This article provides guidelines on sensitive information for TDX users.
Information
“Sensitive Information” is a label covering many types of data. The Information Classification Standard describes four “tiers” of information. Tier 2 and 3 are “sensitive” information.
Tier 2 and 3 information is often in those tiers because it is covered by a specific law, regulation, or industry standard. Examples:
- Protected Health Information, as defined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Student education records, as defined by the Family Educational Rights and Privacy Act (FERPA)
- Customer record information, as defined by the Gramm Leach Bliley Act (GLBA)
- Confidential personnel information, as defined by the State Personnel Act
- Information that is deemed to be confidential in accordance with the North Carolina Public Records Act
If you have access to sensitive information because of your role with the University, you have a responsibility to use, share, and manage that information properly. If you are unsure whether information you have is “sensitive” there are people responsible for Data Governance who can help. The Data Assistance can provide guidance. Information on University Data Governance is available at datagov.unc.edu. You can ask for their assistance using the University Data Assistance request forms here on help.unc.edu.
If you are seeking guidance on how any University Information must be protected, the University's Institutional Privacy Office and Information Security Office have guidance on how to identify the specific types of data you work with, the regulations covering those types, the privacy and security obligations you must meet including the security obligation levels (Low, Moderate, High), and other information on data protection. Please note: the Information Classification Data Tiers and data governance program guide you in appropriate use, and refer you to campus authorities and resources on managing data. They are not a shortcut to your security obligation levels for the detailed type(s) of data you are working with. Consult the Information Security Controls Standard ("MSS"), guidance from your unit's Delegated Security Authority (DSA), security training, information from the Information Security Office, and other resources if you have questions about how to protect University Information.
If you suspect that University sensitive information may be compromised, call 919-962-HELP and request a critical ticket for an Information Security Analyst.