. Many researchers and departments may not have the required resources and/or IT support to implement security controls, so it is critical that that there is a clear understanding of IT and information security roles and responsibilities, well in advance of entering into an agreement, grant or contract.

Next →  Protected personal information


Related topics

Related University Policies & Procedures

Related online resources

Jump to top.

Last modified: Tuesday, 12-Oct-2010 11:29:31 EDT. (ac)