#  Additional Guidance 

 



   ![Person standing on wooden step stool in library](/sites/g/files/omnuum12036/files/styles/hwp_1_1__360x360_scale/public/2026-07/extrasteps.jpeg?itok=UvQ-oWqC) 

 

## When Sensitive Data Needs Extra Steps

Sometimes contracts, laws, university rules, or system limits mean we have to use extra or different protections than our usual standards.

This is especially true for certain kinds of information, like health or financial data, which have additional legal requirements beyond just keeping an asset secure.

On this page, you’ll find explanations and guidance to help you recognize when additional or different protections are required and understand how to handle those situations correctly.



 

##  Lifecycle Protection Beyond Minimum Standards 

Some university data, systems, and services require protection beyond the university Minimum Standards throughout its full lifecycle, from acquisition to secure destruction.

 

 



  Open all sections   Close all sections  



###    Protected health information (PHI)  expand\_more  

[HIPAA](https://www.hhs.gov/hipaa/for-professionals/index.html) regulates the security and privacy of patient data, including clinical records and treatment information. Harvard is a HIPAA hybrid entity, meaning that some parts of the organization are “covered functions” directly subject to HIPAA.  
  
While the DSL4 security controls align with the minimum requirements of the HIPAA Security Rule, [numerous additional operational and administrative controls are required](https://healthit.gov/wp-content/uploads/2017/09/privacy-and-security-guide.pdf) to satisfy both the HIPAA Security and Privacy rules, and the regulation’s compliance requirements.   
  
Seek compliance guidance from the relevant Privacy officer at your covered entity.

 

 



###    Payment-card information (PCI)  expand\_more  

Payment card information is regulated by the PCI Data Security Standard ([PCI DSS](https://www.pcisecuritystandards.org/standards/pci-dss/)), a baseline of operational, administrative and technical controls for payment card account security.

Harvard’s [Office of Treasury Management](https://otm.finance.harvard.edu/2026-pci-compliance-certification-departments-accept-credit-cards) publishes PCI compliance guidance and manages the annual compliance certification required for all Harvard entities that accept credit card payments.

 

 



###    Federal Contract Information (FCI)  expand\_more  

As defined in [section 4.1901](https://www.acquisition.gov/far/4.1901) of the Federal Acquisition Regulation (FAR), FCI is “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, excluding information provided by the Government to the public (such as that on public websites) or simple transactional information, such as that necessary to process payments” and applies to information residing in or transiting through an information system.

Seek guidance from the [Office of the Vice Provost for Research](https://research.harvard.edu/research-policies-compliance/research-data-management/) before executing federal contracts including the Safeguarding Clause 48 CFR 52.204-21 *Basic Safeguarding of Covered Contractor Information Systems*.

Cybersecurity Maturity Model Certification (CMMC) Level 1 focuses on basic cyber hygiene and the protection of federal contract information (FCI).

See also: [University Research Computing and Data (Univ RCD) Service](https://rc.harvard.edu/services/regulated-data-services-user-guide/)

 

 



###    Controlled Unclassified Information (CUI)  expand\_more  

CUI is a broad category of federal data that must be safeguarded in accordance with the NIST Special Publication 800-171 *Protecting CUI in in Nonfederal Systems and Organizations*. Additionally, 32 CFR Part 2002 governs CUI handling.

Cybersecurity Maturity Model Certification (CMMC) Level 2 focuses on the protection of CUI. It includes the controls specified in NIST SP 800-171.

Seek guidance from the [Office of the Vice Provost for Research](https://research.harvard.edu/research-policies-compliance/research-data-management/) before executing contracts or research agreements with federal requirements, particularly if:

- Your sponsor designates certain data as CUI or subject to NIST controls.
- Your solicitations or contracts include references to:
    
    
    - NIST 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    - 32 CFR 2002 Controlled Unclassified Information
    - 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    - 252.204-7008 Compliance with safeguarding covered defense information controls
    - 252.204-7012 Safeguarding covered defense information and cyber incident reporting
    
    See also: [University Research Computing and Data (Univ RCD) Service](https://rc.harvard.edu/services/regulated-data-services-user-guide/)

 

 



###    Criminal Justice Information Services (CJIS) Security Policy (CGISSECPOL)  expand\_more  

The CJIS Security Policy is informed by presidential and FBI directives, federal laws, state laws, decisions made by the criminal justice community's Advisory Policy Board (APB), and National Institute of Standards and Technology (NIST) and has both a security and a compliance component.

The release of criminal offender record information (CORI) for research purposes may also be subject to Department of Criminal Justice Information Services regulations at the state level, such as MA 803 CMR.

Seek guidance from the [Office of the Vice Provost for Research](https://research.harvard.edu/research-policies-compliance/research-data-management/) before executing Data Use Agreements for criminal justice data with CJIS/DCJIS or MA 803 CMR terms.

 

 



###    Family Educational Rights and Privacy Act (FERPA)  expand\_more  

FERPA is a regulation that protects the privacy of students and parents under section 444 of the General Education Provisions Act, as amended. It applies to [education records](https://studentprivacy.ed.gov/ferpa), including “directory information” and determines how that information may be shared. Before disclosing any student information, review the [university’s FERPA overview ](https://provost.harvard.edu/sites/g/files/omnuum12476/files/provost/files/ferpa_overview.pdf) to determine if the “legitimate educational interest” bar is met and consult with the relevant school Registrar to determine and determine if any “FERPA blocks” apply to the data in scope.

 

 



###    GDPR, PIPL and Other Privacy Regulations  expand\_more  

Numerous comprehensive privacy regulations stipulate data protection requirements that differ based on the type of personally identifiable data collected, where data subjects are located when the data is collected, and how that data may be utilized. Examples:

- *General Data Protection Regulation* ([GDPR](https://gdpr-info.eu/)) formally known as EU Regulation 2016/679
- *Personal Information Protection Law (PIPL), China’s* comprehensive personal information and data privacy legislation.

In the U.S., data privacy requirements are shaped by state laws and regulatory enforcement rather than a single federal framework.

Individuals protected by these and other similar regulations have data subject’s rights, such as choice and control over their personal information, and the right to erasure. Entities collecting data from data subjects with such protections must be prepared to safeguard the collected data in accordance with the relevant regulatory framework and must be able to respond to data subject’s rights requests.

The [University Wide Privacy Principles](https://privsec.harvard.edu/privacy-principles) should be incorporated into all processes involving personal information, including new and existing business operations, and human subjects research.

Consult with OGC if necessary to clarify regulatory obligations prior to data collection.

 

 



 

 

 

 

 

##  Related Resources 

Use these resources to take the next step, find University guidance, or explore trusted external references.

 

 



 ### University Policies

Official University policies and governance guidance.

- [University Information Security Policy](/information-security-policy-archived "Information Security Policy - Archived")
- [OVPR Research Data Management and Policy Compliance Resources](https://research.harvard.edu/research-policies-compliance/research-data-management/)
- [General Records Schedule](https://library.harvard.edu/services-tools/general-records-schedule) (GRS)



 

 ### University Standards

Security and privacy requirements for protecting University information.

- [Risk Classification](https://privsec.harvard.edu/classify-risk)
- [Minimum Standards](/apply-standards "Minimum Standards")
- [Data Handling](https://privsec.harvard.edu/shield-data)



 

 ### Roles &amp; Responsibilities

Role-based guidance for supporting a secure University environment.

- [Community Members](/community-members-responsibilities "Community Members Responsibilities")
- [System or Service Custodian](/system-administrators-responsibilities "System or Service Custodian Responsibilities")
- [Data Stewards](/data-stewards-best-practices "Data Stewards Best Practices")