DESCRIPTION OF TRANSFER Categories of data subjects whose personal data is transferred Categories of personal data transferred Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). Nature of the processing Purpose(s) of the data transfer and further processing The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
Federal Medicaid System Security Requirements Compliance Party shall provide a security plan, risk assessment, and security controls review document within three months of the start date of this Agreement (and update it annually thereafter) in order to support audit compliance with 45 CFR 95.621 subpart F, ADP System Security Requirements and Review Process.