Procedure 5.6.2: Confidentiality and Security of Student Information Campus-wide Procedures
Effective Date: Tue, Aug 12, 2008
Each area of the campus that handles student records should establish procedures to protect the security and confidentiality of student information, including hard copy and digital formats. NC Administrative Code and General Statutes, FERPA, Federal Financial Aid Guidelines, and other state and federal guidelines must be followed in handling student information and should be addressed in the procedures for each area. The following guidelines must be followed when accessing confidential information and student records.
Hard copy data
- Student information with social security numbers and birth dates is not to be placed on hard copy file folder labels (use student ID instead)
- Student information with social security numbers and birth dates should not be left unattended on personnel desks in which inappropriate people may have access.
- File folders (hardcopies) containing student information with social security numbers and birth dates must be kept under lock and key with access only by appropriate personnel.
- Any documents containing student information that is confidential should be shredded before discarding.
Electronic data
- Electronic student and confidential information is only accessible to appropriate personnel in accordance with policies and procedures approved by the Information Technology Services Office.
- Access to information systems is only given to appropriate personnel upon written permission by a staff member’s supervisor. Permission records will be maintained by the ITS office.
- Personnel who have been granted authority to access student information will be issued an ID and password by the ITS office to access information systems.
- Each staff member is only to use his/her designated ID and password to access student and confidential information. Under no circumstances should an ID and password be shared or should a staff member access HCC information systems under an ID and password that has not been issued to him or her.
- Student information with social security numbers and birth dates is not to be distributed or transmitted through email or posted on networks.
- The student ID generated by the college operating system will be used in place of the social security number for identification purposes and in all communications.
- Student social security numbers or birth dates may not be used for access to student records/email accounts, etc, only the student ID.
- ITS reserves the right to revoke all privileges to information systems if HCC Information Technology policies and procedures are not followed.
Student communications
- Students are required to create a unique password upon setting up their accounts in HCC information systems (such as Haywired, WebAdvisor, email, etc.)
- When communicating with students regarding technical support, registration, transcripts, financial aid, and financial information, students should not be asked for a social security number or birth date, in public/within hearing distance of other people.
- Two forms of authentication must be requested when verbally verifying student identification. Appropriate forms of authentication are the student Colleague ID number, the last four digits of the social security number and birth date. Under no circumstances should a student be requested to verify his/her social security number through email.
Up one level

