Notification to CDPH of Breach or Security Incident. The Participant shall notify CDPH immediately by telephone call plus email or fax upon the discovery of a breach (as defined in this Agreement), or within twenty-four (24) hours by email or fax of the discovery of any security incident (as defined in this Agreement). Notification shall be provided to the CDPH Program Manager, the CDPH Privacy Officer and the CDPH Chief Information Security Officer, using the contact information listed in Section XIV(G), below. If the breach or security incident occurs after business hours or on a weekend or holiday and involves CalREDIE Data in electronic or computerized form, notification to CDPH shall be provided by calling the CDPH IT Service Desk at the telephone numbers listed in Section XIV(G) below. For purposes of this Section, breaches and security incidents shall be treated as discovered by Participant as of the first day on which such breach or security incident is known to the Participant, or, by exercising reasonable diligence would have been known to the Participant. Participant shall be deemed to have knowledge of a breach or security incident if such breach or security incident is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach or security incident, who is a workforce member or agent of the Participant. Participant shall take: 1. prompt corrective action to mitigate any risks or damages involved with the breach or security incident and to protect the CalREDIE System operating environment; and 2. any action pertaining to a breach required by applicable federal or state laws, including, specifically, California Civil Code section 1798.29.
Appears in 1 contract
Samples: Data Use and Disclosure Agreement
Notification to CDPH of Breach or Security Incident. The Participant shall notify CDPH immediately by telephone call plus email or fax upon the discovery of a breach (as defined in this Agreement), or within twenty-four (24) hours by email or fax of the discovery of any security incident (as defined in this Agreement). Notification shall be shallbe provided to the CDPH Program Manager, the CDPH Privacy Officer and the CDPH Chief Information Security Officer, using the contact information listed in Section XIV(G), below. If the breach or security incident occurs after business hours or on a weekend or holiday and involves CalREDIE CalConnect Data in electronic or computerized form, notification to CDPH shall be provided by calling the CDPH IT Service Desk at the telephone numbers listed in Section XIV(G) ),), below. For purposes of this Section, breaches and security incidents shall be treated as discovered by Participant as of the first day on which such breach or security incident is known to the Participant, or, by exercising reasonable diligence would have been known to the Participant. Participant shall be deemed to have knowledge of a breach or security incident if such breach or security incident is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach or security incident, who is a workforce member or agent of the Participant. Participant shall take:
1. prompt corrective action to mitigate any risks or damages involved with the breach or security incident and to protect the CalREDIE CalConnect System operating environment; and,
2. any action pertaining to a breach required by applicable federal or state laws, including, specifically, California Civil Code section 1798.29.
Appears in 1 contract
Samples: Cost Reimbursable Agreement
Notification to CDPH of Breach or Security Incident. The Participant shall notify CDPH immediately by telephone call plus email or fax upon the discovery of a breach (as defined in this Agreement), or within twenty-four (24) hours by email or fax of the discovery of any security incident (as defined in this Agreement). Notification shall be provided to the CDPH Program Manager, the CDPH Privacy Officer and the CDPH Chief Information Security Officer, using the contact information listed in Section XIV(G), below. If the breach or security incident occurs after business hours or on a weekend or holiday and involves CalREDIE CalCONNECT Data in electronic inelectronic or computerized form, notification to CDPH shall be provided by calling the CDPH IT Service Desk at the telephone numbers listed in Section XIV(G) ),), below. For purposes of this Section, breaches and security incidents shall be treated as treatedas discovered by Participant as of the first day on which such breach or security incident is known to the Participant, or, by exercising reasonable diligence would have been known to the Participant. Participant shall be deemed to have knowledge of a breach or security incident if such breach or security incident is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach or security incident, who is a workforce member or agent of the Participant. Participant shall take:
1. prompt corrective action to mitigate any risks or damages involved with the breach or security incident and to protect the CalREDIE CalCONNECT System operating environment; and,
2. any action pertaining to a breach required by applicable federal or state laws, including, specifically, California Civil Code section 1798.29.
Appears in 1 contract
Samples: Data Use and Disclosure Agreement
Notification to CDPH of Breach or Security Incident. The Participant shall notify CDPH immediately by telephone call plus email or fax upon the discovery of a breach (as defined in this Agreement), or within twenty-four (24) hours by email or fax of the discovery of any security incident (as defined in this Agreement). Notification shall be provided to the CDPH Program Manager, the CDPH Privacy Officer and the CDPH Chief Information Security Officer, using the contact information listed in Section XIV(GXX(G), below. If the breach or security incident occurs after business hours or on a weekend or holiday and involves CalREDIE Data in electronic or computerized form, notification to CDPH shall be provided by calling the CDPH IT Service Desk at the telephone numbers listed in Section XIV(G) XX(G),), below. For purposes of this Section, breaches and security incidents shall be treated as discovered by Participant as of the first day on which such breach or security incident is known to the Participant, or, by exercising reasonable diligence would have been known to the Participant. Participant shall be deemed to have knowledge of a breach or security incident if such breach or security incident is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach or security incident, who is a workforce member or agent of the Participant. Participant shall take:
1. prompt corrective action to mitigate any risks or damages involved with the breach or security incident and to protect the CalREDIE System operating environment; and,
2. any action pertaining to a breach required by applicable federal or state laws, including, specifically, California Civil Code section 1798.29.
Appears in 1 contract
Samples: Data Use and Disclosure Agreement
Notification to CDPH of Breach or Security Incident. The Participant shall notify CDPH immediately by telephone call plus email or fax upon the discovery of a breach (as defined in this Agreement), or within twenty-four (24) hours by email or fax of the discovery of any security incident (as defined in this Agreement). Notification shall be provided to the CDPH Program Manager, the CDPH Privacy Officer and the CDPH Chief Information Security Officer, using the contact information listed in Section XIV(GXII(G), below. If the breach or security incident occurs after business hours or on a weekend or holiday and involves CalREDIE Cal-IVRS Data in electronic or computerized form, notification to CDPH shall be provided by calling the CDPH IT Service Desk at the telephone numbers listed in Section XIV(G) XII(G), below. For purposes of this Section, breaches and security incidents shall be treated as discovered by Participant as of the first day on which such breach or security incident is known to the Participant, or, by exercising reasonable diligence would have been known to the Participant. Participant shall be deemed to have knowledge of a breach or security incident if such breach or security incident is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach or security incident, who is a workforce member or agent of the Participant. Participant shall take:
1. prompt Prompt corrective action to mitigate any risks or damages involved with the breach or security incident and to protect the CalREDIE Cal-IVRS System operating environment; and,
2. any Any action pertaining to a breach required by applicable federal or state laws, including, specifically, California Civil Code section 1798.29.
Appears in 1 contract
Samples: Data Privacy & Security Agreement