Laserfiche WebLink
DocuSign Envelope ID: 601932A9-29F4-4C23-80F1-CEA4FACB795C <br />v.4.10 <br />COLORADO <br />Financfal5ervices <br />l?epartntcrn Of Hl,.. i. i'�,rv�g <br />�ivlsion of Cant�a�ts � .'. P�ocuremenl <br />8. CONFIDENTIAL INFORMATION -STATE RECORDS <br />A. Confidentiality <br />Contractor shall keep confidential, and cause all Subcontractors to keep confidential, all State <br />Records, unless those State Records are publicly available. Contractor shall not, without prior <br />written approval of the State, use, publish, copy, disclose to any third parry, or permit the use by <br />any third party of any State Records, except as otherwise stated in this Contract, permitted by <br />law or approved in writing by the State. Contractor shall provide for the security of all State <br />Confidential Information in accordance with all policies promulgated by the Colorado Office of <br />Information Security and all applicable laws, rules, policies, publications, and guidelines. If <br />Contractor or any of its Subcontractors will or may receive the following types of data, <br />Contractor or its Subcontractors shall provide for the security of such data according to the <br />following: (i) the most recently promulgated IRS Publication 1075 for all Tax Information and in <br />accordance with the Safeguarding Requirements for Federal Tax Information attached to this <br />Contract as an Exhibit, if applicable, (ii) the most recently updated PCI Data Security Standard <br />from the PCI Security Standards Council for all PCI, (iii) the most recently issued version of the <br />U.S. Department of Justice, Federal Bureau of Investigation, Criminal Justice Information <br />Services Security Policy for all CJI, and (iv) the federal Health Insurance Portability and <br />Accountability Act for all PHI and the HIPAA Business Associate Agreement attached to this <br />Contract, if applicable. Contractor shall immediately forward any request or demand for State <br />Records to the State's Principal Representative. <br />B. Other Entity Access and Nondisclosure Agreements <br />Contractor may provide State Records to its agents, employees, assigns and <br />Subcontractors as necessary to perform the Work, but shall restrict access to State Confidential <br />Information to those agents, employees, assigns and Subcontractors who require access to <br />perform their obligations under this Contract. Contractor shall ensure all such agents, employees, <br />assigns, and Subcontractors sign agreements containing nondisclosure provisions at least as <br />protective as those in this Contract, and that the nondisclosure provisions are in force at all times <br />the agent, employee, assign or Subcontractor has access to any State Confidential Information. <br />Contractor shall provide copies of those signed nondisclosure provisions to the State upon <br />execution of the nondisclosure provisions if requested by the State. <br />C. Use, Security, and Retention <br />Contractor shall use, hold and maintain State Confidential Information in compliance <br />with any and all applicable laws and regulations only in facilities located within the United <br />States, and shall maintain a secure environment that ensures confidentiality of all State <br />Confidential Information. Contractor shall provide the State with access, subject to Contractor's <br />reasonable security requirements, for purposes of inspecting and monitoring access and use of <br />State Confidential Information and evaluating security control effectiveness. Upon the expiration <br />Page 14 of 41 <br />