Guidelines for Working Offsite

Summary

Key pointers for workforce members who access MU data remotely or who use MU resources and devices offsite.

Body

  1. Only connect to MU approved VPNs when working or accessing MU resources.
  2. Limit personal use of work email. Do not use your work email for personal accounts.
  3. Limit non work related browsing on MUHC owned devices. There have been threats related to malware and malicious scripts installed due to websites accessed and unapproved software downloads.
  4. Mobile device (smartphones, tablets, laptops, etc.) requirements:
  • Always perform device and application updates. This ensures necessary security patches are applied.
  • Always have PIN, Passcode, and/or Biometrics enabled to access the device.
  • Never access MU resources over public wi-fi.
  • Only download applications from trusted sources.
    • For MUHC owned devices, only download applications approved by MUHC Information Security.
    • Always read the prompts and permissions before downloading applications.
  • Never save PHI on directly on your device or in your personal cloud storage.
  • Report any lost or stolen device immediately.
  • Do not bypass MUHC security controls. For example, installing mechanisms preventing computer locking and screensavers, keyboard macros, and automation software.

Related policies:

Information Security - Portable Electronic Device Policy

Information Security - Remote Work Policy

There are additional requirements for working outside the United States. Please see contact your department director for guidance with Human Resources and Information Security protocols. 

Related policy: https://www.umsystem.edu/ums/is/infosec/standards-travel

Details

Details

Article ID: 1278
Created
Thu 3/6/25 9:25 AM
Modified
Fri 7/11/25 1:21 PM