Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Utah Population Database reports strong NIST SP 800‑171 compliance; committee asks for privacy follow‑up
Summary
UPDB officials reported results of a biennial internal audit against NIST SP 800‑171: 94 of 97 checklist items were fully implemented; three items need improvement (two low risk, one moderate), and no high or critical risks were found. Committee members and participants raised privacy and removal concerns; UPDB explained
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Nicola Kemp, director of the Utah Population Database (UPDB) at the University of Utah, presented the results of the biennial internal security audit required for recipients of certain datasets. UPDB reported it follows NIST SP 800‑171 controls and that the audit reviewed 97 items: 94 were fully implemented and effective, two items were classified low risk and one item moderate risk; none were high or critical.
Kemp described UPDB’s role at the Huntsman Cancer Institute supporting biomedical research, noted the unique genealogical resources UPDB provides and said the audit uses a system security plan tied to NIST guidance and a Plan of Action and Milestones (POAM) to track remediation. She said the single moderate‑risk item is on track to be resolved before year‑end and the other two items shortly thereafter.
Committee members and members of the public raised privacy and deletion questions. UPDB and University compliance staff explained opt‑out options for driver‑license data (an individual can opt out at the Driver License Division to prevent future transmissions; if the data were already ingested UPDB can remove it after verification), and emphasized that datasets released to researchers are de‑identified. University staff said removing an individual entirely from the database is operationally difficult because UPDB ingests data from multiple sources and some analyses rely on genealogical linkages; they offered to return with a follow‑up on how UPDB implements the Government Data Privacy Act and to provide written materials explaining opt‑out and data governance procedures.
The committee requested a written follow‑up on UPDB’s compliance with the Government Data Privacy Act and said staff would consider a future presentation to address outstanding privacy and subject‑access questions.
