On this page

Foundations · SELF-PACED LEARNING

Confidentiality & Digital Safety

Protect assignment information, recognize deceptive messages, and use digital tools with clear authorization.

About 20 minutes, including practice6-question knowledge check

For: Interpreters working with confidential information on-site or remotely.

What you’ll learn

  • Reduce unnecessary copies and exposure of assignment information.
  • Recognize and independently verify suspicious requests.
  • Respond promptly to a possible security incident and avoid unapproved recording or AI use.

LESSON 01

Notice where information travels

An assignment can leave information in more places than its main platform: a notification preview, downloaded attachment, browser tab, screenshot, personal calendar, paper note, or cloud backup. Confidentiality applies to your handling of the information, not just what you say aloud.

Before moving any material, ask three practical questions: Is this needed for my authorized work? Is this recipient and channel approved for this purpose? What happens to the copy afterward? A helpful intention does not itself authorize disclosure. Use the agency or client's instructions, including applicable retention requirements. This course teaches general habits; it does not determine which privacy law applies to every assignment.

Sources: American Translators Association, Interpreters Division

LESSON 02

Protect accounts and devices

NIST recommends strong passwords, multifactor authentication, software updates, and security awareness. Use unique passwords for separate accounts and an approved password manager where available. Enable the strongest multifactor option supported by the organization. An unexpected login approval request is a reason to investigate through a trusted route, not to approve it repeatedly until it stops.

Lock your screen when stepping away, keep required security updates current, and use authorized devices and storage. Do not share a login to help another interpreter cover an assignment. If access is missing, request proper access. Security features help only when they are configured and used; a product name or a padlock icon alone does not establish that sharing particular data is authorized.

Sources: National Institute of Standards and Technology · Cybersecurity and Infrastructure Security Agency

LESSON 03

Verify the request outside the message

Phishing uses a message or conversation to induce an unsafe action, such as disclosing credentials, opening a malicious file, or transferring money. It can arrive by email, text, phone, or social media. Polished wording and a familiar display name are not reliable proof of identity.

Imagine an email saying your assignment payment will be canceled unless you sign in through a new link within ten minutes. Stop. Open the service through your saved, verified address or contact the organization using a number you already trust. Do not use the phone number in the suspicious message as your verification route. Report the concern through the designated channel; do not send credentials or verification codes in a reply.

Sources: National Institute of Standards and Technology

LESSON 04

Check recipients and reduce exposure

Before sending a file or message, verify the recipient, attachment, and access permissions. Autocomplete can select the wrong person. A link may allow broader access than you intended. Use the approved channel for the information, and include only what is needed for the authorized purpose.

Original example: to report a microphone failure, coordination may need the assignment reference, time, and technical symptom; they do not need a copied medical history. When asking an initial question by ordinary email, avoid client names, health information, and sensitive attachments. Ask how to provide further detail securely. Do not assume removing a name makes a detailed story anonymous; dates, locations, and unusual circumstances can identify someone.

  • Avoid forwarding a whole thread when a non-sensitive operational summary will do.
  • Check the actual attachment before sending, not just its filename.
  • Keep client material out of personal cloud folders and personal messaging unless specifically authorized.
  • Use the designated correction or incident process if something went to the wrong recipient.

Sources: National Institute of Standards and Technology

LESSON 05

Recording and AI require a decision

Automatic captions, transcripts, meeting bots, translation services, and AI assistants can create or transmit copies of speech and documents. A tool being convenient or included in a subscription does not establish authorization. Do not add one to an assignment or upload confidential content without the organization's approved process.

NCIHC's AI guidance asks organizations to examine data handling, accuracy, user choice, and accountability. Those are organizational evaluation questions, not issues an individual interpreter can settle by checking a free app's marketing page. For your own practice, use invented text or public material you have permission to use, and verify any generated terminology against reliable references. Do not substitute unreviewed machine output for professional judgment.

Sources: National Council on Interpreting in Health Care

LESSON 06

Report a concern while it can be addressed

If you clicked a suspicious link, disclosed a password, lost a device, or sent information incorrectly, report it promptly through the designated incident channel. Describe what happened factually, including time and the type of information involved, using an appropriate secure route. If credentials may be compromised, follow security support's instructions and change affected passwords through a trusted site. Do not continue interacting with the suspicious sender.

Do not decide on your own that no harm occurred, erase evidence to hide a mistake, or notify clients or the public without coordination. The responsible organization must assess containment, required notices, and follow-up. For International Languages, use the contact provided for your assignment. If you need help locating the right channel, email admin@intlanguages.com without sensitive client details and request secure follow-up.

Sources: National Institute of Standards and Technology · International Languages

Sources & scope

Sources checked September 17, 2026 · Prepared by International Languages

These are general security practices. Agency and client instructions, contracts, and applicable laws determine permitted handling and incident procedures.

This course does not certify a platform, person, or organization as HIPAA compliant or establish an incident-response deadline.

These lessons support professional development. They do not award professional certification or continuing education credit. A knowledge check measures understanding of this lesson, not interpreting proficiency.

  1. The Interpreting Profession ↗American Translators Association, Interpreters Division
  2. Cybersecurity Basics ↗National Institute of Standards and Technology
  3. Require Multifactor Authentication ↗Cybersecurity and Infrastructure Security Agency
  4. Phishing ↗National Institute of Standards and Technology
  5. Guidance for Healthcare Organizations Evaluating the Potential Use of AI-generated Interpreting ↗National Council on Interpreting in Health Care
  6. Contact International Languages ↗International Languages
Suggest a correction or ask a question →

THE FINAL STEP

Ready to put it into practice?

Check your understanding of the lesson with 6 practical questions. This knowledge check does not assess spoken interpreting proficiency.

  1. 01
    Choose the best response

    One answer per question. You can go back before submitting.

  2. 02
    See how you did

    Get your score and helpful explanations. Retake as needed.

  3. 03
    Keep learning

    Your passing result is saved in this browser. No form or account is needed.

Progress is saved on this device for 24 hours. Your name and email are not saved with the quiz.