5.1

Table Of Contents
n
US Social Security Number
Patient Identification Numbers
The personally identifiable information (PII) commonly held by hospitals and healthcare-related organizations
and businesses in the United States of America. This policy should be customized to define the patient
identification number format.
The policy looks for at least one match to personally identifiable information, which may include:
n
Patient Identification Numbers
n
US National Provider Identifier
n
US Social Security Number
Payment Card Industry Data Security Standard (PCI-DSS)
The PCI DSS, a set of comprehensive requirements for enhancing payment account data security, was
developed by the founding payment brands of the PCI Security Standards Council, including American
Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. Inc.
International, to help facilitate the broad adoption of consistent data security measures on a global basis.
The PCI DSS is a multifaceted security standard that includes requirements for security management, policies,
procedures, network architecture, software design and other critical protective measures. This comprehensive
standard is intended to help organizations proactively protect customer account data.
The policy looks for at least one match to either of the content blades:
n
Credit Card Number
n
Credit Card Track Data
Texas SB-122
Texas SB-122 is a state data privacy law which protects personally identifiable information. Texas SB-122 was
signed into law June 17, 2005 and became effective September 1, 2005. The law applies to any person that
conducts business in Texas and owns or licenses unencrypted computerized data that includes personally
identifiable information.
The policy looks for at least one match to personally identifiable information, which may include:
n
Credit Card Number
n
Credit Card Track Data
n
US Drivers License Number
n
US Social Security Number
UK BIC Numbers
A Bank Identifier Code (BIC) uniquely identifies a particular bank and is used in the UK and worldwide for
the exchange of money and messages between banks. The policy identifies documents and transmissions that
contain BIC codes, also known as SWIFT codes, issued by the Society for Worldwide Interbank Financial
Telecommunication (SWIFT).
The policy looks for a match to the content blade UK BIC Number.
Chapter 15 vShield Data Security Management
VMware, Inc. 195