麻豆精品

Privacy

Northern Illinois University (麻豆精品) is committed to an effective privacy compliance program. The privacy program, located within 麻豆精品’s Ethics and Compliance Office (ECO), provides strategic leadership, oversight, and coordination to ensure campuswide compliance with applicable laws and regulations. 

The ECO collaborates with academic and administrative departments on campus, such as Information Security, Internal Audit, the College of Health and Human Sciences, and the Office of General Counsel.

We are a resource to campus departments to answer your privacy questions and help you update policies and practices on protecting the privacy of the information that you receive, create, use, and share. It is through our combined efforts that we will reduce risks to the university and individuals while advancing campus departments’ goals.

For questions about our privacy program, please email the director of privacy and record retention at khsu1@niu.edu

We provide services to 麻豆精品 to support the elements of an effective privacy compliance program by: 

  • Serving in a leadership role for compliance with applicable privacy laws, such as the Illinois Personal Information Protection Act, Health Insurance Portability and Accountability Act of 1996 (HIPAA), Family Educational Rights and Privacy Act (FERPA), Gramm-Leach-Bliley Act (GLBA), and General Data Protection Regulation (GDPR)
  • Serving as the designated University Privacy Officer, HIPAA Privacy Officer, HIPAA Steering Committee Chair, GLBA Qualified Individual, GLBA Committee Chair, and Data Protection Officer
  • Establishing an ongoing process to track and investigate inappropriate access and disclosure of university data, including protected health information, in collaboration with 麻豆精品’s Division of Information Technology 
  • Managing breach determinations and notifications as required by applicable laws and contracts
  • Taking a lead role in overseeing that 麻豆精品 has and maintains privacy and confidentiality consents, authorization forms, information notices, and materials reflecting university practices and legal requirements
  • Reviewing and updating university policies and procedures related to privacy 
  • Reviewing the privacy-related terms of university contracts and agreements
  • Participating in developing privacy-related contract terms and monitoring vendors’ performance to address privacy concerns, requirements, and responsibilities

麻豆精品 provides health care services through some of its units’ licensed health care practitioners. When an 麻豆精品 student receives health care services from an 麻豆精品 unit, the student’s health and billing records are protected under the Family Educational Rights and Privacy Act (FERPA). While there are some nuances to FERPA’s application, this is the general rule.

However, when the 麻豆精品 unit provides health care services to a community member who is not an 麻豆精品 student and when the 麻豆精品 unit makes certain electronic transactions related to those health care services, the person’s health care information is protected by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its regulations.

麻豆精品 has designated itself as a HIPAA hybrid entity. This means that HIPAA does not apply to the entire university. HIPAA applies to those units within 麻豆精品 that provide health care services to non-students and electronically perform certain transactions related to those health care services.

Representatives from those 麻豆精品 units serve on a HIPAA Steering Committee. The committee meets regularly to discuss topics such as changes to HIPAA’s privacy and security regulations, HIPAA training, updates to 麻豆精品’s HIPAA Security and Privacy Compliance Policy, and business associate agreements.

麻豆精品 receives federal financial aid under Title IV of the Higher Education Act. The Gramm-Leach-Bliley Act (GLBA) applies to universities that receive such federal financial aid. The GLBA has rules regarding data privacy and security. A university complies with GLBA’s privacy rules by complying with the Family Educational Rights and Privacy Act (FERPA). To comply with GLBA’s security rules, a university follows the security provisions set out in the Federal Trade Commission’s GLBA Safeguards Rule.

Representatives from 麻豆精品 units serve on a GLBA committee. The committee meets regularly to discuss topics such as changes to GLBA’s regulations, updates to 麻豆精品’s GLBA Information Security Plan, and oversight of contracts and service providers who access data protected by GLBA.

The ECO works collaboratively with 麻豆精品’s Procurement Services/Contract Management team and 麻豆精品’s Office of General Counsel’s contracts team to review contracts and agreements from a privacy perspective. The privacy officer serves as the subject matter expert on data use, data breach notification, and other privacy-related terms in contracts.

Contact Us

Ethics and Compliance Office
, 2nd floor
815-753-5560
eco@niu.edu