• HMIS/Comparable Security Officer Agreement

    HMIS/Comparable Security Officer Agreement

  • From the Dallas & Collin County CoC Data Systems Operating Policies and Procedures:

    Each Partner Agency must designate a HMIS/Comparable Database Security Officer. The Security Officer serves as the agency’s primary point of contact for system security, privacy, and ethics within the Dallas & Collin County CoC Data Systems. The Security Officer is responsible for monitoring and supporting these functions across the agency’s HMIS/Comparable Database projects.

  • Please select your organization:

  • The Security Officer will:

    • Serve as the primary liaison between the Partner Agency and CoC Data Systems administrators on matters related to privacy, security, ethics, and system access.
    • Ensure and monitor the technical security of the agency’s access to the CoC Data Systems, including internet connectivity, firewall protection on all networks, anti-virus software, and weekly system scans, either directly or with the assistance of a technical professional.
    • Ensure all end users complete required privacy, security, and ethics training prior to and during system access.
    • Monitor agency compliance with data security standards and approved methods for electronically transmitting client Personal Protected Information (PPI) as detailed in the Housing Forward Privacy, Security, and Ethics training.
    • Monitor and enforce compliance with client privacy notices, including ensuring the Privacy Notice is posted and visible to all clients.
    • Receive and disseminate security-related communications from the CoC Data Systems team to appropriate agency staff.
    • Monitor and enforce compliance with ethical data collection, entry, and retrieval practices.
    • Ensure agency users log in at least once per month by monitoring user activity and account access. Accounts inactive for 60 days will be locked; 90 days of inactivity requires refresher training, and 6 months or more of inactivity requires full New User Training.
    • Immediately notifying the appropriate Data System Lead(s) when an end user is no longer with the agency, including the systems from which access should be removed.
  • Agency Security Officer Contact Information

  • Clear
  • Should be Empty: