Purpose
User authentication is a means to control who has access to an Information Resource system. Controlling the access is necessary for any Information Resource. Access gained by a non-authorized entity can cause loss of information confidentiality, integrity and availability that may result in loss of revenue, liability, loss of trust, or embarrassment to SmartSalem Medial Center (SSMC)
- Guidelines for maintaining secure passwords
- Guidelines for Data confidentiality, integrity and protection
Description
Passwords are essential to computer security. They are the front line of protection for authorized user accounts.All authorized users are responsible for taking the actions outlined below to secure their passwords so as to avoid unauthorized access SSMC network. Purpose The purpose of this policy is to establish the rules and standard for creation, distribution, safeguarding, termination, and reclamation of SSMC user authentication mechanism Scope The scope of this policy is applicable to all SSMC users who have login credentials (user name & password) to access the SSMC IT systems.
Policy
- All system-level passwords must be changed on a least a quarterly basis.
- All user-level passwords (e.g. desktop computer,email.) must be changed at least every 45 days.
- It must adhere to a minimum length as established by SSMC management
- Indivigual user passwords must not be shared with unauthorized persons.
- All user-level and system-level passwords must confirm to the guidelines described below.
- If a use forgot his password (by any chance), they can report to SSMC IT and IT will help to reset the same.
- If the security of a password is in doubt, the password must be changed immediately.
- Password lockout: User account will be locked if there are more than 10 attempts to log and user needs to contact SSMC IT team for password reset where a new password will be provided and user needs to change this upon his first log on.
- Computing devices must not be left unattended without enabling a password protected screensaver or logging off of the device
- In the event passwords are found or discovered, the following steps must be taken:
- Take control of the passwords and protect them
- Report the discovery to the IT Help Desk
Standards
General Password Guidelines
- ✅ The password contains both upper and lower case characters (e.g. a-z, A-Z)
- ✅ The password has digits and punctuation characters as well as letters, if possible (e.g. 0-9, !@#$%^&*()_+|~-=`{}[]:";'<>?,./)
- ✅ The password is at least eight alpha-numeric characters long
- ✅ The password is not a word in any language, slang, dialect, jargon, etc.
- ✅ The password is not based on personal information, names of family, etc.
- ✅ Passwords must safeguared with full confidentiality.
Passwords must not be easy to guess and they:
- 🛑 must not be your Username
- 🛑 must not be your employee number
- 🛑 must not be your name
- 🛑 must not be your birthday
- 🛑 must not be your license plate number
- 🛑 must not be your address
- 🛑 must not be your phone number
- 🛑 must not be the name of your department
- 🛑 must not be makes or models of vehicles
- 🛑 must not be any information about you that is known or is easy to learn (favorite - food, color, sport, etc.)
Data confidentiality and Protection
Heads of Department are responsible for ensuring that these Data Principles are applied within their departments:
- All patient personal data will be obtained and processed fairly and lawfully.
- Personal data shall only be obtained for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or purposes.
- Any information held for any purpose or purposes will be adequate, relevant and not excessive in relation to that purpose or those purposes for which they are processed.
- Personal data shall be accurate and where necessary kept up to date.
- Appropriate technical and organizational measures shall be taken against unauthorized or unlawful personal processing of personal data, against alteration, disclosure or destruction of personal data and against accidental loss or destruction of personal data.
- Personal data shall not be transferred to a country or territory outside the UAE Area unless that country or territory ensures an adequate level of protection for rights and freedoms of data subjects in relation to the processing of personal data.
Measures to be taken
To avoid unauthorized access to Personal Data and Data protection the following security requirements shall be done.
- Staff members must only be authorized to access the patient/finance system level by the appropriate manager’s permission. These levels to be in accordance with the requirement to undertake their roles efficiently and effectively.
- IT will create different security groups on Active Directory (for data access control) and on HIS (for patient data access) to control the user access to respective sources.
- Staff must log off patient/finance systems or their personal computer whenever they leave the terminal to avoid unauthorized access.
- No staff member should allow others to operate the patient systems using their password.
- Staff must keep passwords confidential and if a member of staff becomes aware that their password has been compromised they must report it to the IT Department, who will help them to amend the password.
Abbreviations
SMC-DKP: SmartSalem Medical Centre Dubai Knowledge Park
SSMC-IMC: SmartSalem Medical Centre Index Mall
SSMC-CW: SmartSalem Medical Centre City Walk
SSMC-HQ: SmartSalem Head Quarter
