Department: UW Medicine Information Technology Services
Policy Number:
Effective Date: June 11th, 2007
Review Date: April 27th, 2007
Purpose
The purpose of this standard is to document UW Medicine minimum requirements for Other Networked Devices on the UW Medicine networks, and document proper security. procedures.
Standard
It is UW Medicine[1] policy that other Networked Devices, such as, but not limited to, printers, copiers, internet microscopes, barcode readers meet the following minimum requirements:
1. Acquire an appropriate IP address.
· Obtain dynamic or static IP address through an IT Services Help Desk or UW Technology or other UW Medicine approved DHCP server, or
· Use private IP that is logically separated from the University of Washington IP network subnets.
2. Ensure patches and/or updates are applied in a timely manner.
3. Disable all unused system services.
4. Use strong passwords.
See Choosing a Good Password:
http://www.washington.edu/computing/uwnetid/password/
5. Where needed for adequate protection, use active network filtering or a firewall.
If your device cannot be secured as above, it is the System Owner’s responsibility to request a policy exemption. See UW Medicine Information Security Standard: SEC-01.02 Information Security Policy Exemption Standard.
For general security information refer to http://security.uwmedicine.org or contact the IT Services Helpdesk at https://helpdesk.mcis.washington.edu/.
UW Medicine IT Services: Date:
James S. Fine, M.D., CIO, ISO
[1] For the purposes of HIPAA, UW Medicine includes the following entities: University of Washington Medical Center and Clinics; Harborview Medical Center and Clinics; UW Medicine Neighborhood Clinics (University of Washington Physicians Network); UW Physicians Sports Medicine Clinic; Hall Health Primary Care Center; University of Washington Physicians; UW Medicine Eastside Specialty Center, as well as certain services and activities that support UW Medicine that are performed by non-healthcare components of the University of Washington as defined within Privacy Policy PP-01 Use & Disclosure of Protected Health Information – Organizational Requirements. UW School of Medicine is subject to the UW Medicine Information Security Program.