1. Purpose and Scope
This Data Security Policy establishes the standards and practices Appalachian Insights and Analytics, LLC ('AIA') uses to protect the confidentiality, integrity, and availability of data in our care. This policy applies to all AIA personnel, contractors, and systems that handle organizational, client, research participant, or federal data.
2. Data Classification
Level 1 — Public
Information approved for public release (website content, published reports, marketing materials). No special handling required.
Level 2 — Internal
Business information not intended for public release (financial records, contracts, operational documents). Store securely; do not share externally without authorization.
Level 3 — Confidential
Client data, proprietary research findings, personally identifiable information (PII). Restricted access; encrypted storage and transmission required.
Level 4 — Restricted / Sensitive
Federal agency data, human subjects research data, protected health information (PHI), and data subject to federal data use agreements. Highest protection standards apply, governed by applicable federal regulations including FISMA and HIPAA where applicable.
3. Data Storage and Access Controls
- All Level 3 and Level 4 data must be stored in encrypted, access-controlled systems
- Google Workspace is the primary document storage platform — access limited to authorized AIA personnel
- Passwords must be unique, strong (minimum 12 characters), and managed using a password manager
- Multi-factor authentication (MFA) is required for all Google Workspace accounts and financial systems
- Client and research data may not be stored on personal devices without encryption
4. Data Transmission
- Sensitive data must be transmitted only via encrypted channels (HTTPS, TLS-encrypted email, or secure file transfer)
- Research participant data may not be transmitted via standard email without encryption or password protection
- Data sharing with clients and federal agencies must be governed by a signed Data Use Agreement (DUA)
5. Research Data Protections
- All human subjects research data is handled in accordance with applicable IRB protocols and informed consent requirements
- De-identified data must be maintained as de-identified — re-identification is prohibited unless authorized by IRB
- Survey platforms must be configured with appropriate access controls and data retention settings
- Participant data must be retained for the period required by the sponsoring agency or IRB, then securely destroyed
6. Incident Response
In the event of a suspected data breach or security incident, AIA will:
- Immediately contain the incident and preserve evidence
- Notify affected clients and federal agencies as required by contract and applicable law
- Document the incident, response actions, and lessons learned
- Notify research participants if their data was compromised, in accordance with IRB requirements
7. Training and Compliance
- All AIA personnel review this policy annually and upon onboarding
- Personnel handling federal data complete applicable security awareness training as required by agency contracts
- This policy is reviewed annually and updated to reflect changes in technology, regulations, and AIA operations