Cybersecurity Awareness Month – October 2022
We’d like to explain a few government terms which are relevant to data and cybersecurity compliance at CC – these concepts are what we use to identify risk.
PII – Personally Identifiable Information –
Information about someone that could identify them either directly or in directly, particularly in combination with other PII or a person’s name.
Examples: name, telephone number, credit card number, street address, social security number, license plate numbers, geolocation data from a picture taken on a cell phone (or any other unique identifying number, characteristic, code, or combination that allows an individual to be identified).
PHI – Protected Health Information –
Information about someone’s health thus violating Health Insurance Portability and Accountability Act (HIPAA) and the Family Educational Rights and Privacy Act (FERPA). When combined with PII, this is particularly troublesome.
Examples: Medical records, beneficiaries
PCI DSS – Payment Card Industry Data Security Standard
PCI DSS is a widely accepted set of policies and procedures that optimize the security of credit, debit and cash card transactions and protect cardholders against misuse of their personal information.
Finally, the Gramm-Leach-Bliley-Act (GLBA) has created new rules and guidelines for Financial Aid that have very specific terminology.
NPI — Nonpublic Personal Information
Nonpublic Personal Information, or NPI, is a type of sensitive information created and defined by the GLBA, which specifically regulates financial services institutions.
Examples:
- Basic information provided by a consumer on an application, such as name, address, social security number, or income.
- Information from a transaction involving a financial product or service such as account numbers, credit or debit card purchases, payment history, and loan balances.
- Information that financial institutions obtain as part of providing a financial product or services such as credit reports or court records.