Foundations · SELF-PACED LEARNING
Confidentiality & Digital Safety
Protect assignment information, recognize deceptive messages, and use digital tools with clear authorization.
For: Interpreters working with confidential information on-site or remotely.
What you’ll learn
- Reduce unnecessary copies and exposure of assignment information.
- Recognize and independently verify suspicious requests.
- Respond promptly to a possible security incident and avoid unapproved recording or AI use.
LESSON 01
Notice where information travels
An assignment can leave information in more places than its main platform: a notification preview, downloaded attachment, browser tab, screenshot, personal calendar, paper note, or cloud backup. Confidentiality applies to your handling of the information, not just what you say aloud.
Before moving any material, ask three practical questions: Is this needed for my authorized work? Is this recipient and channel approved for this purpose? What happens to the copy afterward? A helpful intention does not itself authorize disclosure. Use the agency or client's instructions, including applicable retention requirements. This course teaches general habits; it does not determine which privacy law applies to every assignment.
Sources: American Translators Association, Interpreters Division
LESSON 02
Protect accounts and devices
NIST recommends strong passwords, multifactor authentication, software updates, and security awareness. Use unique passwords for separate accounts and an approved password manager where available. Enable the strongest multifactor option supported by the organization. An unexpected login approval request is a reason to investigate through a trusted route, not to approve it repeatedly until it stops.
Lock your screen when stepping away, keep required security updates current, and use authorized devices and storage. Do not share a login to help another interpreter cover an assignment. If access is missing, request proper access. Security features help only when they are configured and used; a product name or a padlock icon alone does not establish that sharing particular data is authorized.
Sources: National Institute of Standards and Technology · Cybersecurity and Infrastructure Security Agency
LESSON 03
Verify the request outside the message
Phishing uses a message or conversation to induce an unsafe action, such as disclosing credentials, opening a malicious file, or transferring money. It can arrive by email, text, phone, or social media. Polished wording and a familiar display name are not reliable proof of identity.
Imagine an email saying your assignment payment will be canceled unless you sign in through a new link within ten minutes. Stop. Open the service through your saved, verified address or contact the organization using a number you already trust. Do not use the phone number in the suspicious message as your verification route. Report the concern through the designated channel; do not send credentials or verification codes in a reply.
LESSON 04
Check recipients and reduce exposure
Before sending a file or message, verify the recipient, attachment, and access permissions. Autocomplete can select the wrong person. A link may allow broader access than you intended. Use the approved channel for the information, and include only what is needed for the authorized purpose.
Original example: to report a microphone failure, coordination may need the assignment reference, time, and technical symptom; they do not need a copied medical history. When asking an initial question by ordinary email, avoid client names, health information, and sensitive attachments. Ask how to provide further detail securely. Do not assume removing a name makes a detailed story anonymous; dates, locations, and unusual circumstances can identify someone.
- Avoid forwarding a whole thread when a non-sensitive operational summary will do.
- Check the actual attachment before sending, not just its filename.
- Keep client material out of personal cloud folders and personal messaging unless specifically authorized.
- Use the designated correction or incident process if something went to the wrong recipient.
LESSON 05
Recording and AI require a decision
Automatic captions, transcripts, meeting bots, translation services, and AI assistants can create or transmit copies of speech and documents. A tool being convenient or included in a subscription does not establish authorization. Do not add one to an assignment or upload confidential content without the organization's approved process.
NCIHC's AI guidance asks organizations to examine data handling, accuracy, user choice, and accountability. Those are organizational evaluation questions, not issues an individual interpreter can settle by checking a free app's marketing page. For your own practice, use invented text or public material you have permission to use, and verify any generated terminology against reliable references. Do not substitute unreviewed machine output for professional judgment.
LESSON 06
Report a concern while it can be addressed
If you clicked a suspicious link, disclosed a password, lost a device, or sent information incorrectly, report it promptly through the designated incident channel. Describe what happened factually, including time and the type of information involved, using an appropriate secure route. If credentials may be compromised, follow security support's instructions and change affected passwords through a trusted site. Do not continue interacting with the suspicious sender.
Do not decide on your own that no harm occurred, erase evidence to hide a mistake, or notify clients or the public without coordination. The responsible organization must assess containment, required notices, and follow-up. For International Languages, use the contact provided for your assignment. If you need help locating the right channel, email admin@intlanguages.com without sensitive client details and request secure follow-up.
Sources: National Institute of Standards and Technology · International Languages
Sources & scope
Sources checked September 17, 2026 · Prepared by International Languages
These are general security practices. Agency and client instructions, contracts, and applicable laws determine permitted handling and incident procedures.
This course does not certify a platform, person, or organization as HIPAA compliant or establish an incident-response deadline.
These lessons support professional development. They do not award professional certification or continuing education credit. A knowledge check measures understanding of this lesson, not interpreting proficiency.
- The Interpreting Profession ↗American Translators Association, Interpreters Division
- Cybersecurity Basics ↗National Institute of Standards and Technology
- Require Multifactor Authentication ↗Cybersecurity and Infrastructure Security Agency
- Phishing ↗National Institute of Standards and Technology
- Guidance for Healthcare Organizations Evaluating the Potential Use of AI-generated Interpreting ↗National Council on Interpreting in Health Care
- Contact International Languages ↗International Languages