3
Page updated: August 2020
V. The Provider/Representative agrees to the following security requirements. All
computers that access Medi-Cal data must meet the following requirements, in addition
to any State and Federal required administrative, technical, physical, and organizational
safeguards:
A. Antivirus software. All workstations, laptops and other systems that access the
Medi-Cal website or process and/or store Medi-Cal Protected Health Information
(PHI) must install and actively use comprehensive anti-virus software solution with
automatic updates scheduled at least daily.
B. Patch Management. All workstations, laptops and other systems that access the
Medi-Cal Web site or process and/or store Medi-Cal PHI must have critical security
patches applied, with system reboot if necessary. There must be a documented
patch management process, which determines installation timeframe based on risk
assessment and vendor recommendations. At a maximum, all applicable patches
must be installed within 30 days of vendor release.
C. System Timeout. The systems that access the Medi-Cal website or process and/or
store Medi-Cal PHI must provide an automatic timeout, requiring re-authentication
of the user session. It is recommended that the automatic timeout be after no more
than 20 minutes of inactivity.
D. User Name and Password Controls. Systems that access the Medi-Cal website or
process and/or store Medi-Cal PHI should be accessed using a unique user name
and password combination. The user name must be promptly disabled, deleted, or
the password changed upon the transfer or termination of an employee with
knowledge of the password. Passwords are not to be shared. Passwords must be:
(1) At least eight characters, (2) A non-dictionary word, (3) Not be stored in
readable format on the computer, (4) Be changed every 90 days, preferably 60
days, (5) Be changed if revealed or compromised, and (6) Be composed of
characters from at least three of the following four groups from the standard
keyboard:
• Upper case letters (A-Z)
• Lower case letters (a-z)
• Arabic numerals (0-9)
• Non-alphanumeric characters (punctuation symbols)
E. Workstation/Laptop encryption. All workstations and laptops that access the Medi-
Cal website or process and/or store Medi-Cal PHI are recommended to be
encrypted using a FIPS 140-2 certified algorithm, which is 128-bit or higher, such
as Advanced Encryption Standard (AES); full disk encryption is recommended.
Part 1 – Medi-Cal Point of Service (POS) Network/Internet Agreement (PRO Pubs)
point
frm1 net