<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Legal and Ethical Principals Padlet - Technology in Schools by John Hendry</title>
      <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0</link>
      <description>Protecting Student Data
EDG-6305-DS1</description>
      <language>en-us</language>
      <pubDate>2022-04-28 17:49:20 UTC</pubDate>
      <lastBuildDate>2022-05-04 18:07:17 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Privacy and protection of student data</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165414593</link>
         <description><![CDATA[<div>This padlet is concentrating on technology in schools, specifically privacy issues and protection of user data. The author is employed as a network administrator for a rural school district west of Fort Worth, Texas. The district is comprised of five educational campuses along with an administration building, bus barn, and maintenance building. The author is working on a Master of Arts in Administrative Leadership at Angelo State University.</div><div>This presentation is geared towards administrators and technicians in school technology departments, particularly those who are involved with securing access to student and staff personal data.&nbsp; The Family Educational Rights and Privacy Act (FERPA) allows parents and students who are 18-years-old or older to have some control over any disclosure of student records or personally identifiable information (PII) from school records (20 U.S.C. § 1232g). I chose this topic because student information needs to be kept private. Information contained in this padlet should assist information technology workers in protecting students’ PII from access by outside forces.<br><br><br></div><h1>References</h1><div>The Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g (1974).</div><div><br></div>]]></description>
         <enclosure url="https://www.ecfr.gov/current/title-34/part-99" />
         <pubDate>2022-04-30 18:39:17 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165414593</guid>
      </item>
      <item>
         <title>The Family Educational Rights and Privacy Act (FERPA) </title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165415980</link>
         <description><![CDATA[<div>The Family Educational Rights and Privacy act is located in Title 20, Section 1232g (20 U.S.C. § 1232g). The law requires schools that receive federal funds to comply with procedures regarding the privacy of student educational records.<br><br></div><ul><li>Those procedures include non-disclosure of a student's protected information to a third party or any party that is not the student or the student’s parent(s). For instance, a school could not provide student educational information on a resume or recommendation letter without the expressed consent of the student.</li><li>Students also have the right to inspect their school records and any request must be granted within 45 days of receipt. If there have been changes to the student’s file, the student must be notified before those files can be disclosed to future employers or other educational institutes.</li><li>Institutions that do not comply with FERPA guidelines risk losing federal funding (Hlavak &amp; Easterly, 2015).</li></ul>]]></description>
         <enclosure url="https://www.ecfr.gov/current/title-34/part-99" />
         <pubDate>2022-04-30 18:43:09 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165415980</guid>
      </item>
      <item>
         <title>5 Tips for Protecting Student Data and Living Up to FERPA</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165421653</link>
         <description><![CDATA[<div>The article contains valuable advice for information technology departments when dealing with outside vendors regarding student data. Third-party companies are not allowed to receive student information, except under certain circumstances that are legitimate educational uses and the data remains under direct control by the school (Schwartz, 2018).</div><div>&nbsp;</div>]]></description>
         <enclosure url="https://marketbrief.edweek.org/marketplace-k-12/5-tips-protecting-student-data-living-ferpa/" />
         <pubDate>2022-04-30 18:57:26 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165421653</guid>
      </item>
      <item>
         <title>FERPA does not offer personal rights</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165905845</link>
         <description><![CDATA[<div>In 2002 the Supreme Court ruled that there were no personal rights to enforce HIPPA. The ruling stemmed from a Washington case where Gonzaga University was sued over the withholding of a certification affidavit. The petitioner was awarded damages on the FERPA claim in the lower court, but it was appealed and ultimately the Supreme Court found in favor of the school (<em>Gonzaga University v. Doe</em>, 2002).<br><br></div><ul><li>Although the school could lose federal funds for a FERPA violation, the court ruled that FERPA “does not give rise to a private cause of action” (<em>Gonzaga University v. Doe</em>, 2002, para. 1).</li><li>The FERPA statute only addresses federal funding and does not offer personal rights under civil rights provisions of FERPA (<em>Gonzaga University v. Doe</em>, 2002).</li></ul>]]></description>
         <enclosure url="https://www.supremecourt.gov/opinions/boundvolumes/536bv.pdf" />
         <pubDate>2022-05-01 17:43:10 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165905845</guid>
      </item>
      <item>
         <title>Cameras in Special Education rooms</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165920386</link>
         <description><![CDATA[<div>“In order to promote student safety, on written request by a parent, school district board of trustees, governing body of an open-enrollment charter school, principal, assistant principal, or staff member, as authorized by Texas Education Code (TEC) §29.022(a-1), a school district or an open-enrollment charter school must provide video equipment to campuses in accordance with TEC, §29.022, and this section. Campuses that receive video equipment must place, operate, and maintain video cameras in self-contained classrooms or other special education settings in accordance with TEC, §29.022, and this section. (19 TAC § 103.1301)”<br><br></div><ul><li>Cameras may be requested by any party related to the school.</li><li>FERPA regulations still apply to the release of any video clip.</li><li>Recordings must be retained for three months.</li></ul>]]></description>
         <enclosure url="https://texreg.sos.state.tx.us/public/readtac$ext.TacPage?sl=R&amp;app=9&amp;p_dir=&amp;p_rloc=&amp;p_tloc=&amp;p_ploc=&amp;pg=1&amp;p_tac=&amp;ti=19&amp;pt=2&amp;ch=103&amp;rl=1301" />
         <pubDate>2022-05-01 18:13:54 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165920386</guid>
      </item>
      <item>
         <title>Student privacy and the Fourteenth Amendment</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165962097</link>
         <description><![CDATA[<div>Schools could be opening themselves up to lawsuits based on zero-tolerance policies concerning legally prescribed or over-the-counter medications. Elisabeth Frost cites an example of a student in possession of prescribed birth control pills, which is protected under the Fourteenth Amendment. She argues that schools that use zero tolerance in such cases are in violation of constitutional law(Frost, 2006).<br><br></div><ul><li>Schools with zero-tolerance policies should review criteria to ensure that students are treated fairly.</li><li>Policies that could be in violation of state or federal laws also should be reviewed.</li><li>Parental consent rules may also be in violation of federal or state laws.</li></ul>]]></description>
         <enclosure url="https://constitution.congress.gov/constitution/amendment-14/" />
         <pubDate>2022-05-01 19:30:55 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165962097</guid>
      </item>
      <item>
         <title>Student Code of Conduct</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165968198</link>
         <description><![CDATA[<div>The school I am employed at publishes a Student Code of Conduct based on recommendations from the Texas Association of School Boards (TASB). However, the code is relatively lax when it comes to privacy issues. The only rules that come close are in regards to technology: “Attempt to access or circumvent passwords or other security-related information of the district, students, or employees or upload or create computer viruses, including off school<br>&nbsp;property if the conduct causes a substantial disruption to the educational environment. Attempt to alter, destroy, or disable district technology resources including but not limited to computers and related equipment, district data, the data of others, or other networks connected to the district’s system, including off school property if the conduct causes a substantial disruption to the educational environment” (Bridgeport Independent School District, 2021, p. 14)<br><br></div>]]></description>
         <enclosure url="https://drive.google.com/file/d/1ne4nY_EBKEofvghDDLY55j1oZ1Pdc-ys/view?usp=sharing" />
         <pubDate>2022-05-01 19:43:57 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2165968198</guid>
      </item>
      <item>
         <title>IEEE Computer Society</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166009666</link>
         <description><![CDATA[<div>IEEE Computer Society (also known as “I-triple-E”) is one of the oldest associations for computer professionals.&nbsp; The group was founded in 1946 and boasts a worldwide membership of over 373,000 professionals (IEEE Computer Society, n.d.).<br><br></div><div>A blog posting on cybersecurity strategies is relevant due to the risks involved should rogue individuals gain access to computer systems. Organizations have a feeling that they are not at risk of a cyber-attack and can be ill-prepared when that attack eventually occurs. Security starts with realigning attitudes that cybersecurity is everyone’s responsibility and begin to institute policies and procedures to prevent attacks (Waqas, 2021).<br><br></div>]]></description>
         <enclosure url="https://www.computer.org/publications/tech-news/trends/cybersecurity-for-organizations" />
         <pubDate>2022-05-01 21:12:03 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166009666</guid>
      </item>
      <item>
         <title>Student Data Hacked in New York City</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166018193</link>
         <description><![CDATA[<div>With the advent of technology for teaching, grading, attendance, and other school-related activities, third-party companies are entrusted with students private personal information. This article talked about the California-based company Illuminate Education, which suffered a breach and allowed up to 820,000 current and former NYC students' information to be stolen.<br><br></div><div>What is most disheartening about this story is that the company misrepresented its cybersecurity protocols to the school district, leading the district to believe that data was encrypted. According to the news story, New York state law requires encryption for personally identifiable student information (Elsen-Rooney, 2022).<br><br></div><div>The main issue with this story is that schools are trusting third-party vendors to maintain security within the law, but there are bad actors who are not living up to their end of the bargain, and it is virtually impossible for a school district to personally vet each and every vendor they deal with for cybersecurity issues.<br><br></div>]]></description>
         <enclosure url="https://www.nydailynews.com/new-york/education/ny-hack-illuminate-online-gradebook-compromised-personal-data-20220325-ahy3b3b3t5cjzajau63muqcniq-story.html" />
         <pubDate>2022-05-01 21:29:45 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166018193</guid>
      </item>
      <item>
         <title>Code of Ethics</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166027730</link>
         <description><![CDATA[<div>Principle 2 of the IEEE Computer Society (IEEE) Code of Ethics states: “Software engineers shall act in a manner that is in the best interests of their client and employer, consistent with the public interest. In particular, software engineers shall, as appropriate:<br>&nbsp;2.05. Keep private any confidential information gained in their professional work, where such confidentiality is consistent with the public interest and consistent with the law” (IEEE Computer Society, 1999, 2 section).<br><br></div><div>In my career as a computer programmer and now as a network engineer and information technology professional, I have access to a large amount of data. I consider it paramount that I protect that data to the best of my ability and take any safeguards necessary to prevent its unauthorized use. Although I am not a member of IEEE, I take their code of ethics very seriously.<br><br></div>]]></description>
         <enclosure url="https://www.computer.org/education/code-of-ethics" />
         <pubDate>2022-05-01 21:53:14 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2166027730</guid>
      </item>
      <item>
         <title>Clay Walker - Peaster ISD</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2168866519</link>
         <description><![CDATA[<div>​</div><div>&nbsp;Clay Walker is the technology director of <a href="https://www.peaster.net">Peaster Independent School District</a> (Peaster ISD). &nbsp; He is a former director at Bridgeport Independent School District and Little Elm Independent School District before taking the job at Peaster in 2020.</div><div>We talked about the importance of having legal and ethical guidelines to safeguard student PII (Personal identifiable information). Walker said that the law “codifies the requirements that schools must protect PII.&nbsp; This can also give merit to the local director responsible that he/she is not "going crazy" trying to protect PII” (C. Walker &amp; J. Hendry, personal communication, April 28, 2022).&nbsp; Walker said that administrators must understand the balance between security and usability.&nbsp; Information technology administrators lean more towards the security side. An emphasis on security can hinder usability by the customer (students). PII is an unseen commodity until there is a data breach. When that happens, it is too late to worry about what has been protected.</div><div>Walker described three best practices for safeguarding data in the school:</div><blockquote><ul><li><strong>Limited access</strong>.&nbsp; Users should not have access to data that is not necessary for their job.&nbsp; For example, does a classroom teacher need to know the SSN of students in her class?&nbsp; No.&nbsp; So the systems that house that data should make sure the teachers do not have access to that particular element.</li><li><strong>Mitigation</strong>. This goes along with Limited Access.&nbsp; IF/When there is a network breach, only specific roles should have access to sensitive data.&nbsp; For example, if a user's account is the source of a network breach, what becomes exposed is ONLY what that user has access to.&nbsp; If this is a non-privileged user, they only have access to their classroom data which does not include sensitive data (such as SSN), but only Names and Local ID's.&nbsp;</li><li><strong>Education</strong>.&nbsp; In 2022, the end-user, without a doubt, is the most vulnerable piece of our security puzzle.&nbsp; Majority (if not all) data breaches are focusing on the end-user clicking a link, opening and email, etc.&nbsp; Educating the end-user to recognize illegitimate email messages and other communications is key in preventing network breaches (C. Walker &amp; J. Hendry, personal communication, April 28, 2022). &nbsp;</li></ul></blockquote><div>&nbsp;</div><div>One of the biggest issues facing school technology departments involves online testing.&nbsp; The Texas Education Agency (TEA) has mandated that all assessment tests move to an online platform (Tex. Educ. Code § 39.02341) by the 2022-2023 academic year. Walker noted the new statute places technology departments in a more crucial role. “Up to this point, it has been more of a convenience that the technology department be available to fix things.&nbsp; In reality, if the network or computer is broken, the teacher can still deliver instruction.&nbsp; While it may not be ideal, it can still happen.&nbsp; With the new online testing requirements, if the network or computer is broken, our assessments (that help determine our state accountability ratings) are not being delivered and therefore our accountability ratings are in direct jeopardy (C. Walker &amp; J. Hendry, personal communication, April 28, 2022)”&nbsp; Walker told me that technology departments can no longer be afterthoughts by school administrations.</div><div>Keeping up with all of the requirements and changes to the educational technology industry can be a full-time job. Walker is a member of the North Texas Association of Technical Directors (NTATD), an informal regional group that shares information, tips, and tools for better management of school technical departments. The group also discusses legal issues and the impacts they may have on educational institutions along with best practices for dealing with those potential issues.</div><div>​</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-03 19:33:08 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2168866519</guid>
      </item>
      <item>
         <title>Best practices for safekeeping critical data</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170368351</link>
         <description><![CDATA[<div>​</div><div>&nbsp;I have been working in the computer industry in various jobs for the last 27 years.&nbsp; The following is a list of recommendations and best practices to assist in keeping customer or user data safe and secure:</div><ul><li>Limit data access to only those who require it for their job. Teachers do not need the social security number or home addresses of students. Do a regular inventory of who has access to critical data and limit access where necessary (C. Walker &amp; J. Hendry, personal communication, April 28, 2022).</li><li>The safest way to protect data is to never collect the data. If specific data is not going to be used, then institutions should never ask for or collect that data (J. Clayton &amp; J. Hendry, personal communication, May 29, 2022).&nbsp;</li><li>Limiting access rights to users can protect the overall network from potential bad actors. A teacher only needs access to some data regarding their classrooms. Principals only need data for their schools. Limiting access mitigates large amounts of data loss should those individuals get hacked or accidentally release data (C. Walker &amp; J. Hendry, personal communication, April 28, 2022).</li><li>Know your vendors. Make sure that you understand their methods of securing data and that the security they implement is adequate to safeguard data and meet legal requirements for security. Understand that anytime you allow a third-party company to access data, you are putting your data at risk (Elsen-Rooney, 2022).</li><li>Educate your uses – frequently. Sometimes it’s difficult to remember that many teachers and administrators are not computer-literate. Most data breaches come from users clicking something they shouldn’t have, such as a bogus webpage, or a bad link in an email (C. Walker &amp; J. Hendry, personal communication, April 28, 2022). Constant training, education, and online drills are necessary to help teach users the importance of online safety.</li><li>Don’t ignore your infrastructure. An IT administrator should constantly monitor and check servers, computers, and other appliances to ensure they have the latest virus and malware protection updates. It’s much easier to keep holes closed than have to restore data from backups.</li><li>Which leads to backups. Make sure that your off-site backups are stored in a secure location. I worked with a company once that stored their backups at the owner’s home. It was fine until his home was the target of a burglary and the perpetrators walked off with several backups of customer data.</li></ul><div>​</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 18:01:55 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170368351</guid>
      </item>
      <item>
         <title>My connection</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170368976</link>
         <description><![CDATA[<div>Since my early days as a computer programmer, I’ve known that protecting data is paramount. Whether it is customer data or proprietary code I am judged by how I am able to safeguard the information provided to me. The fact that there are laws concerning data privacy is secondary to me. I believe that it is my moral and ethical obligation to protect information that is not mine to distribute and I don’t need a law to instruct me on what should be second nature. I have had easy access to valid credit card numbers, social security numbers, home addresses, and even medical information for customers of the companies I have completed projects for. There was never any inclination on my part to procure any of that information for personal gain.</div><div>However, as I have progressed through this class I have learned that laws are needed to prevent careless and accidental disclosure of information along with specific criteria for the release of data. It has been an interesting journey to see the different means of setting legal standards and understanding how those standards intertwine. However, I do believe that when it comes to ethical standards, one either has a sense of good ethics or they don’t. I’ve always believed that personal ethics are something internal. Ethics are not taught but instead are nurtured.&nbsp;</div><div><br></div><div><br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 18:02:21 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170368976</guid>
      </item>
      <item>
         <title>List of reference</title>
         <author>jhendry11</author>
         <link>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170377818</link>
         <description><![CDATA[<div>Bridgeport Independent School District. (2021). <em>Bridgeport ISD student code of conduct</em>. <a href="https://drive.google.com/file/d/1ne4nY_EBKEofvghDDLY55j1oZ1Pdc-ys/view">https://drive.google.com/file/d/1ne4nY_EBKEofvghDDLY55j1oZ1Pdc-ys/view</a><br><br>Clayton, J., &amp; Hendry, J. (2022, May 29). Personal communication.<br><br></div><div>Elsen-Rooney, M. (2022, March 25). Data of 820,000 NYC students compromised in hack of online grading system: education dept.. <em>New York Daily News</em>. <a href="https://www.nydailynews.com/new-york/education/ny-hack-illuminate-online-gradebook-compromised-personal-data-20220325-ahy3b3b3t5cjzajau63muqcniq-story.html">https://www.nydailynews.com/new-york/education/ny-hack-illuminate-online-gradebook-compromised-personal-data-20220325-ahy3b3b3t5cjzajau63muqcniq-story.html</a></div><div><br>Frost, E. (2006). Zero privacy: schools are violating students' Fourteenth Amendment right of privacy under the guise of enforcing zero tolerance policies. <em>Washington Law Review</em>, <em>81</em>(2), 391–415. <a href="https://digitalcommons.law.uw.edu/wlr/vol81/iss2/6/">https://digitalcommons.law.uw.edu/wlr/vol81/iss2/6/</a></div><div><br>Gonzaga University v. Doe, 536 U.S. 273 (2002). <a href="https://www.supremecourt.gov/opinions/boundvolumes/536bv.pdf">https://www.supremecourt.gov/opinions/boundvolumes/536bv.pdf</a></div><div><br>Hlavak, G. C., Esq., &amp; Easterly, E. J., Esq. (2015, April 1). <em>FERPA primer: the basics and beyond</em>. National association of colleges and employers. <a href="https://www.naceweb.org/public-policy-and-legal/legal-issues/ferpa-primer-the-basics-and-beyond/">https://www.naceweb.org/public-policy-and-legal/legal-issues/ferpa-primer-the-basics-and-beyond/</a></div><div><br>IEEE Computer Society. (n.d.). <em>About the IEEE computer society</em>. IEEE computer society. Retrieved May 1, 2022, from <a href="https://www.computer.org/about">https://www.computer.org/about</a></div><div><br>IEEE Computer Society. (1999). <em>Code of ethics</em>. <a href="https://www.computer.org/education/code-of-ethics">https://www.computer.org/education/code-of-ethics</a></div><div><br>Schwartz, S. (2018, June 26). 5 tips for protecting student data and living up to FERPA. <em>Education Week</em>. <a href="https://marketbrief.edweek.org/marketplace-k-12/5-tips-protecting-student-data-living-ferpa/">https://marketbrief.edweek.org/marketplace-k-12/5-tips-protecting-student-data-living-ferpa/</a></div><div><br>Texas Education Code § 39.02341 (2019 &amp; rev. 2021). <a href="https://statutes.capitol.texas.gov/Docs/ED/htm/ED.39.htm">https://statutes.capitol.texas.gov/Docs/ED/htm/ED.39.htm</a></div><div><br>The Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g (1974 &amp; rev. 2022). <a href="https://www.ecfr.gov/current/title-34/part-99">https://www.ecfr.gov/current/title-34/part-99</a></div><div><br>U.S. Const. art. XIV, § 1.<br><br>Walker, C., &amp; Hendry, J. (2022, April 28). Personal communication.<br><br></div><div>Waqas, I. (2021, October 31). How to win the security fight: quick tips for CISOs and organizations. <em>Trends</em>. <a href="https://www.computer.org/publications/tech-news/trends/cybersecurity-for-organizations">https://www.computer.org/publications/tech-news/trends/cybersecurity-for-organizations</a></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 18:07:17 UTC</pubDate>
         <guid>https://padlet.com/jhendry11/uqvh0w9g9kohrlr0/wish/2170377818</guid>
      </item>
   </channel>
</rss>
