Cybersecurity Data Handling

Effective date: October 5, 2026

This notice summarizes Providence Agency Services LLC’s operational approach to cybersecurity and data handling. It is not a certification, attestation, or promise that every control required by a particular solicitation is satisfied.

Data-handling principles

  • Collect only information needed for an approved business purpose.
  • Do not place PHI, Social Security numbers, full Medicare numbers, passwords, or payment data in public forms or ordinary email.
  • Limit access to authorized personnel with a business need and use secure channels identified for the engagement.
  • Keep records, retention schedules, vendor terms, and incident contacts documented for the applicable project.

Partner and subcontractor review

Before a teaming or subcontracting engagement, the parties should document the scope, permitted data, security responsibilities, breach notification process, access controls, insurance requirements, records retention, flow-down terms, and return or destruction of data. A prime contractor’s security instructions and the solicitation control when they are more specific.

Incident notice

Potential loss, unauthorized access, misdirected disclosure, or suspected compromise should be reported promptly through the project’s designated contact. Do not send incident details containing sensitive data through a public form.

Security questions: [email protected]. This notice should be reviewed and supplemented by qualified security and legal professionals before use in a regulated or government contract.

Scroll to Top