Health system personal data security, confidentiality and usage policy
The University of Kansas Health System (heath system) is committed to the protection of sensitive employee and candidate data. This policy defines how the health system collects, uses, stores, and protects personal information from employees and candidates, and what rights employees and candidates have. This policy will govern the processes and expectations surrounding the intake, storage, and utilization of personal identifiable information to protect such information from inappropriate use.
Purpose
This policy establishes requirements for the collection, use, retention, disclosure, and safeguarding of personal data processed for employment-related purposes in accordance with applicable law, regulation, contractual obligation, and health system data retention and other policies, including hiring, payroll, benefits administration, performance management, and compliance obligations.
Definition
Sensitive employee and candidate data means personal identifiable information that requires heightened protection against unauthorized access, use, disclosure, alteration, or destruction because such unauthorized activity could reasonably result in personal harm, adverse effects on individual rights or interests, financial fraud, identity theft, or reputational harm.
Personal data types
Types of personal data that may be collected and processed for employment-related purposes include, without limitation, the following categories:
- Personally identifiable information, including name, address, mobile phone number, Social Security number, date of birth, gender, race and ethnicity, education, and employment history
- Employee demographic and employment information, including cost center, hire date, termination date, job title, work location, and worker type
- Leave of absence information, including leave status, reason, and dates
- Financial information, including salary grade, pay range, earnings, and tax withholding elections
- Banking information, including direct deposit details
- Performance-related information, including evaluations and disciplinary actions
- Other personal data reasonably necessary to support employment administration, benefits administration, compliance, security, investigations, business continuity, or other authorized business functions
Policy
Data sharing and disclosure
Personal data may be disclosed only as necessary for authorized business purposes, to approved third parties subject to appropriate contractual, confidentiality, and security obligations, or as otherwise required or permitted to satisfy legal, regulatory, or operational obligations.
- Approved third-party service providers that support authorized employment-related, benefits administration, payment, verification, safety, or other operational processes
- Governmental authorities and regulatory bodies for taxation, employment, reporting, audit, or compliance purposes
- Authorized notification service providers for business continuity, safety, or emergency communications, subject to applicable consent and preference controls
- Courts, law enforcement, or other authorized parties when disclosure is required or permitted by applicable law, regulation, legal process, or contractual obligation
Personal mobile phone information must not be disclosed to third parties or affiliates for marketing or promotional purposes. Any authorized disclosure of contact information for employment-related or benefits administration purposes must be limited to the data necessary and governed by applicable contractual, legal, and privacy requirements.
Data security measures
The health system shall implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect sensitive employee and candidate data from unauthorized access, use, disclosure, alteration, or destruction. Such safeguards may include, as appropriate based on risk, system architecture, and the sensitivity of the data, encryption for data in transit and at rest, secure file transfer mechanisms, digitally signed application programming interfaces, routine cybersecurity assessments, role-based access controls, authentication controls such as passwords and multi-factor authentication, and workforce training.
Employee and candidate rights
- Employees may manage disclosure preferences for personal mobile phone information used for certain emergency notification services through authorized preference-management processes, except where the collection, use, or disclosure of such information is required for safety, business continuity, emergency response, or other applicable operational or legal purposes.
- Such consent remains effective until it is withdrawn through an authorized withdrawal or preference-management process, subject to reasonable processing time and any applicable legal, safety, or operational exceptions.
- Candidates and employees are responsible for any carrier, messaging, or data charges associated with such communications.