Information Security Policies
The security of the medical school's systems and data is of the utmost importance to Feinberg IT. Knowledge of and compliance with our security policies and procedures are the responsibility of each staff and faculty member.
Skip to our information security policies list
Information Security & Access
Maintaining the privacy, security and integrity of data about our research participants, students and staff is both an ethical and legal responsibility. Given the nature of clinical care and biomedical research, staff at Northwestern University Feinberg School of Medicine are much more likely to collect, use, manage and be exposed to Protected Health Information (PHI) and Personally Identifiable Information (PII) than staff at most other schools within Northwestern University. To address this need, Feinberg has developed additional policies on the appropriate use of electronic resources that work in concert with university-wide policies.
Failure to comply with these policies will lead to sanctions, up to and including administrative suspension of activities, loss of faculty appointment, department or unit financial penalties or dismissal from the university.
View the General Security Policy
Questions about Feinberg IT Security policies or resources can be addressed to FSMIT-Policy@northwestern.edu.
Data Security Plan Requirements for Feinberg Research
The Feinberg IT Information Security provides guidelines, oversight and consultation to the research community on Data Security Plans (DSP). Visit the Feinberg Hub to view the Data Security Plan Requirements for Feinberg Research Policy, which establishes the use of DSP for studies that collect personal or health-related information.
Information Security Policies
- Administrative Computer Access Accounts Policy
Defines the control and management of administrative computer access accounts (submit the Computer Administrator Rights form to begin the process). - Assessing the Probability of Public Disclosure of Protected Data
Defines the required method to assess the probability of unauthorized disclosure of protected university data resulting from all forms of device compromise and/or unauthorized data loss as a result of reported or discovered incidents. - Authorization & Access Control Policy
Establishes the requirements to ensure authentication and access to electronic Personal Health Information (ePHI) or personally identifiable information (PII) is approved and sufficient to perform duties while maintaining compliance with university policies. - Cloud Security Policy
Defines the appropriate use of cloud services and the security controls to establish when adopting cloud computing. - Data Backup Policy
Establishes the required actions to ensure administrative data and research data are backed up, safely stored and accessible and available to restore ongoing operations. - Device Physical Security Policy
Establishes the required physical attributes of a computing device and its surroundings. - Device Security Policy
Defines the appropriate use of personal devices and smartphones. - Device Transfer & Disposal Policy
Establishes the requirements for disposal, re-use or transfer of Feinberg computing devices (submit the Computer Transfer of Ownership Form to begin the process. - Log Management Policy
Establishes the requirements to record activity in information systems that contain or use ePHI or PII. - Patch Management Policy
Establishes the patch management program and oversight for Feinberg. - Security Risk Management Policy
Establishes the information security risk management program and oversight for Feinberg. - Security Training Policy
Establishes the required security privacy training and awareness as required by the HIPAA Privacy and Security Rule. - Vulnerability Management Policy
Establishes the framework for the Feinberg vulnerability management program. - Web Application Maintainability Policy
Ensures all Feinberg web applications, whether developed in-house, purchased or vendor-built, are securely hosted, properly registered and maintained throughout their lifecycle.