Data Handling & Classification
Not all data is created equal. Learn to classify data, handle it appropriately, avoid shadow IT risks, and prevent the most common data exposure mistakes.
What You Will Learn
Not all data is created equal. Patient records, client files, and financial data need more protection than a public newsletter. This module teaches you how to classify data, handle it appropriately, and avoid the most common data exposure mistakes.
- Data classification: public, internal, confidential, and restricted
- Handling rules: how to store, share, and dispose of each data type
- Shadow IT: the hidden risk of unapproved tools and apps
- Email mistakes: how to prevent the most common data exposure errors
- Industry examples: HIPAA, attorney-client privilege, grant data, and student records
Why Data Classification Matters
Data classification is the foundation of data privacy. When you know what type of data you are handling, you know how to protect it. Most data breaches in small organizations are not the result of sophisticated hacking. They are the result of someone sending the wrong file to the wrong person, storing sensitive data in the wrong place, or using an unapproved tool.
Quick Check
You need to send a patient intake form to a colleague. How should you send it?
The Four Data Classifications
Data Classification Levels
- Public: Information that is already available to the public. Examples: your website content, published brochures, press releases. No special handling required.
- Internal: Information meant for staff but not sensitive. Examples: staff directories, internal newsletters, meeting notes without sensitive topics. Share within the organization but not externally.
- Confidential: Sensitive information that could harm individuals or the organization if exposed. Examples: financial reports, contracts, vendor pricing, donor lists. Requires encryption, access controls, and secure sharing.
- Restricted: The most sensitive data. Exposure has legal, regulatory, or severe business consequences. Examples: patient records (PHI), attorney-client communications, student records, Social Security numbers, bank account details. Requires encryption, strict access controls, audit logging, and secure disposal.
Quick Check
A vendor asks you to email them a spreadsheet containing your organization’s bank account numbers and routing numbers for setting up payments. What classification is this data and how should you share it?
Handling Rules for Each Classification
- Public data: Store anywhere, share freely, no special disposal required.
- Internal data: Store on organization systems, share with staff only, standard disposal.
- Confidential data: Store with access controls, share through approved methods, shred or securely delete.
- Restricted data: Store encrypted with strict access controls, share only through approved encrypted channels, shred with cross-cut shredder or use certified data destruction.
Shadow IT: The Hidden Risk
Shadow IT is any software, app, or cloud service that staff use for work without IT approval. It is one of the biggest data exposure risks in small organizations. Common examples include personal Google Drive, Dropbox, personal email, and free online tools.
The risk is simple: when staff upload work files to personal cloud accounts, those files are outside your organization’s control. There is no encryption, no access logging, no IT oversight, and no way to recover or delete the data if the person leaves.
Quick Check
Your team needs a project management tool. A colleague signs up for a free Trello account using their personal email and starts uploading client documents. What is the risk?
Common Email Mistakes
Top Email Data Exposure Risks
- Wrong recipient: Autocomplete fills in the wrong person with a similar name. Always verify the recipient before sending sensitive data.
- Reply-all with sensitive data: Someone replies all to a large email chain with confidential information attached. Check who is on the thread before replying.
- Unencrypted attachments: Sending restricted data as a regular email attachment. Use encrypted email or secure file sharing instead.
- Forwarding without permission: Forwarding confidential emails to people who should not have access. When in doubt, ask before forwarding.
How This Looks in Your Industry
Healthcare Practices
PHI (Protected Health Information) is restricted data under HIPAA. This includes patient names, addresses, birth dates, Social Security numbers, diagnoses, and treatment information. PHI must be encrypted, access-controlled, and shared only through approved channels. Emailing PHI to the wrong person is a reportable HIPAA breach.
Legal Firms
Attorney-client communications are restricted. Exposing them can waive privilege and compromise cases. All case files, client communications, and settlement details should be classified as restricted and handled with encryption and access controls.
Nonprofits
Donor information, grant reports, and financial data are confidential or restricted. Grant agreements may specify how data must be handled. Donor trust depends on keeping their information private. Use approved tools for all grant and donor data.
Daycares and Schools
Student records, parent contact information, and photos of children are restricted under FERPA and COPPA. Staff photos on personal phones, student data in personal cloud accounts, and parent information in unapproved apps all create compliance risks.
Key Takeaways
- Data classification is the foundation of data privacy. Know what type of data you are handling.
- Four levels: Public, Internal, Confidential, Restricted. Each has different handling rules.
- Shadow IT (unapproved tools) is a major data exposure risk. Request tools through IT.
- Always verify email recipients before sending sensitive data. Autocomplete mistakes are common.
- Restricted data (PHI, client files, financial data) requires encryption, access controls, and secure disposal.
Module Quiz
Select an answer for each question to reveal the correct response and explanation.
1. Which data classification level applies to patient medical records?
2. You want to use a free online PDF converter to merge two confidential client documents. What should you do?
3. You accidentally email a spreadsheet with donor names and donation amounts to your entire mailing list instead of just the board. What should you do?
4. What is shadow IT?
5. How should restricted data be disposed of?
Module 04 of 10 – Cybersecurity Essentials Training
