Sample Data Classification Policy
The Hawaii Health Information Corporation has a sample data classification policy here.
Here’s an excerpt:
A. [COMPANY]’s data classification system has been designed to support the “need to know” principle so that information may be protected from unauthorized disclosure, use, modification, and deletion. Consistent use of this data classification system will facilitate business activities and help keep the costs for information security to a minimum. Without the consistent use of this data classification system, [COMPANY] unduly risks loss of customer relationships, loss of public confidence, internal operational disruption, excessive costs, and competitive disadvantage.
B. This data classification policy is applicable to all information in the [COMPANY]’s possession. Example information such as medical records on patients, confidential information from suppliers, business partners and others are protected under this data classification policy. No distinctions between the word “data”, “information”, “knowledge,” and “wisdom” are made for purposes of this policy.
An archive of the file can be found here: Sample Data Classification Policy
Very useful sample–check it out!