AR-08-727 Accounting of Disclosures

Accounting of Disclosures

AR-08-727
Accounting of Disclosures
Accountability, Audit and Risk Management
Identify
Privacy and Confidentiality
NOT SELECTED
NA
No
Laws and regulations are violated as a result of inaccurate accounting practices of disclosures of information
The organization: a. Keeps an accurate accounting of disclosures of information held in each system of records under its control, including: (1) Date, nature, and purpose of each disclosure of a record; and (2) Name and address of the person or agency to which the disclosure was made; b. Retains the accounting of disclosures for the life of the record or five years after the disclosure is made, whichever is longer; and c. Makes the accounting of disclosures available to the person named in the record upon request.
Potential records are maintained, and a custodian of these records is identified.
No statewide control
Obtain data privacy policy and procedures; other relevant documents or records and ascertain if: (I) the organization maintains records of disclosures of information held in each system of records under its control, including: (a) Date, nature, and purpose of each disclosure of a record; and (b) Name and address of the person or agency to which the disclosure was made; (ii) the organization retains the records of disclosures for the life of the record or five years after the disclosure is made, whichever is longer; and (iii) the organization makes the records of disclosures available to the person named in the record upon request.