§ 7. STORAGE OF PHI.
   (A)   The department and the village have a duty to protect the confidentiality and integrity of confidential medical information as required by law, professional ethics, and accreditation requirements. This policy defines the guidelines and procedures that must be followed for the storage of PHI. All personnel must strictly observe the following standards relating to the storage of PHI:
      (1)   The department and the village personnel must ensure that, outside of regular working hours, all desks and working areas that contain PHI are properly secured, unless the immediate area can be secured from unauthorized access.
      (2)   When PHI is being released through electronic medium such as teleconference, video feed, or over the Internet, the department and the village personnel must treat the protection of PHI in the same manner as PHI recorded on paper, securing and limiting access to the PHI to authorized personnel only.
      (3)   PHI stored in medical equipment (e.g. EKG, Ultrasound, Flexsig machines) must be kept secure and disposed of as provided for in this policy.
      (4)   When not in use, PHI must always be protected from unauthorized access. When left in an unattended room, such information must be appropriately secured.
      (5)   If PHI is to be stored on the hard disk drive or other internal components of a personal computer or PDA (Personal Digital Assistant), it must be protected by either a password or encryption. Unless encrypted, when not in use, this media must be secured from unauthorized access.
      (6)   If PHI is stored on diskettes, CD-ROM or other removable data storage media, it cannot be commingled with other electronic information.
   (B)   The department's Privacy Officer is responsible for enforcing this policy, and shall be entitled to the assistance of the Village Manager in doing so, if such assistance should be needed. Individuals who violate this policy will be subject to the appropriate and applicable disciplinary process under this policy and the applicable ordinances of the village, up to and including termination or dismissal.
(Ord. 0030-03, passed 4-2-03)