LegalFix

§ 1101.5 - Security, confidentiality and protection of records.

Copy with citation
Copy as parenthetical citation

The Act requires that records subject to the Act be maintained with appropriate administrative, technical and physical safeguards to ensure the security and confidentiality of records and to protect against any anticipated threats or hazards to their security or integrity which could result in substantial harm, embarrassment, inconvenience or unfairness to any individual on whom information is maintained.

When maintained in manual form (typed, printed, handwritten, etc.) records shall be maintained, at a minimum, subject to the following safeguards, or safeguards affording comparable protection:

Areas in which the records are maintained or regularly used shall be posted with an appropriate warning stating that access to the records is limited to authorized persons. The warning shall also summarize the requirements of § 1101.3 and state that the Act contains a criminal penalty for the unauthorized dislosure of records to which it applies.

During working hours: (i) The area in which the records are maintained or regularly used shall be occupied by authorized personnel or (ii) access to the records shall be restricted by their storage in locked metal file cabinets or a locked room.

During non-working hours, access to the records shall be restricted by their storage in locked metal file cabinets or a locked room.

Where a locked room is the method of security provided for a system, that security shall be supplemented by: (i) Providing lockable file cabinets or containers for the records or (ii) changing the lock or locks for the room so that they may not be opened with a master key. For purposes of this paragraph, a master key is a key which may be used to open rooms other than the room containing records subject to the Act, unless those rooms are utilized by officials or employees authorized to have access to the records subject to the Act.

Personnel handling personal information during routine use will ensure that the information is properly controlled to prevent unintentional or unauthorized disclosure. Such information will be used, held, or stored only where facilities or conditions are adequate to prevent unauthorized or unintentional disclosure.

When the records subject to the Act are maintained in computerized form, safeguards shall be utilized based on those recommended in the National Bureau of Standard's booklet “Computer Security Guidelines for Implementing the Privacy Act of 1974” (May 30, 1975), and any supplements thereto, which are adequate and appropriate to assuring the integrity of the records.

LegalFix

Copyright ©2024 LegalFix. All rights reserved. LegalFix is not a law firm, is not licensed to practice law, and does not provide legal advice, services, or representation. The information on this website is an overview of the legal plans you can purchase—or that may be provided by your employer as an employee benefit or by your credit union or other membership group as a membership benefit.

LegalFix provides its members with easy access to affordable legal services through a network of independent law firms. LegalFix, its corporate entity, and its officers, directors, employees, agents, and contractors do not provide legal advice, services, or representation—directly or indirectly.

The articles and information on the site are not legal advice and should not be relied upon—they are for information purposes only. You should become a LegalFix member to get legal services from one of our network law firms.

You should not disclose confidential or potentially incriminating information to LegalFix—you should only communicate such information to your network law firm.

The benefits and legal services described in the LegalFix legal plans are not always available in all states or with all plans. See the legal plan Benefit Overview and the more comprehensive legal plan contract during checkout for coverage details in your state.

Use of this website, the purchase of legal plans, and access to the LegalFix networks of law firms are subject to the LegalFix Terms of Service and Privacy Policy.

We have updated our Terms of Service, Privacy Policy, and Disclosures. By continuing to browse this site, you agree to our Terms of Service, Privacy Policy, and Disclosures.
§ 1101.5 - Security, confidentiality and protection of records.