Storing Restricted and Sensitive Data in Box @ UNH

Box @ UNH provides enhanced security via SSL connection and encryption of data at rest; however, some data is inappropriate for storage in Box @ UNH as well as most university general use servers and fileshares.

  • UNH Data Classifications and Storage

    • Public Data (1 lock): No restrictions on storage in Box @ UNH.
    • Sensitive data (2 lock): No restrictions on storage in Box @ UNH
    • Restricted (legally protected) data (3 locks): Certain information should not be stored in Box @ UNH. Contact UNH ISS for appropriate solutions.
  • Don't store unnecessary data:

    • Scan existing files with Identity Finder before transfer to Box @ UNH to locate SSN's and credit card numbers.
    • Old and outdated files no longer useful (e.g., "just in case")
    • No business need for the data (or obsolete business need).
    • Legal exposure; data is discoverable in lawsuits.
    • Define and use a record retention policy (USNH Policy)
  • Box @ UNH not accepted nor recommended for:

    • Protected health information (PHI) subject to HIPAA/HITECH regulations
      • Understand "cover entity"
      • PHI not covered by HIPAA still must be protected
    • Credit Card information
      • Customer data; does not apply to P-Cards
      • Policy, not law
    • Export controlled research data
      • Sharing risk
  • Be wary of using Box Sync when storing restricted data.

    • Places inappropriate information on local devices
    • Use only with encrypted devices when storing restricted data
Custom Fields
  • Application: Box@UNH
  • Department: Enterprise Collaboration & Messaging
Attached Files
There are no attachments for this article.
Related Articles RSS Feed
Box Drive Lock Feature Available
Viewed 1019 times since Mon, Feb 26, 2018
How to Determine if Your Windows Device is Automatically Updating
Viewed 718 times since Thu, Nov 2, 2017
Box@UNH Resources
Viewed 24 times since Wed, Jan 30, 2019
Updating Box Collaborators
Viewed 227 times since Wed, Jul 25, 2018
SEED: Accepted Equipment List & Disposal Guide
Viewed 3173 times since Tue, Apr 28, 2015
PCI DSS - Payment Card Security
Viewed 2365 times since Thu, May 7, 2015
Find sensitive data before the bad folks do!
Viewed 1170 times since Mon, Jun 27, 2016
Box Drive - Known Limitations
Viewed 34 times since Wed, Jan 30, 2019
Using Favorites in Box@UNH
Viewed 780 times since Wed, Mar 8, 2017
Box: Creating Shareable Links
Viewed 398 times since Tue, Mar 6, 2018