Build, Sustain, Improve! 1 Rochelle Foxworth,
Description: Build, Sustain, Improve! 1 Rochelle Foxworth, Supervisory Privacy Officer July 2023 VBA PRIVACY PROGRAM Relevant, Responsive, Respected! To provide an overview of the VBA Privacy Program and emphasize the legal responsibility to protect and
Related Topics
Download Presentation
"Build, Sustain, Improve! 1 Rochelle Foxworth," is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Build, Sustain, Improve! 1 Rochelle Foxworth, Supervisory Privacy Officer July 2023 VBA PRIVACY PROGRAM<br>
slide2. Relevant, Responsive, Respected! To provide an overview of the VBA Privacy Program and emphasize the legal responsibility to protect and safeguard the personally-identifiable information (PII) and protected health information (PHI) of individuals whose information we collect. 2 2<br>
slide3. Relevant, Responsive, Respected! ​Professional Development Training – We create and provide training based on VA Directive 6509 – Duties of Privacy Officers, to support the professional development of the privacy community. Privacy Officers receive TMS credit for these trainings.​
Monthly Privacy Officer Meetings – These are chats with Privacy Officers from across VBA to discuss current topics derived from questions coming from ROs or current updates from VBACO Privacy Office.​
Completion Assistance of Facility Self-Assessments (FSA) – Created by the Privacy and Records Assessment Directorate (PRAD) office to conduct ongoing monitoring and assess facilities’ Privacy and Records Management Programs for compliance with applicable policies, statutes, and regulations. All ROs are required to complete quarterly.​
Privacy Incidents – Assist facilities with filing Privacy Security Event Tracking System (PSETS) tickets. 3 3<br>
slide4. Relevant, Responsive, Respected! Privacy Officer Training Program supports VBA Privacy Officers by defining common knowledge skills and abilities (KSAs), training resources, and professional development tools required to implement and ensure local compliance with Privacy policies and procedures. ​ 4 Sample Topics:​
The Role of the VBA Privacy Officer​
Incident Response and Reporting​
Privacy Awareness 4<br>
slide5. Relevant, Responsive, Respected! VBA Privacy Office provides the following services to assist the ROs in completing the assessment: ​
​
Monitoring of ROs completion of the quarterly requirement for compliance and sending reminders of upcoming deadlines​
Provide quarterly training focused on the content areas being evaluated   ​
Consult and assist the VBAÂ Privacy Officers while they complete the 120-question assessment along with providing resource assistance for questions requiring mandatory document upload 5 5<br>
slide6. Relevant, Responsive, Respected! Which office administers Facility Self-Assessments (FSAs)?  ​
VBA Privacy Office​
Privacy and Records Assessment Directorate (PRAD)
VA Privacy Service ​​
Office of Management and Budget (OMB) 6 6<br>
slide7. Relevant, Responsive, Respected! What is a Privacy Incident?​
​A privacy incident is any event that has resulted in unauthorized use or disclosure of personal identifiable information (PII) or protected health information (PHI) where persons, other than authorized users, access PII/PHI or use it for an unauthorized purpose.​
​
How to Report Privacy Incidents:​
​
Report incidents to your Privacy Officer (PO).​
Anyone can report a suspected privacy incident. You are not required to speak to your manager before reporting an incident but should keep management informed when incidents occur. This can be done via email or phone call.​
Privacy Officers are required to report privacy incidents within one hour of notification. 7 7<br>
slide8. Relevant, Responsive, Respected! Privacy incidents are reported to the Privacy Officer?Â
True
False 8 8<br>
slide9. Relevant, Responsive, Respected! What is a Privacy Incident?
A privacy incident is any event that has resulted in unauthorized use or disclosure of personal identifiable information (PII) or protected health information (PHI) where persons, other than authorized users, access PII/PHI or use it for an unauthorized purpose.
True
False 9 9<br>
slide10. Relevant, Responsive, Respected! VACO Privacy Officers provide customer service by answering questions to VBA Business Lines, Staff Offices, Office of General Counsel (OGC), Regional Offices and Veterans, their family and dependents about:​
Privacy Laws​
VA Privacy Regulations​
Facility Self Assessments​
Privacy and Records Assessment Directorate Assessment​
Privacy Incidents 10 10<br>
slide11. Relevant, Responsive, Respected! The VBA Privacy Office ensures that VA policies comply with Federal regulatory requirements and legislative mandates. We promulgate those policies throughout VBA.
VA Privacy Policies, Statutes, and Guidance
VA Code of Fair Information Principles
VA Notice of Privacy Practices​
VA Information Security Rules of Behavior for Organization​
VA Information Security Rules of Behavior for Non-Organization​
Handbook 6300.4, Procedures for Processing Requests for Records Subject to the Privacy Act​
VA Handbook 6300.5 for SORN guidance​
VA Directive 6500 - VA Cybersecurity Program​
VA Handbook 6500 - Risk Management Framework for VA Information Systems and Information Security Program​
Directive 6502, VA Enterprise Privacy Program​
Directive 6502.3, Web Page Privacy Policy​
Handbook 6502.3, Webpage Privacy Policy​
VA Handbook 6502.4, Procedures for Matching Programs​
Directive 6507, Reducing the Use of Social Security Numbers​ (SSN)
Handbook 6507.1, Acceptable uses of the Social Security Number and the VA SSN Review Board​
Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment 11 11<br>
slide12. Relevant, Responsive, Respected! VA Privacy Policies, Statutes, and Guidance (cont.)
Handbook 6508.1, Procedures for Privacy Threshold Analysis and Privacy Impact Assessment
Directive 6509, Duties of Privacy Officers
Directive 6511, Presentations Displaying Personally-Identifiable Information
Directive 6609, Mailing of Sensitive Personal Information
Privacy Statutes
The Privacy Act of 1974
The Computer Matching and Privacy Protection Act
The eGovernment Act of 2002
The Freedom of Information Act
The Paperwork Reduction Act
OMB Guidance
OMB Memorandum M-22-05, Guidance on Federal Information Security and Privacy Management Requirements
OMB Circular A-130, Managing Information as a Strategic Resource
OMB Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information
OMB Memorandum 06-16, Protection of Sensitive Agency Information
OMB Memorandum 06-15, Safeguarding Personally Identifiable Information 12 12<br>
slide2. Relevant, Responsive, Respected! To provide an overview of the VBA Privacy Program and emphasize the legal responsibility to protect and safeguard the personally-identifiable information (PII) and protected health information (PHI) of individuals whose information we collect. 2 2<br>
slide3. Relevant, Responsive, Respected! ​Professional Development Training – We create and provide training based on VA Directive 6509 – Duties of Privacy Officers, to support the professional development of the privacy community. Privacy Officers receive TMS credit for these trainings.​
Monthly Privacy Officer Meetings – These are chats with Privacy Officers from across VBA to discuss current topics derived from questions coming from ROs or current updates from VBACO Privacy Office.​
Completion Assistance of Facility Self-Assessments (FSA) – Created by the Privacy and Records Assessment Directorate (PRAD) office to conduct ongoing monitoring and assess facilities’ Privacy and Records Management Programs for compliance with applicable policies, statutes, and regulations. All ROs are required to complete quarterly.​
Privacy Incidents – Assist facilities with filing Privacy Security Event Tracking System (PSETS) tickets. 3 3<br>
slide4. Relevant, Responsive, Respected! Privacy Officer Training Program supports VBA Privacy Officers by defining common knowledge skills and abilities (KSAs), training resources, and professional development tools required to implement and ensure local compliance with Privacy policies and procedures. ​ 4 Sample Topics:​
The Role of the VBA Privacy Officer​
Incident Response and Reporting​
Privacy Awareness 4<br>
slide5. Relevant, Responsive, Respected! VBA Privacy Office provides the following services to assist the ROs in completing the assessment: ​
​
Monitoring of ROs completion of the quarterly requirement for compliance and sending reminders of upcoming deadlines​
Provide quarterly training focused on the content areas being evaluated   ​
Consult and assist the VBAÂ Privacy Officers while they complete the 120-question assessment along with providing resource assistance for questions requiring mandatory document upload 5 5<br>
slide6. Relevant, Responsive, Respected! Which office administers Facility Self-Assessments (FSAs)?  ​
VBA Privacy Office​
Privacy and Records Assessment Directorate (PRAD)
VA Privacy Service ​​
Office of Management and Budget (OMB) 6 6<br>
slide7. Relevant, Responsive, Respected! What is a Privacy Incident?​
​A privacy incident is any event that has resulted in unauthorized use or disclosure of personal identifiable information (PII) or protected health information (PHI) where persons, other than authorized users, access PII/PHI or use it for an unauthorized purpose.​
​
How to Report Privacy Incidents:​
​
Report incidents to your Privacy Officer (PO).​
Anyone can report a suspected privacy incident. You are not required to speak to your manager before reporting an incident but should keep management informed when incidents occur. This can be done via email or phone call.​
Privacy Officers are required to report privacy incidents within one hour of notification. 7 7<br>
slide8. Relevant, Responsive, Respected! Privacy incidents are reported to the Privacy Officer?Â
True
False 8 8<br>
slide9. Relevant, Responsive, Respected! What is a Privacy Incident?
A privacy incident is any event that has resulted in unauthorized use or disclosure of personal identifiable information (PII) or protected health information (PHI) where persons, other than authorized users, access PII/PHI or use it for an unauthorized purpose.
True
False 9 9<br>
slide10. Relevant, Responsive, Respected! VACO Privacy Officers provide customer service by answering questions to VBA Business Lines, Staff Offices, Office of General Counsel (OGC), Regional Offices and Veterans, their family and dependents about:​
Privacy Laws​
VA Privacy Regulations​
Facility Self Assessments​
Privacy and Records Assessment Directorate Assessment​
Privacy Incidents 10 10<br>
slide11. Relevant, Responsive, Respected! The VBA Privacy Office ensures that VA policies comply with Federal regulatory requirements and legislative mandates. We promulgate those policies throughout VBA.
VA Privacy Policies, Statutes, and Guidance
VA Code of Fair Information Principles
VA Notice of Privacy Practices​
VA Information Security Rules of Behavior for Organization​
VA Information Security Rules of Behavior for Non-Organization​
Handbook 6300.4, Procedures for Processing Requests for Records Subject to the Privacy Act​
VA Handbook 6300.5 for SORN guidance​
VA Directive 6500 - VA Cybersecurity Program​
VA Handbook 6500 - Risk Management Framework for VA Information Systems and Information Security Program​
Directive 6502, VA Enterprise Privacy Program​
Directive 6502.3, Web Page Privacy Policy​
Handbook 6502.3, Webpage Privacy Policy​
VA Handbook 6502.4, Procedures for Matching Programs​
Directive 6507, Reducing the Use of Social Security Numbers​ (SSN)
Handbook 6507.1, Acceptable uses of the Social Security Number and the VA SSN Review Board​
Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment 11 11<br>
slide12. Relevant, Responsive, Respected! VA Privacy Policies, Statutes, and Guidance (cont.)
Handbook 6508.1, Procedures for Privacy Threshold Analysis and Privacy Impact Assessment
Directive 6509, Duties of Privacy Officers
Directive 6511, Presentations Displaying Personally-Identifiable Information
Directive 6609, Mailing of Sensitive Personal Information
Privacy Statutes
The Privacy Act of 1974
The Computer Matching and Privacy Protection Act
The eGovernment Act of 2002
The Freedom of Information Act
The Paperwork Reduction Act
OMB Guidance
OMB Memorandum M-22-05, Guidance on Federal Information Security and Privacy Management Requirements
OMB Circular A-130, Managing Information as a Strategic Resource
OMB Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information
OMB Memorandum 06-16, Protection of Sensitive Agency Information
OMB Memorandum 06-15, Safeguarding Personally Identifiable Information 12 12<br>