not,without prior written approval of the State,use for Grantee's own benefit,publish, copy,
<br /> or otherwise disclose to any third party, or permit the use by any third party for its benefit or
<br /> to the detriment of the State, any State Records, except as otherwise stated in this Grant
<br /> Award Letter. Grantee shall provide for the security of all State Confidential Information in
<br /> accordance with all policies promulgated by the Colorado Office of Information Security and
<br /> all applicable laws,rules,policies,publications,and guidelines including,without limitation:
<br /> (i)the most recently promulgated IRS Publication 1075 for all Tax Information, (ii)the most
<br /> recently updated PCI Data Security Standard from the PCI Security Standards Council for all
<br /> PCI, (iii)the most recently issued version of the U.S. Department of Justice, Federal Bureau
<br /> of Investigation, Criminal Justice Information Services Security Policy for all CJI, and (iv)
<br /> the federal Health Insurance Portability and Accountability Act for all PHI and the HIPAA
<br /> Business Associate Addendum attached to this Contract. Grantee shall immediately forward
<br /> any request or demand for State Records to the State's principal representative.
<br /> B. Other Entity Access and Nondisclosure Agreements
<br /> Grantee may provide State Records to its agents, employees, assigns and Subcontractors as
<br /> necessary to perform the Work, but shall restrict access to State Confidential Information to
<br /> those agents, employees, assigns and Subcontractors who require access to perform their
<br /> obligations under this Grant Award Letter. Grantee shall ensure all such agents, employees,
<br /> assigns, and Subcontractors sign nondisclosure agreements with provisions at least as
<br /> protective as those in this Grant, and that the nondisclosure agreements are in force at all
<br /> times the agent, employee, assign or Subcontractor has access to any State Confidential
<br /> Information. Grantee shall provide copies of those signed nondisclosure restrictions to the
<br /> State upon request.
<br /> C. Use, Security, and Retention
<br /> Grantee shall use, hold and maintain State Confidential Information in compliance with any
<br /> and all applicable laws and regulations in facilities located within the United States,and shall
<br /> maintain a secure environment that ensures confidentiality of all State Confidential
<br /> Information wherever located. Grantee shall provide the State with access, subject to
<br /> Grantee's reasonable security requirements,for purposes of inspecting and monitoring access
<br /> and use of State Confidential Information and evaluating security control effectiveness.Upon
<br /> the expiration or termination of this Grant, Grantee shall return State Records provided to
<br /> Grantee or destroy such State Records and certify to the State that it has done so, as directed
<br /> by the State. If Grantee is prevented by law or regulation from returning or destroying State
<br /> Confidential Information, Grantee warrants it will guarantee the confidentiality of, and cease
<br /> to use, such State Confidential Information.
<br /> D. Incident Notice and Remediation
<br /> If Grantee becomes aware of any Incident,it shall notify the State immediately and cooperate
<br /> with the State regarding recovery,remediation,and the necessity to involve law enforcement,
<br /> as determined by the State. After an Incident, Grantee shall take steps to reduce the risk of
<br /> incurring a similar type of Incident in the future as directed by the State, which may include,
<br /> but is not limited to,developing and implementing a remediation plan that is approved by the
<br /> State at no additional cost to the State.
<br /> 11. CONFLICTS OF INTEREST
<br /> Grantee shall not engage in any business or activities,or maintain any relationships that conflict in
<br /> any way with the full performance of the obligations of Grantee under this Grant. Grantee
<br /> Contract No.CTGG1 2018-1918 Page 6 of 9 Version 0717
<br />
|