[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-189318-105":3,"detail-sidebar-cat-1-en-105":81,"doc-detail-189318-en":127},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":74,"head_meta":76,"extra_data":78,"updated_unix":80},105,"en","data-security-incident-response-procedure","Data Security Incident Response Procedure","","Data security incident response procedures define how an organization identifies, manages, and escalates security events affecting student records, personnel files, sensitive financial records, and private personal information (including grievance, medical, FMLA, and military status data). The process distinguishes impacted data categories such as personally identifiable information and protected health information, and assigns responsible stakeholders across University Registrar, Human Resources, Library, Advancement, HIPAA covered entities, and principal investigators for identifiable human subject data.",{"@graph":14,"@context":73},[15,34,56],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/template/","Template",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/template/general/","General",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/template/data-security-incident-response-procedure/189318/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/data-security-incident-response-procedure/189318.png","ImageObject",442,249,{"name":42,"@type":43},"Levi","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-10-01","2026-09-03",true,{"@type":52,"interactionType":53,"userInteractionCount":55},"InteractionCounter",{"@type":54},"ViewAction",8,{"@type":57,"mainEntity":58},"FAQPage",[59,65,69],{"name":60,"@type":61,"acceptedAnswer":62},"Which data categories are covered by the incident response procedure?","Question",{"text":63,"@type":64},"The procedure covers student records, personnel files, sensitive financial records, private personal information, personally identifiable information, protected health information, and identifiable human subject data.","Answer",{"name":66,"@type":61,"acceptedAnswer":67},"Who is responsible for handling incidents involving private personal information (PPI)?",{"text":68,"@type":64},"Responsibilities include the University Registrar, Human Resources, Library, Advancement, and others, based on the specific PPI elements involved.",{"name":70,"@type":61,"acceptedAnswer":71},"How does the procedure handle protected health information (PHI)?",{"text":72,"@type":64},"PHI incidents are associated with HIPAA covered entities, ensuring the response follows the relevant HIPAA-aligned stakeholder responsibility.","https://schema.org",{"og:url":32,"og:type":75,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":77,"canonical":32},"index,follow",{"doc_id":79,"site_id":7},189318,1788395938,{"code":4,"msg":82,"data":83},"success",[84,89,94,99,104,109,114,119,124],{"id":85,"doc_module":22,"doc_module_name":25,"category_name":86,"show_sort_weight":87,"slug":88},11,"Presentations",90,"presentations",{"id":90,"doc_module":22,"doc_module_name":25,"category_name":91,"show_sort_weight":92,"slug":93},12,"Resumes",80,"resumes",{"id":95,"doc_module":22,"doc_module_name":25,"category_name":96,"show_sort_weight":97,"slug":98},14,"Invoices",70,"invoices",{"id":100,"doc_module":22,"doc_module_name":25,"category_name":101,"show_sort_weight":102,"slug":103},15,"Posters",60,"posters",{"id":105,"doc_module":22,"doc_module_name":25,"category_name":106,"show_sort_weight":107,"slug":108},16,"Social Media",50,"social-media",{"id":110,"doc_module":22,"doc_module_name":25,"category_name":111,"show_sort_weight":112,"slug":113},17,"Forms",40,"forms",{"id":115,"doc_module":22,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},18,"Letters",30,"letters",{"id":120,"doc_module":22,"doc_module_name":25,"category_name":121,"show_sort_weight":122,"slug":123},21,"Paper Templates",5,"papers-templates",{"id":125,"doc_module":22,"doc_module_name":25,"category_name":29,"show_sort_weight":4,"slug":126},158,"general-158",{"code":4,"msg":82,"data":128},{"doc_id":79,"user_id":129,"nickname":42,"user_avatar":130,"doc_module":22,"category_id":125,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":55,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":136,"language":137,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":138,"faqs":139,"seo_title":140,"seo_description":12,"update_tm":80,"read_time":30},7971461740909,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","|  |  |\n| --- | --- |\n| Student Records | University Registrar |\n| Personnel Files | Chief Human Resources Officer |\n| Sensitive Financial Records | AVP Business Affairs |\n| Private Personal Information (PPI) -e.g. , grievance information, medical information, FMLA information, military status, etc. | University Registrar, Human Resources, Library, Advancement, Others |\n| Personally Identifiable Information (social security numbers, credit card and bank account numbers, etc.) | University Registrar, Human Resources, Library, Advancement, Others |\n| Protected Health Information (PHI) | HIPAA Covered Entities |\n| Identifiable Human Subject Data | Principal Investigators |","cbCaiv7YrazNhmSj","https://ap.wps.com/l/cbCaiv7YrazNhmSj","pdf",247256,9,"English","# Incident Scope and Affected Data Types\n## Student Records and Personnel Files\n## Sensitive Financial Records and Private Personal Information\n## Personally Identifiable Information and Protected Health Information\n## Identifiable Human Subject Data and Stakeholder Roles","[{\"question\":\"Which data categories are covered by the incident response procedure?\",\"answer\":\"The procedure covers student records, personnel files, sensitive financial records, private personal information, personally identifiable information, protected health information, and identifiable human subject data.\"},{\"question\":\"Who is responsible for handling incidents involving private personal information (PPI)?\",\"answer\":\"Responsibilities include the University Registrar, Human Resources, Library, Advancement, and others, based on the specific PPI elements involved.\"},{\"question\":\"How does the procedure handle protected health information (PHI)?\",\"answer\":\"PHI incidents are associated with HIPAA covered entities, ensuring the response follows the relevant HIPAA-aligned stakeholder responsibility.\"}]","Data Security Incident Response Procedure | PDF"]