Data Storage and Handling. The provider shall encrypt any data accessible from the hosted application meeting the following criteria at rest and in transit: o Names o Addresses o Phone numbers o Email addresses o Birth dates o Federal/state/local documents numbers o Account numbers o Race or religious information o User names o Passwords o Employee identification numbers o All Health Insurance Portability and Accountability Act (HIPAA) information o All Purchase Card Industry Data Security Standards (PCI DSS) information • Any data, accessible from the hosted application or directly accessible from it, should be encrypted.
Appears in 2 contracts
Sources: Contract for Services, Contract