Standards Group:
YALE-MSS-1: System Classification
YALE-MSS-1.3: Ensure appropriate contracts for all third-party relationships are in place
Details
Disclosing data to a third-party increases risk. To properly address this, additional contracts may be required.
If moderate or high-risk data is shared with a third-party, a Data Addendum (DA) between Yale and the third-party is required. In addition, if electronic protected health information (ePHI) is disclosed to a third-party, a Business Associates Agreement (BAA) is required.
Third-parties are responsible for meeting training requirements. Training requirements should be covered in contracts when applicable. Contracts should require that third-parties ensure that anyone who performs work under their agreement receives annual instruction and/or training to comply with the provisions of their contract(s) with Yale.
Require third-parties notify Yale of a security incident within 72 hours of a discovery of a confirmed incident.