Classification System
UAB IT worked closely with information security officials from UAB Health System to develop the three level data classification system for all data. This system establishes roles and responsibilities for those individuals and groups who will safeguard and use UAB data. Many of the policies and guidelines established to support this classification system are required by federal law and UAB must remain compliant.
What’s your data?
Public Data
Public data is data that can be disclosed to the general public without harm.
Examples of public data include phone directory information, course catalogs, public research findings, enrollment figures, public web sites, general benefits data, press releases, newsletters and other similar information.
Sensitive Data
Sensitive data is data that should be kept confidential, with access requiring authorization or legitimate need-to-know involvement.
Examples of sensitive data include FERPA information, budgetary plans, proprietary business plans, patent pending information, export controls information and data protected by law.
Restricted/PHI data
Restricted/PHI data is sensitive data that is highly confidential in nature, and carries significant risk from unauthorized access. Privacy and security controls are typically required by law or contract for this data.
Examples include Social Security numbers, credit card numbers (PCI), personally identified information, protected health information, GLBA data, export controlled data, FISMA regulated data, login credentials, and information protected by non-disclosure agreements. Fill out the Risk Assessment form for more information.
Can you store or share data?
See the table below for guidance on how you can store and transmit data. Electronic storage and emailing of credit card numbers is never allowed.
| Public | Sensitive | Restricted/PHI | |
|---|---|---|---|
| UABFile Share | |||
| Desktop C Drive | password required; encryption optional. |
||
| Laptop C Drive | password required; encryption optional. |
password/pin and encryption required. |
|
| UAB Box | Risk assessment required. |
||
| UAB M365 | |||
| Personal accounts | |||
| Thumb Drive | encryption required. |
||
| Mobile Device | device password/pin and encryption required. |
device password/pin and encryption required. |
|
| UAB Email | only to uab.edu or uabmc.edu email addresses. |
only to uab.edu or uabmc.edu email addresses. |
|
| UABMC Email | only to uab.edu or uabmc.edu email addresses. |
requires third-party encryption tool to send externally. |



