4.5. SR 07-06-2015 EOty1� ,.,�� Request for Action
River
To Item Number
Mayor and City Council 4.5
Agenda Section Meeting Date Prepared by
ConsentJuly 6, 2015 Tina Allard, City Clerk
Item Description Reviewed by
Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator
Reviewed by
Action Requested
Adopt,by motion, the Policy for Ensuring Security of Not Public Data
Background/Discussion
Staff discussed the draft policy at the June 15, 2015, Council worksession meeting. This policy is
developed to meet state law requirements regarding data breaches and security.
Financial Impact
There would be cost requests coming forward as part of budget discussions regarding a security
assessment of our data.
Attachments
■ June 15, 2015, Staff Report
■ Draft Policy
POWERED 6T
Template Updoted 4/14 INAWRE1
Oty
Elk Request for Action
R.iVer
To Item Number
Mayor and City Council 9.2
Agenda Section Meeting Date Prepared by
Worksession June 15, 2015 Tina Allard, City Clerk
Item Description Reviewed by
Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator
Reviewed by
Action Requested
Review policy and direct staff on changes. Policy will be approved on a future regular meeting agenda.
Background/Discussion
The legislature made changes to the data practices law regarding access to Not Public Data. Some of
these changes came about due to many of the breaches highlighted in the news media in recent years.
The city is mandated to establish additional security measures "...ensuring data that is not public is only
accessible to persons whose work assignments reasonably require access to the data..."
What this means is the city needs to develop a policy designed to prevent employees from accessing not
public data unless they have a legitimate work reason to do so.
The policy covers the following:
1. Who must follow the policy
■ City employees
■ Firefighters
■ Volunteers
■ Appointed/elected officials
■ City vendors and consultants
2. How the city secures data
■ Protected folder structures on shared network drives
■ Locking offices/file cabinets
■ Password protection of computers, tablets, and phones
■ Shredding documents before disposal
3. Responsibilities of supervisor's and employees
4. Breach investigation process with step-by-step procedures and letter templates for staff.
5. Requirements for preparing a final report.
6. Annual security assessment of Personallnfoa-mation. Personallnfoa-mation is defined in state law as a
person's name kept in combination with a social security number, driver's license, or account
numbers with passwords or access codes.
Financial Impact
N/A
Attachments
■ Draft Policy
POWERED 6T
Template Updoted 4/14 INAMIRE1
Policy for Ensuring Security of Not Public Data
Applicability
This policy is applicable to all City of Elk River employees,including firefighters,volunteers,
appointed, and elected officials. This policy is also applicable to all city vendors and consultants.
Security
The types of Not Public Data maintained by the city are retained in the City Data Inventory Document.
All Not Public Data will be stored in files or databases which are not readily accessible to individuals
who are not authorized to access the data. The files and databases shall be secured during hours
when the offices are closed. Security shall include:
1. Storing Not Public Data only in city offices, except when necessary for city business.
2. Assigning appropriate security roles, limiting access to appropriate shared network drives,
and implementing password protections for not public electronic data.
3. Password protecting employee computers and locking computers before leaving
workstations.
4. Securing Not Public Data within locked work spaces and in locked file cabinets.
5. Shredding Not Public Data documents before disposal.
Access
Employee position descriptions shall include language outlining the employee's responsibility when
working with Not Public Data.
Only those whose job responsibilities require access will be allowed access to files and records that
contain Not Public Data. Within the City of Elk River, department directors may assign tasks by
employee or by job classifications. The responsible authority,in conjunction with department
directors and employee supervisors shall determine which employee's job responsibilities require
them to have access to Not Public Data.
If a department maintains Not Public Data that all employees within such department do not have a
work assignment allowing access to the Not Public Data, the department will ensure that the Not
Public Data are secure. This policy also applies to departments that share workspaces with other
departments within the city where Not Public Data are maintained.
In the event of a temporary duty assigned by a manager or supervisor, an employee may access
certain Not Public Data for as long as the work is assigned to the employee.
The responsible authority or designee and department directors may have access to all Not Public
Data maintained by the city if necessary for specified duties. Any access to Not Public Data will be
strictly limited to the data necessary to complete the work assignment.
Employees with access to Not Public Data will be instructed to:
1. not discuss, disclose or otherwise release private or confidential data to city employees
whose job responsibilities do not require access to the data•,
2. not leave private or confidential data where non-authorized individuals might see it; and
3. shred private or confidential data before discarding, or dispose through confidential
locked recycling.
When a contract with an outside party requires access to private or confidential information, the
contracting party will be required to use and disseminate the information consistent with the
Minnesota Data Practices Act.
Data Sharing with Authorized Entities or Individuals
State or federal law may authorize the sharing of Not Public Data in specific circumstances. Not Public
Data may be shared with another entity if a federal or state law allows or mandates it. Individuals will
have notice of any sharing applicable Tennessen warnings (see Minn. Stat. § 13.04) or the city will
obtain the individual's informed consent. Any sharing of Not Public Data will be strictly limited to the
data necessary or required to comply with the applicable law.
Security Assessment
Annually, the city will conduct a security assessment of any personal information maintained by the
city. The city administrator shall supervise preparation of a report on the status of security of the
personal information.
For the purposes of this subdivision,personal information is defined as a person's name kept in
combination with a social security number, driver's license number, or account numbers with
passwords or access codes. Personal information does not include publicly available information that
is lawfully made available to the general public from federal, state, or local government records.
Penalties for Unlawfully Accessing Not Public Data
The city will utilize the penalties for unlawful access to not public data as provided for in Minnesota
Statutes, section 13.09,if necessary. Penalties include suspension without pay, dismissal, or referring
the matter to the appropriate prosecutorial authority who may pursue a criminal misdemeanor
charge.
Breach in Security Data
Application
This section applies to breaches of the security of Not Public Data maintained by or on behalf of the
City of Elk River. The city administrator will implement and oversee these procedures and may
delegate responsibilities to other city personnel as appropriate.
Definitions
For purposes of this section the definitions in Minn. Stat, § 13.055 shall apply.
Reporting a Suspected Breach
Any person who knows of, or reasonably believes, a security breach of Not Public Data has occurred
shall immediately report the breach to the city adminstrator, and if they are a city employee or
contractor, to their supervisor. City employees who report a breach under this policy shall not be
subject to retaliation.
Response to Suspected Breach
Upon the report of a suspected breach, the city administrator shall take any and all actions necessary
to secure the data and to protect the data from continued or repeated breach and shall conduct a
preliminary internal assessment of the scope of the breach.
If the breach is suspected on a city computing system that contains or has network access to Not
Public Data, the city administrator shall consult with city IT personnel and consider control measures,
including, but not limited to, removing the computer system from the city network.
Determination of Breach
The city administrator,in conjunction with the city attorney, shall determine whether a breach has
occurred. Due consideration should be given to the potential for damage to individuals if no breach
is determined and notice is not provided. Contact the League of Minnesota Cities (LMCIT) Claims
Department. LMCIT may provide a breach coach to assist with the handling of a data security
breach or cyber event.
Notice
If it is determined that a breach has occurred, the city administrator shall provide notice to all data
subjects affected by the breach. The city administrator,in conjunction with the city attorney, shall
determine whether notice is required to be provided and to whom such notice is to be provided. At
a minimum,individuals shall be notified if their private or confidential data was, or is reasonably
believed to have been, acquired by an unauthorized person. If specific individuals cannot be
identified, notice should be sent to groups of individuals likely to have been affected, such as all
whose information is stored in the database or files involved in the breach. Appropriate measures
should also be taken to prevent notice lists from being over-inclusive. The forms of notice to be
provided are attached.
1. Timing. Notice shall be provided to all affected data subjects without unreasonable delay,
subject to:
a) The legitimate needs of a law enforcement agency; and
b) any measures necessary to determine the scope of the breach and restore the
reasonable security of the data.
Immediate notification may be appropriate in the event of a breach that could have
immediate deleterious impact on individuals whose data may have been acquired by an
unauthorized person.
2. Content. The notice shall generally include the following information:
a) A general description of what happened, and when, to the extent known.
b) The nature of the individual's private or confidential information that was involved
(not listing the specific private/confidential data).
c) Information about what the city has done to protect the individual's
private/confidential information from further disclosure.
d) City assistance (such as website information or phone number of a city resource) for
further information about the incident.
e) Information, such as websites, about what individuals can do to protect themselves
against identity theft including; contact information for nationwide credit reporting
agencies; the Federal Trade Commission and appropriate state agency resources.
Information that a report will be prepared as noted below, on how the individual
may obtain access to the report, and that the individual may request delivery of the
report by mail or email.
3. Method. Notice under this section may be provided by one of the following methods:
a) Written notice by first class mail to each affected individual;
b) electronic notice to each affected individual,if the notice provided is consistent with
the provisions regarding electronic records and signatures as set forth in the United
States Code, title 15, section 7001; or
C) substitute notice,if the city demonstrates that the cost of providing the written
notice required by paragraph (a) would exceed$250,000, or that the affected class of
individuals to be notified exceeds 500,000, or the city does not have sufficient
contact information. Substitute notice consists of all the following:
i. email notice if the city has an email address for the affected individuals;
ii. conspicuous posting of the notice on the website page of the city; and
iii. notification to major media outlets that reach the general public within the
city's jurisdiction.
Contacting Law Enforcement
The city administrator,in conjunction with the city attorney, shall determine if it is appropriate to
contact law enforcement in relation to any breach or suspected breach. Information may be shared
with law enforcement consistent with applicable data privacy laws.
If law enforcement is contacted,it should be informed of the city's practice to provide notice to
affected individuals. If law enforcement advises that such notice would impede an active criminal
investigation, notice may be delayed. Delayed notice should be sent out as soon as law enforcement
advises that it would be no longer impede the criminal investigation.
Coordination with Credit Reporting Agencies
If notice is required to be given to 1,000 or more individuals at one time, the city shall notify,
without unreasonable delay, all consumer reporting agencies that compile and maintain files on
consumers on a nationwide basis as defined in 15 U.S.C. Sect. 1681a, of the timing, distribution and
content of the notice to be sent. Such contacts shall include but not limited to the following:
■ Equifax Experian TransUnion
US Consumer Services Experian Security Assistance 1.800.680.7289
Equifax Information PO Box 72
Services, LLC Allen,TX 75013
Phone: 1.800.525.6285 1.888.397.3742
Report
Upon completion of an investigation into any breach in the security of data and final disposition of
any disciplinary action under Minn. Stat. § 13.43,including exhaustion of all rights of appeal under
any applicable collective bargaining agreement, the city administrator shall prepare a report on the
facts and results of the investigation. If the breach involves unauthorized access to or acquisition of
data by an employee, contractor, or agent of the government entity, the report must at minimum
include:
1. A description of the type of data that were accessed or acquired;
2. the number of individuals whose data was improperly accessed or acquired;
3. if there has been final disposition of disciplinary action for purposes of Minn. Stat. § 13.43,
the name of each employee determined to be responsible for the unauthorized access or
acquisition, unless the employee was performing duties under Minn. Stat. ch. 5B;
4. the final disposition of any disciplinary action taken against each employee in response.
Documentation
The city administrator or designee must document each reported breach,regardless of whether
notice is given. Documentation should be completed at the time of the initial report or as soon
thereafter as practical.
When appropriate, all documentation related to the breach and investigation shall be labeled and
maintained as not public pursuant to the applicable data privacy classification,including,but not
limited to, "security information" as defined by Minn. Stat. § 13.37. Subd. 1(a). The documentation
shall be retained in accordance with the applicable records retention policy.
Was the data accessed Did the indivival have the data Did the individual's work
private or YE5 subject's informed consent to NO assignment reasonably
confidential? access the data? require access to the private
or confidential data?
Was the data accessed for
No data security breach YES that work related purpose? NO Data Breach!
Standard Breach Notification Letter
Pate]
[Name]
[Address]
[City, State, Zip]
RE: Important Notice Regarding Possible Disclosure of Private Information
Dear [Name]:
We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take
privacy very seriously, and it is important to us that you are made fully aware of a potential privacy
issue. We have learned that your personal information,including ,
, and ,may have been compromised.
On [give date of discovery],it was discovered that [describe incident and give date of breach]. We
have not received any indication that the information has been accessed or used by an unauthorized
individual.
We sincerely apologize and regret that this situation has occurred. The City of Elk River is
committed to providing quality care,including protecting your protected information, and we want
to assure you that we have policies and procedures to protect your privacy.
If you have any questions,please contact the City of Elk River's Human Resources Director at
763.635.1024.
Sincerely,
[Name,Title]*
*Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance
official.
Standard Breach Notification Letter
Pate]
[Name]
[Address]
[City, State, Zip]
RE: Important Notice Regarding Possible Disclosure of Private Information
Dear [Name]:
[Entity] takes seriously its responsibility to protect information about the individuals it serves. I am
writing to inform you of a concern regarding possible unauthorized access of your private
information.
On [date], [Entity] discovered that [description of the issue/what occurred]. The records included
[description of data].
OPTIONAL: At this time,your data has not been used inappropriately;rather we have determined
that your data could have been vien)ed by an unauthorized person.
The [description of issue] was immediately corrected upon discovery.
Upon completion of our investigation,you have the right to receive a report on the details of the
investigation. If you would like a copy of the report, contact us to request delivery of the report via
mail or email.
We recommend you take precautionary measures to protect yourself, such as monitoring your
personal credit reports. Under federal law,you have the right to receive, at your request, a free copy
of your credit report every 12 months from each of the three consumer credit reporting companies.
A credit report can provide information regarding those who have received information about your
credit history within a certain period of time. You may request a free credit report online at
www.annualcreditreport.com or by telephone at 1.877.322.8228.
When you receive your credit reports, check for any transactions or accounts you do not recognize.
If you see anything you do not understand, call the telephone number listed on the credit report or
visit the Federal Trade Commission's Web site on identity theft at www.consumer.gov/idtheft/.
[Entity] deeply regrets that this occurred and apologizes for any uneasiness and inconvenience this
may cause you. If you have any questions,please contact [name, address, email,phone].
We will keep you informed of any additional developments that may be of importance to you.
Sincerely,
[Name,Title]*
*Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance
official.
Standard Breach Notification Letter P)/Remedial Measures
Pate]
[Name]
[Address]
[City, State, Zip]
RE: Important Notice Regarding Possible Disclosure of Private Information
Dear [Name]:
We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take
privacy very seriously, and it is important to us that you are made fully aware of a potential privacy
issue. We have learned that your personal information,including , and
, may have been compromised.
On]give date of discovery], it paras discovered that]describe incident and give date of breach]. 1F`e reported the incident
to lana enforcement because theft may have been involved[if applicable]. However,we have not received any
indication that the information has been accessed or used by an unauthorized individual.
We are keenly aware of how important your personal information is to you. If you choose, as a
measure of added security,we are offering one year of credit monitoring and reporting services at no
cost to you. This service is performed through [Vendor], an organization that watches for and
reports to you unusual credit activity, such as creating new accounts in your name. [Vendor] will
also request that the three credit bureaus place a"Fraud Alert" on your credit report. If you would
Eke to receive this service,please respond yes by or
We understand that this may pose an inconvenience to you. We sincerely apologize and regret that
this situation has occurred. The City of Elk River is committed to providing quality care,including
protecting your personal information, and we want to assure you that we have policies and
procedures to protect your privacy.
If you want to take advantage of the free credit monitoring service, or if you have any questions
please contact the Human Resources Director at 763.635.1024.
Sincerely,
[Name,Title]*
*Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance
official.
Standard Breach Notification Letter P)/Remedial Measures&
Investigative Report Due to Acquisition by an Unauthorised Person
Pate]
[Name]
[Address]
[City, State, Zip]
RE: Important Notice Regarding Possible Disclosure of Private Information
Dear [Name]:
We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take
privacy very seriously, and it is important to us that you are made fully aware of a potential privacy
issue. We have learned that your personal information,including , and
, may have been compromised.
On]give date of discovery], it paras discovered that]describe incident and give date of breach]. lie reported the incident
to Ian)enforcement because theft may have been involved[if applicable]. Based upon our investigation,we
reasonably believe that the data was acquired by an unauthorized person individual. Accordingly,
the City of Elk River will prepare a report upon completion of an investigation and final disposition
of any disciplinary action (if applicable). You may obtain access to the completed report via mail or
email by making a request to
We are keenly aware of how important your personal information is to you. If you choose, as a
measure of added security,we are offering one year of credit monitoring and reporting services at no
cost to you. This service is performed through [Vendor], an organization that watches for and
reports to you unusual credit activity, such as creating new accounts in your name. [Vendor] will
also request that the three credit bureaus place a"Fraud Alert" on your credit report. If you would
Eke to receive this service,please respond yes by to at the above-
listed address.
We understand that this may pose an inconvenience to you. We sincerely apologize and regret that
this situation has occurred. The City of Elk River is committed to providing quality care,including
protecting your personal information, and we want to assure you that we have policies and
procedures to protect your privacy.
If you want to take advantage of the free credit monitoring service, or if you have any questions
please contact the Human Resources Director at 763.635.1024.
Sincerely,
[Name,Title]*
*Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance
official.