Ohio Admin. Code 3301-2-18 - Restricting and logging access to confidential personal information in computerized personal information systems
For personal information systems that are computer systems and
contain confidential personal information, the department
shall
will do
the following:
(A) Access
restrictions. Access to confidential personal information that is kept
electronically shall require
needs a password or other authentication
measure;
(B) Acquisition of a new
computer system. When the department acquires a new computer system that
stores, manages, or contains confidential personal information, the department
shall
will
include a mechanism for recording specific access by employees of the
department to confidential personal information in the system;
(C) Upgrading existing computer systems. When
the department modifies an existing computer system that stores, manages, or
contains confidential personal information, the department
shall
will
make a determination whether the modification constitutes an upgrade. Any
upgrades to a computer system shall
will include a mechanism for recording specific access
by employees of the department to confidential personal information in the
system;
(D) Existing computer
systems. Logging requirements
obligations regarding confidential personal
information in existing computer systems:
(1)
The department shall require
will mandate that employees of the department who
access confidential personal information within computer systems to maintain a
log that records that access;
(2)
Access to confidential information is not required
necessary to
be entered into the log under the following circumstances:
(a) The employee of the department is
accessing confidential personal information for official departmental purposes,
including research, and the access is not specifically directed toward a
specifically named individual or a group of specifically named
individuals;
(b) The employee of
the department is accessing confidential personal information for routine
office procedures and the access is not specifically directed toward a
specifically named individual or a group of specifically named
individuals;
(c) The employee of
the department comes into incidental contact with confidential personal
information and the access of the information is not specifically directed
toward a specifically named individual or a group of specifically named
individuals;
(d) The employee of
the agency accesses confidential personal information about an individual based
upon a request made under either of the following circumstances:
(i) The individual requests confidential
personal information about himself/herself;
(ii) The individual makes a request that the
department takes some action on that individual's behalf and accessing the
confidential personal information is required
needed in
order to consider or process that request.
(3) For purposes of this paragraph, the
department may choose the form or forms of logging, whether in electronic or
paper formats.
Notes
Promulgated Under: 119.03
Statutory Authority: 3301.07, 1347.15
Rule Amplifies: 1347.15
Prior Effective Dates: 09/25/2010, 11/18/2016
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.
No prior version found.