5.1.43 Technology
May 1, 2026
...nd people by clearly outlining actions that are not acceptable. 1. Do Not Share Passwords Passwords are personal credentials and must never be shared—verbally, in writing, or digitally. This includes coworkers, volunteer...
5.1.42 Cybersecurity Incident Reporting
May 1, 2026
...ay: Suspicious login activity Unexpected login alerts, unfamiliar locations, or password reset emails you did not request Malware or security warnings Pop-ups, antivirus alerts, or messages indicating a potential infecti...
5.1.34 Lost Personal Device
May 1, 2026
...ecure your accounts From another device: Change your Crosspoint (Microsoft 365) password immediately Update passwords for any other accounts accessed on that device (email, banking, etc.) Revoke active sessions if possib...
...quirements Device Protection: All devices must be secured with a passcode, PIN, password, or biometric authentication (Face ID, fingerprint). Automatic Lock: Devices should automatically lock after a short period of inac...
5.1.32 Use of Personal Devices for Work
May 1, 2026
...thentication (MFA) must be enabled Devices should be protected with a passcode, password, or biometric lock Public or shared computers should not be used to access sensitive information Files must not be downloaded and s...
5.1.24 Clicked on a Bad Link
May 1, 2026
...her instructions from IT. Do not continue clicking, downloading files, entering passwords, or responding to any messages connected to the suspicious link. When reporting the issue, include: The email, text, or website wh...
5.1.23 Recognizing Phishing Attempts
May 1, 2026
...hishing is a fraudulent attempt to gain access to sensitive information—such as passwords, financial data, or internal systems—by pretending to be a trusted source. These attacks most commonly occur through email, but ca...
5.1.18 Multi Factor Authentication (MFA)
May 1, 2026
...to a system. This adds an additional layer of protection beyond a username and password. What are authentication factors? MFA typically includes a combination of the following: Something you know (password or PIN) Somet...
5.1.17 Personal Password Compromise
May 1, 2026
Personal Password Compromise If you suspect that any of your passwords have been compromised, you must act immediately. Required Action: Notify the IT Department or the Director of Operations without delay . Why Th...
5.1.14 Password Management
May 1, 2026
Password Management All employees of Crosspoint Church are required to maintain secure password practices across all systems. A password management tool should be used to securely store credentials. While no standard pla...
6.1.5 Risk Management Plan
May 1, 2026
...sures Preventative Measures HIPAA-compliant EHR system Secure billing platforms Password-protected devices Annual HIPAA training for staff Data Breach Response Notify leadership immediately Contain breach Assess s...