Educause Security Discussion mailing list archives

Re: Marketscore and Higher Ed


From: Mike Wiseman <mike.wiseman () UTORONTO CA>
Date: Fri, 7 Jan 2005 12:22:23 -0500

Mike, are you going to request a formal written statement from Marketscore
that states it is doing everything in your best interests to protect the
university data you are responsible for?

While it may look like they are meeting industry standards in privacy
protection, I am not comfortable with any public, sensitive, intellectual,
confidential university data traveling through any third party server for
which I have no specific formal written guarantee stating that it is doing
everything within all federal laws and regulations to protect the
information it gleans.

HIPAA requires a Business Associate Agreement.  Are you going to request one
from them? I know I'm reaching a bit far here, but I think it's important to
make such a point.


One of my main concerns regarding this Marketscore issue is the exposure that users and
services at my institution, up to now, have faced. We are in the process of formulating
policy and procedures to deal with this which will probably involve restriction of this
type of activity for the same reasons Theresa expresses. If it was found that Marketscore
did not adhere to standards that I know about, it would have made the situation more
worrisome.

Mike

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/groups/.

Current thread: