Table of Contents
Add Health Data Security
This page is designed to be used as a reference for the policies and restrictions that govern the access to and use of Add Health Restricted-Use Data that is hosted at University of California, Irvine. It does not cover the entirety of the Restricted-Use Data Hosting Agreement. Users are responsible for reviewing and adhering to all relevant agreements and policies.
Privacy and Security Program
The Restricted-Use Data Hosting Agreement requires institutions to maintain a Privacy and Security Program which maps our security controls to the high protection obligation level requirements as defined in the UNC Information Security Controls Standard.
UNC Policies
UCOP & UCI Policies
Shared Responsibility Model
While there are many physical and technical security measures in place, security is a shared responsibility. All users of Add Health data must be aware of their responsibility to follow the above policies and maintain data security.
Below are summaries highlighting the main points for each area of responsibility.
Responsibility of Principal Investigator
- Ensuring that only approved and authorized users are added to the Add Health agreement and related Data Use Agreement.
- Ensuring that users understand the permitted uses and restrictions associated with Add Health Restricted-Use Data.
- Ensuring that users complete required onboarding and training before being granted access.
- Notifying system administrators when user access should be added, renewed, modified, or removed.
- Ensuring that research use remains consistent with the approved Add Health agreement, conditions of use, and any related IRB or data use requirements.
Responsibility of All Users
- Review and comply with the Add Health Conditions of Use.
- Complete UC Cyber Security Awareness Training annually
- Protecting credentials and never sharing accounts or passwords.
- Accessing the data only for approved purposes.
- Not attempting to identify, locate, contact, or re-identify individuals represented in the data.
- Protecting their endpoint systems and work areas from unauthorized access or disclosure.
- No unauthorized copying or sharing of data.
- Prompt reporting of suspected security incidents.
Responsibility of System Administrators
- Maintaining the operating system, software, access controls, firewall rules, encryption, logging, backups, monitoring, and other technical safeguards.
- Annually extending the expiration date of user accounts that are authorized to maintain access to the data.
- Applying patches and responding to vulnerabilities.
- Maintaining administrative records such as access changes and system changes.
- Supporting UCI and UNC incident response activities.
Onboarding procedure
When a new user is confirmed and approved by the PI:
- Notify System administrators, who will create the user account
- Authentication can be configured for new user accounts one of two ways:
- Provide an SSH key to socit@uci.edu
- Schedule an on-boarding meeting (virtual or in-person) during which a password and MFA token will be configured.
- Accounts will be set to expire after 1 year. Annual confirmation of current active users is required to re-enable accounts.
UCI Add Health server details
| Hostname | addhealth.socsci.uci.edu |
|---|---|
| IP address | 128.195.247.155 |
| Access Protocols | SSH |
| Session timeout | 30 minutes |
Firewall Restrictions: Allowed Network Access
Only connections from on-campus or from the Cisco AnyConnect VPN will be allowed to connect to the server. If you are off-campus or on a UCI-WiFi network, you must first connect to the VPN before attempting to connect to the Add Health server.
Firewall restrictions in place on the server only allow connections from these subnets:
| Subnet name | CIDR |
|---|---|
| Campus Network 128.195 | 128.195.0.0/16 |
| Campus Network 128.200 | 128.200.0.0/16 |
| VPN | 172.23.0.0/20 |
Maintenance and Backup Schedule
| Maintenance/Security updates | Monthly, on the 1st Monday, 9am-11am |
|---|---|
| Full System Backup | Weekly on Sunday |
| Differential file-level backup | Nightly |
