Policies
Information Security
The security of the medical school's systems and data is of the utmost importance to Feinberg IT. Knowledge of and compliance with our security policies and procedures are the responsibility of each staff and faculty member.
Hardware & Software
All Feinberg staff and faculty must adhere to Feinberg IT and NUIT guidelines and standards related to the procurement and use of approved hardware and software.
Policy Compliance
To assist Feinberg faculty, staff and students in being compliant with policy, Feinberg IT has developed a brief overview of the need-to-know policy information for various applications, hardware and data. Links to additional details are included when available.
Encryption
All types of laptops, handheld devices and portable storage devices must be encrypted. See our hardware and software policies. Feinberg IT will encrypt these devices prior to delivery to the end user.
Mobile devices like iPhones, iPads, Android and Windows phones are compliant if encrypted. This happens automatically with most devices when a PIN is used.
Storage
Feinberg data, including grant information, research data and student information, must only be stored on university-provisioned devices. Data cannot be stored in cloud services (e.g., Dropbox) without the university's agreement. Feinberg data can be stored on medical school servers, commonly called FSMFiles or FSMResFiles. Box may be used as long as no PII or PHI is stored.
NAS devices are not permitted at Feinberg.
Auto-forwarding outside Northwestern University and its affiliates is not permitted. If you have previously forwarded to sites such as gmail.com, comcast.net or aol.com, you will be contacted by Feinberg IT about how to move your emails to university servers and how to stop forwarding your emails.
Smartphones/Tablets
You may use a smartphone or tablet for work purposes only if the device requires a PIN to unlock it. This PIN also encrypts the device. On Android devices, encryption must also be enabled, in addition to a PIN. Please contact Feinberg IT for more information.
Purchasing Computers & Devices
All devices with a hard drive must be purchased, onboarded and deployed by Feinberg IT. These devices include laptops, desktops, tablets, flash drives (thumb drives) and external drives. We are happy to complete your order by including accessories such as mice, connectors and keyboards, but these items can also be purchased through your department/unit personnel.
Please create a ticket with Feinberg IT for your order.
View Feinberg IT standard machines and accessories.
Electronic Health Information
Access to the electronic medical data for research purposes is governed by the Research Use of EDW data policy. Commonly asked questions and answers about this policy can be found on the EDW FAQ page.
Thumb/Flash Drives
Thumb drives must be encrypted. Please contact Feinberg IT for assistance.
Is My Machine Managed?
If you are concerned that your device is not managed (no purple Feinberg Help shield), contact Feinberg IT.
De-identified Data Definition
Data are not de-identified until all 18 HIPAA identifiers are removed. They are:
- Names
- Geographic subdivisions smaller than a state
- All elements of dates (except year)
- Telephone numbers
- Fax numbers
- Electronic mail addresses
- Social security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web Universal Resource Locators (URLs)
- Internet Protocol (IP) address numbers
- Biometric identifiers
- Full face photographic images
- Any other unique identifying number
Student Email
Remember that u.northwestern.edu, fsm.northwestern.edu and md.northwestern.edu are not secure for PHI or PII. Please use @northwestern.edu addresses if you are involved with research, patient, student or other secure data.