Laserfiche WebLink
<br />delivery. Only employees, officials in the course of their duties, and approved/vetted outside vendors, <br />contractors, and visitors are allowed access to the facility. Employees are required to display identification <br />at all times while working. <br />Employees must immediately report a lost identification badge to their supervisor. Lost employee <br />identification and /or access card will result in immediate deactivation of the lost card and issuance of a <br />new identification and/or access card. All doors without biometric or electronic access control systems <br />must be re-coded or re- keyed annually, as well as following any involuntary termination. <br />Transactional Security Policies <br /> <br />Maintaining fiscal integrity and discipline is paramount in the medical cannabis industry. A majority of <br />transactions are still cash based, and a secure method of accounting for and securing the cash is <br />imperative. Blüm SL will encourage use of credit and debit cards when possible in an effort to automate <br />the process, and reduce and mitigate problems associated with cash, including theft and fraud. The entire <br />transaction process occurs with Blüm SL’s POS system, which ties directly into our inventory <br />management systems, and is monitored by high definition cameras. When a transaction occurs, payment <br />will be collected in the form of credit or debit card, or cash. The outgoing medication will be scanned and <br />removed from the inventory system. <br /> <br />Blüm SL can undertake a flash audit at any time to reveal any discrepancies in payments or medication <br />quantities. All cash drawers are reconciled after each shift and reconciliation is signed off by a dispensary <br />manage, to enable Blüm SL to reconcile individual cash stations quickly and accurately. Any discrepancies <br />will be identified at the close of a drawer or station and can further be reviewed by camera. Daily batch <br />reports are created and reviewed by management. This series of checks and balances effectively mitigates <br />risk of financial indiscretions that may otherwise occur at any level of the financial reporting process. A <br />contracted armored car service will be provided as deemed appropriate and dedicated to delivering, <br />receiving and securing facility proceeds, which may significantly reduce the risk of robbery and theft. <br /> <br />Patient/Transactional Security Blüm SL has the experience, knowledge, and tools necessary to control sensitive, confidential patient <br />information and employee records, and to maintain a unified, secure, HIPAA-compliant registry of its <br />medical cannabis patients. The MJ Freeway software system provides the requisite fields and protections <br />necessary to control security issues, to secure employee records, and to meet confidentiality requirements <br />for patient records. <br />Pursuant to California Health and Safety Code Section 11362.7 et seq., Blüm SL shall maintain records of its <br />patients on site using only the State of California Medical Cannabis Identification Card issued by the County <br />or its designee, or a copy of the prescribing doctor’s written recommendation, to further protect <br />confidentiality of the cardholder. <br /> The Blüm SL network will utilize a layered defense to protect patient information, and information systems <br />containing patient data will be physically and logically segregated from POS systems and from website <br />infrastructure. Internal and external digital firewalls will protect the internal network from external attacks <br />directed against the website. All physical and system access to patient information will be logged and <br />monitored on a regular schedule. Access control lists mapped to assigned job roles, combined with real- <br />time alerts, will ensure immediate notification to management should there be an unauthorized attempt to <br />access patient data. <br /> Visitor Security <br />Visitors, including outside vendors and consultants are only allowed when escorted by a general manager, <br />after proper clearance through Blüm SL protocol. Such visitors must obtain a visitor identification badge <br />before entering a limited access area, and will be escorted at all times. The visitor identification badge must <br />be visibly displayed at all times while the visitor is in any limited access area. All visitors must be logged in <br />and out, and the log will be available for inspection by the City of San Leandro at all times. All visitor <br />identification badges will be returned to Blüm SL upon exit. <br /> Third Party Contractor Security, Requirements and Responsibilities <br />As with visitor protocol, third party contractors are only allowed when escorted by a general manager, after <br />proper clearance through Blüm SL protocol. Such visitors must obtain a visitor identification badge before <br />entering a limited access area, and will be escorted at all times. The visitor identification badge must be <br />432