Lehigh handles data that carries legal obligations: student records, health information, financial data, research data, and copyrighted material. The Information Security Office works with General Counsel, Research Integrity, and other university offices to make sure Lehigh meets its obligations under the laws and regulations that govern that data.
This page explains what each requirement covers, who it applies to, and who to contact with questions.
HIPAA
What it covers: The Health Insurance Portability and Accountability Act protects the privacy and security of health information. At Lehigh, this applies to units that handle protected health information, including Health & Wellness Services and certain research involving health data.
Who it applies to: Faculty, staff, and researchers who handle patient or health-related data as part of their role.
Contact: Eric Zematis, Security and Privacy Officer for HIPAA, ejz218@lehigh.edu
GLBA
What it covers: The Gramm-Leach-Bliley Act requires safeguards for student financial information, including financial aid, billing, and payment data.
Who it applies to: Staff in Financial Aid, Bursar's Office, and any office that processes or stores student financial account information.
Contact: Eric Zematis, Qualified Individual under GLBA, ejz218@lehigh.edu
GDPR
What it covers: The General Data Protection Regulation governs how Lehigh collects, stores, and processes personal data belonging to individuals in the European Union, including EU students, applicants, and research subjects.
Who it applies to: Admissions, international programs, and researchers working with EU-based data or participants.
Contact: Eric Zematis, Data Protection Officer, ejz218@lehigh.edu
Copyright / DMCA
What it covers: The Digital Millennium Copyright Act governs how Lehigh responds to claims of copyright infringement involving university networks and systems, including file sharing and unauthorized distribution of copyrighted material.
Who it applies to: Anyone using Lehigh's network. Most commonly relevant to students using file-sharing services.
Contact: Eric Zematis, DMCA Copyright Agent, ejz218@lehigh.edu
NIST 800-171
What it covers: This federal standard defines security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. It primarily affects federally sponsored research involving export-controlled or otherwise sensitive government data.
Who it applies to: Principal investigators and research teams working under federal contracts or grants that involve CUI.
Contact: Information Security Office, security@lehigh.edu
Export Control
What it covers: Federal export control laws restrict the transfer of certain technology, technical data, and software to foreign nationals and foreign countries, including transfers that happen through research collaboration, teaching, or data sharing.
Who it applies to: Researchers working with export-controlled technology, technical data, or restricted-country collaborators. Most relevant to engineering, physical sciences, and federally sponsored research.
Contact: Office of Research Integrity, Matthew Dohn, Assistant Director, Research Integrity mcd517@lehigh.edu
Data Breach Notification
What it covers: Pennsylvania and federal law require Lehigh to notify affected individuals and, in some cases, regulators, when certain categories of personal data are exposed in a security incident.
Who it applies to: Anyone who handles personal, financial, health, or student data. If you suspect a breach, report it immediately.
Report a suspected breach: its.lehigh.edu/report-incident or security@lehigh.edu
Electronic Discovery (e-Discovery)
What it covers: When Lehigh is involved in litigation, regulatory inquiry, or an internal investigation, the university may be legally required to preserve and produce electronic records, including email, documents, and system logs.
Who it applies to: Any Lehigh employee may receive a litigation hold notice requiring preservation of specific records. Compliance with a hold notice is mandatory.
Contact: Office of General Counsel
Questions
If you're not sure which requirement applies to your work, or you need help determining your compliance obligations for a specific project or grant, contact the Information Security Office at security@lehigh.edu.