Group Insurance Service Center

Group Insurance Service Center

  • 20 Winter St
  • Pembroke, Massachusetts
  • 02359-4965

Website Links

Description

Written Information Security Policy (WISP) For Group Insurance Service Center, Incorporated and GISC Insurance Agency, Incorporated (GISC) Date: February 3, 2010 Person in charge of compliance: Karen J. Sealund I. OBJECTIVE: In order to protect our clients’ privacy and personal information, GISC has developed this Written Information Security Policy (WISP). This set of comprehensive guidelines and policies are implemented in compliance with Massachusetts General Laws 201 CMR 17 “Standards for the Protection of Personal Information of Residents of the Commonwealth.” This WISP is reviewed periodically and amended as necessary to protect our staff, contractors and clients’ personal information. II. Designated Employee to Maintain our Security Plan. GISC has appointed Karen Sealund to be the designated employee in charge of maintaining, updating and implementing our information security program. III. Internal and External Risk Assessment [201 CMR 17.03.2(b)] In order to assess any risk of access to personal information, we have evaluated where that information may be present. GISC may ONLY keep electronic information or other sensitive information on the File Server Computer, which are password protected and located in the Server Room. Personal information residing on non-electronic media (HR documents, contracts, medical and dental claims, underwriting files, census information, enrollment forms, change forms, COBRA forms, Weekly Income forms, Flex claim forms, etc.) are kept in our office areas, which is protected by locking mechanisms on all doors. All GISC computers / server are protected behind a Sonicwall Firewall. Due to our business requirements, GISC’s employees need access to personal information which is contained in the documents that we process for our clients. In order to ensure that none of this information is vulnerable to a breach, we have implemented the following policies: a. Employee Training [201 CMR 17.03 (b)(i)] All employees are responsible for maintaining the privacy and integrity of personal information. Any paper record containing personal information about any employee, client, insured or third party individual must be kept behind lock and key when not in use. Any computer containing personal information about any employee, client, insured or third party individual will be kept password protected. No personal information is to be disclosed without fully authenticating the receiving party. When disposing of paper records containing personal information, a paper shredding disposal container will be used as provided by a shredding service. The containers are strategically placed throughout the office and are emptied by the shredding service on a monthly basis. Our appointed information security coordinator, Karen Sealund, is responsible for training all new employees on this policy and insures periodic reviews for existing employees. WHAT IS SENSITIVE INFORMATION? Sensitive information is information that is not lawfully available to the public and could be used to damage our employees, insureds/members of our clients, or our business.

Products & services

Similar companies nearby