Skip to main content

Policies

Read Feinberg's IT policies below. See our schoolwide policies page for a full list. Questions about Feinberg IT Security policies or resources can be addressed to FSMIT-Policy@northwestern.edu.

Information Security

The security of the medical school's systems and data is of the utmost importance to Feinberg IT. Knowledge of and compliance with our security policies and procedures are the responsibility of each staff and faculty member. 

See our information security policies

Research Use of EDW Data

The Research Use of EDW Data policy is intended to ensure that research data is obtained from authoritative data sources with evidence of approval and only through approved pathways consistent with existing agreements for NMHC data. Please review the EDW FAQ for more information about how this policy may apply to your research and how to access EHR data appropriately.

Data Storage

Our Data Storage Policy and procedure establishes the requirements for storing Feinberg research, administrative and educational data. These requirements include approved data storage platforms based on data sensitivity, the ability to execute reliable data backup and recovery procedures and the manageability and configurability of data access control.

Hardware & Software

All Feinberg staff and faculty must adhere to Feinberg IT and NUIT guidelines and standards related to the procurement and use of approved hardware and software.

See the Hardward & Software Standards

Email

The Email Encryption Policy requires that email messages and attachments be encrypted when they contain PHI or PII. Encryption may occur automatically, manually or be placed into quarantine.

The Email Auto-Forwarding Policy states that email auto-forwarding is allowed only between policy-defined Northwestern-affiliated environments.

Procurement

The Feinberg Procurement Policy outlines the requirements and procedures for purchasing computers and related items through Feinberg. Any computer item with storage must be purchased through the Feinberg IT Procurement Team.

Policy Compliance

To assist Feinberg faculty, staff and students in being compliant with policy, Feinberg IT has developed a brief overview of the need-to-know policy information for various applications, hardware and data. Links to additional details are included when available.

Encryption

All types of laptops, handheld devices and portable storage devices must be encrypted. See our hardware and software policies. Feinberg IT will encrypt these devices prior to delivery to the end user.

Mobile devices like iPhones, iPads, Android and Windows phones are compliant if encrypted. This happens automatically with most devices when a PIN is used.

Storage

Feinberg data, including grant information, research data and student information, must only be stored on university-provisioned devices. Data cannot be stored in cloud services (e.g., Dropbox) without the university's agreement. Feinberg data can be stored on medical school servers, commonly called FSMFiles or FSMResFiles. Box may be used as long as no PII or PHI is stored.

NAS devices are not permitted at Feinberg.

Email

Auto-forwarding outside Northwestern University and its affiliates is not permitted. If you have previously forwarded to sites such as gmail.com, comcast.net or aol.com, you will be contacted by Feinberg IT about how to move your emails to university servers and how to stop forwarding your emails.

Smartphones/Tablets

You may use a smartphone or tablet for work purposes only if the device requires a PIN to unlock it. This PIN also encrypts the device. On Android devices, encryption must also be enabled, in addition to a PIN. Please contact Feinberg IT for more information.

Purchasing Computers & Devices

All devices with a hard drive must be purchased, onboarded and deployed by Feinberg IT. These devices include laptops, desktops, tablets, flash drives (thumb drives) and external drives. We are happy to complete your order by including accessories such as mice, connectors and keyboards, but these items can also be purchased through your department/unit personnel.

Please create a ticket with Feinberg IT for your order.

View Feinberg IT standard machines and accessories.

Electronic Health Information

Access to the electronic medical data for research purposes is governed by the Research Use of EDW data policy. Commonly asked questions and answers about this policy can be found on the EDW FAQ page.

Thumb/Flash Drives

Thumb drives must be encrypted. Please contact Feinberg IT for assistance.

Is My Machine Managed?

If you are concerned that your device is not managed (no purple Feinberg Help shield), contact Feinberg IT.

De-identified Data Definition

Data are not de-identified until all 18 HIPAA identifiers are removed. They are:

  1. Names
  2. Geographic subdivisions smaller than a state
  3. All elements of dates (except year)
  4. Telephone numbers
  5. Fax numbers
  6. Electronic mail addresses
  7. Social security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers and serial numbers
  13. Device identifiers and serial numbers
  14. Web Universal Resource Locators (URLs)
  15. Internet Protocol (IP) address numbers
  16. Biometric identifiers
  17. Full face photographic images
  18. Any other unique identifying number

Student Email

Remember that u.northwestern.edu, fsm.northwestern.edu and md.northwestern.edu are not secure for PHI or PII. Please use @northwestern.edu addresses if you are involved with research, patient, student or other secure data.