Handling Sensitive Personal Information and Breach Notification A. As part of its contract with HHSC Contractor may receive or create sensitive personal information, as section 521.002 of the Business and Commerce Code defines that phrase. Contractor must use appropriate safeguards to protect this sensitive personal information. These safeguards must include maintaining the sensitive personal information in a form that is unusable, unreadable, or indecipherable to unauthorized persons. Contractor may consult the “Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals” issued by the U.S. Department of Health and Human Services to determine ways to meet this standard. B. Contractor must notify HHSC of any confirmed or suspected unauthorized acquisition, access, use or disclosure of sensitive personal information related to this Contract, including any breach of system security, as section 521.053 of the Business and Commerce Code defines that phrase. Contractor must submit a written report to HHSC as soon as possible but no later than 10 business days after discovering the unauthorized acquisition, access, use or disclosure. The written report must identify everyone whose sensitive personal information has been or is reasonably believed to have been compromised. C. Contractor must either disclose the unauthorized acquisition, access, use or disclosure to everyone whose sensitive personal information has been or is reasonably believed to have been compromised or pay the expenses associated with HHSC doing the disclosure if: 1. Contractor experiences a breach of system security involving information owned by HHSC for which disclosure or notification is required under section 521.053 of the Business and Commerce Code; or 2. Contractor experiences a breach of unsecured protected health information, as 45 C.F.R. §164.402 defines that phrase, and HHSC becomes responsible for doing the notification required by 45 C.F.R. §164.404. HHSC may, at its discretion, waive Contractor's payment of expenses associated with HHSC doing the disclosure.
What Will Happen After We Receive Your Letter When we receive your letter, we must do two things:
Happen After We Receive Your Letter When we receive your letter, we must do two things:
Your Rights and Our Responsibilities After We Receive Your Written Notice We must acknowledge your letter within 30 days, unless we have corrected the error by then. Within 90 days, we must either correct the error or explain why we believe the bill was correct. After we receive your letter, we cannot try to collect any amount you question, or report you as delinquent. We can continue to bill you for the amount you question, including finance charges and we can apply any unpaid amount against your credit limit. You do not have to pay any questioned amount while we are investigating, but you are still obligated to pay the parts of your bill that are not in question. If we find that we made a mistake on your bill, you will not have to pay any finance charges related to any questioned amount. If we didn’t make a mistake, you may have to pay finance charges, and you will have to make up any missed payments on the questioned amount. In either case, we will send you a statement of the amount you owe and the date that it is due. If you fail to pay the amount that we think you owe, we may report you as delinquent. However, if our explanation does not satisfy you and you write to us within ten days telling us that you still refuse to pay, we must tell anyone we report you to that you have a question about your bill. In addition, we must tell you the name of anyone we reported you to. Upon settlement of a disputed bill, we must notify anyone we reported you to that the matter has been settled. If we don’t follow these rules, we can’t collect the first $50 of the questioned amount, even if your bill was correct.
PLEASE READ THIS NEXT SECTION CAREFULLY Although there will be circumstances when it is appropriate to seek parental consent, children’s data protection and privacy rights are their own. The law considers that children of average maturity will, from the age of around 12, have sufficient awareness of their own privacy to make certain choices relating to their personal data themselves. Parents’ views remain important, but sometimes the law will require us to give more weight to the decision the child makes about his or her own privacy. For most purposes, it will not in fact be necessary or practical for us to obtain consent from you (or your child) for the use we make of your (or your child’s) personal data. The law recognises this but also requires that, as far as possible, we set out clearly what these uses will be. Please also see our 'Privacy Notice' which is available on the School's website.