Restricted-risk data is the highest classification of sensitive information, where unauthorized access, disclosure, or misuse could result in significant legal, financial, operational, or reputational damage to individuals or the institution. This category often includes data that is subject to stringent regulatory and compliance requirements, such as classified information, national security data, sensitive legal documents, or any other information specifically designated as restricted by law or organizational policies.
- Individually identifiable financial or medical information; credit card numbers, student financial information, Protected Health Information (PHI)
- Information commonly used to establish identity that is protected by state, federal, or foreign privacy laws and regulations, such as Pennsylvania law protecting personal information, and not classified in Tier 4; Social security numbers (SSN)
- Individually identifiable genetic information that is not Tier 4.
- National security information (subject to specific government requirements)
- Passwords and PINS that can be used to access confidential information
- Human Research Data
- Attorney-client privileged information
- Controlled Unclassified Information (CUI)
- Export controlled information (ITAR, EAR)
- IT security information (ie privileged credentials, incident information)
- Student loan application information (GLBA)