Laserfiche WebLink
<br />92 SECTION 6: ATTACHMENTS | 2014_0122 <br /> <br />any Claim or audit is started before the expiration of this period, the Contractor shall retain or cause to be retained all <br />Records until all Claims or audit findings have been resolved. <br /> <br />(f) The Contractor shall cooperate fully with the State and its agents in connection with an audit or inspection. Following any <br />audit or inspection, the State may conduct and the Contractor shall cooperate with an exit conference. <br /> <br />(g) The Contractor shall incorporate this entire Section verbatim into any contract or other agreement that it enters into with any <br />Contractor Party. <br /> <br />Protection of Confidential Information <br /> <br />(a) Contractor and Contractor Parties, at their own expense, have a duty to and shall protect from a Confidential Information <br />Breach any and all Confidential Information which they come to possess or control, wherever and however stored or <br />maintained, in a commercially reasonable manner in accordance with current industry standards. <br /> <br />(b) Each Contractor or Contractor Party shall develop, implement and maintain a comprehensive data - security program for the <br />protection of Confidential Information. The safeguards contained in such program shall be consistent with and comply with <br />the safeguards for protection of Confidential Information, and information of a similar character, as set forth in all applicable <br />federal and state law and written policy of the Department or State concerning the confidentiality of Confidential Information. <br />Such data-security program shall include, but not be limited to, the following: <br /> <br />(1) A security policy for employees related to the storage, access and transportation of data containing Confidential <br />Information; <br /> <br />(2) Reasonable restrictions on access to records containing Confidential Information, including access to any locked <br />storage where such records are kept; <br /> <br />(3) A process for reviewing policies and security measures at least annually; <br /> <br />(4) Creating secure access controls to Confidential Information, including but not limited to passwords; and <br /> <br />(5) Encrypting of Confidential Information that is stored on laptops, portable devices or being transmitted <br />electronically. <br /> <br />(c) The Contractor and Contractor Parties shall notify the Department and the Connecticut Office of the Attorney General as <br />soon as practical, but no later than twenty-four (24) hours, after they become aware of or suspect that any Confidential <br />Information which Contractor or Contractor Parties have come to possess or control has been subject to a Confidential <br />Information Breach. If a Confidential Information Breach has occurred, the Contractor shall, within three (3) business days <br />after the notification, present a credit monitoring and protection plan to the Commissioner of Administrative Services, the <br />Department and the Connecticut Office of the Attorney General, for review and approval. Such credit monitoring or <br />protection plan shall be made available by the Contractor at its own cost and expense to all individuals affected by the <br />Confidential Information Breach. Such credit monitoring or protection plan shall include, but is not limited to <br />reimbursement for the cost of placing and lifting one (1) security freeze per credit file pursuant to Connecticut General <br />Statutes § 36a-701a. Such credit monitoring or protection plans shall be approved by the State in accordance with this Section <br />and shall cover a length of time commensurate with the circumstances of the Confidential Information Breach. The <br />Contractors’ costs and expenses for the credit monitoring and protection plan shall not be recoverable from the Department, <br />any State of Connecticut entity or any affected individuals. <br /> <br />(d) The Contractor shall incorporate the requirements of this Section in all subcontracts requiring each Contractor Party to <br />safeguard Confidential Information in the same manner as provided for in this Section. <br /> <br />(e) Nothing in this Section shall supersede in any manner Contractor’s or Contractor Party’s obligations pursuant to HIPAA <br />or the provisions of this Contract concerning the obligations of the Contractor as a Business Associate of the Department.