UNM's Qualtrics Platform Support Matrix specifies the data categories/elements that have been reviewed by UNM’s Information Security and Privacy Office and UNM data stewards that can be captured in Qualtrics. It is your responsibility to ensure that the data collected in Qualtrics has been reviewed for storage on the platform. UNM recommends that researchers consider what data is already collected and accessible in UNM enterprise systems so that survey respondents are not asked to re-enter data that UNM already has.
By using the Qualtrics system you acknowledge your responsibility to work in compliance with the recommendations included in the support matrix, any applicable protocols (such as IRB), any data use agreements, and all applicable UNM policies in your use of the Qualtrics system and the management and use of collected data both within and outside of the Qualtrics platform.
Qualtrics Sensitive Data Guide
These reviews do not reduce your responsibility as a user of this system for managing, transferring, storing, sharing, retaining, preserving, and destroying all data collected through these or in outside systems in a manner consistent with the requirements of UNM’s data classification system, and associated policies.
Data Characteristics | Recommended Platform | ||
---|---|---|---|
Classification Level | Sample Data Elements | Qualtrics
Recommended Not Recommended No specific guidance – check with UNM office(s) | Generic System |
"E Class" (Encrypted) | |||
Student Military Records | ISPO |
| |
Student Medical Records | ISPO | ||
Social Security Number (or part of SSN) | ISPO | ||
Protected Health Information (eg)
| ISPO | ||
Employee Benefits File | ISPO Data Stewards | ||
Employee Health Records | ISPO Data Stewards | ||
Protected Payroll and Health Benefits Deduction Information | ISPO Data Stewards | ||
Banking Information | ISPO Data Stewards | ||
Tax Information | ISPO Data Stewards | ||
Human Subjects Research Data - Including PII | ISPO Institutional Review Board | ||
Data subject to ITAR restrictions | ISPO Industrial Security | ||
“C Class” (Confidential) | |||
Payroll File (not in “E Class” above) | ISPO Data Stewards |
| |
Personnel File (not in “E Class” above) | ISPO Data Stewards | ||
Employment Transactions | ISPO Data Stewards | ||
Research Proposals | ISPO Data Stewards | ||
Work in Progress Budgets | ISPO Data Stewards | ||
PCard Number | ISPO Data Stewards | ||
Employee Address | ISPO Data Stewards | ||
Confidential Student Information
| ISPO Data Stewards | ||
Human Subjects Research Data - Anonymized | ISPO Institutional Review Board | ||
Research data not subject to more restrictive controls that have not otherwise been published or publicly shared | ISPO Data Stewards | ||
Community member information
| ISPO Data Stewards | ||
Data related to unfiled or pending patents | ISPO UNM Rainforest Innovations | ||
“P Class” (Public) | |||
Records accessible pursuant to NM IPRA | ISPO Data Stewards |
| |
Sunshine portal data | ISPO Data Stewards | ||
Information on public web sites | ISPO Data Stewards | ||
Employee Information classified as “directory information”
| ISPO Data Stewards | ||
Student information classified as “directory information”
| ISPO Data Stewards |
Sample data elements added beyond those in the current online data classification
Related UNM Policies
- https://hsc.unm.edu/ctsc/services/informatics/about-redcap.html
- http://data.unm.edu/data-classification.html
- https://policy.unm.edu/university-policies/2000/2580.html
- Data Governance
- UAP 2500 (“Acceptable Computer Use”)
- UAP 2520 (“Computer Security Controls and Access to Sensitive and Protected Information”)
- UAP 2550 (“Information Security”)
- UAP 2560 (“Information Technology Governance”)
- Information Technology Standard for UNM Data Classification
- UNM Sensitive Information Stewardship and Confidentiality Statement
- HSC-230 “Electronic Data Storage and Transmission”
- HSC-300 “ePHI Security Compliance”
- HIPAA “Use and Disclosure of Protected Health Information Policy”
- HIPAA “Responding to Breaches of Protected Health Information _PHI) Policy
- HIPAA “Right to Access of Protected Health Information by the Patient Policy
- HIPAA “Right to Request to Amend Designated Record Set Policy”