|
Data Classification |
Definition |
Risk Level |
||
|
High |
Medium |
Low |
||
|
Restricted |
Information is non-public information protected by laws, contractual agreements, or business stipulations (e.g., PHI beyond HIPAA such as chemical dependency rehabilitation program services, attorney-client communications) |
PCI, ePHI, PHI, PII |
PII |
N/A |
|
Confidential |
Information is non-public information protected by laws, contractual agreements, or business stipulations (e.g., PHI not requiring special additional security beyond HIPAA, corporate strategic plans, employee payroll records, audit findingsfk). |
PCI, ePHI, PHI, PII |
PII |
Specific non-PHI, non-PII, or de-identified company data |
|
Internal |
information is non-public information that is generated or collected by ORG for the use of covered individuals and other authorized parties in performing ORG business functions (e.g., policies, procedures, salary information, security diagrams) |
PII |
PII |
Specific non-PHI, non-PII, or de-identified company data |
|
Public |
information is information that has been generated specifically for disclosure to persons outside ORG and has been approved for release (e.g., press releases, marketing materials, clinician websites). |
N/A |
N/A |
Manipulated to remove non-public data |
