This policy sets forth Pacific's approach to applying sanctions upon completion of investigations regarding misuse of Protected Data. Attempting to obtain or use, actually obtaining or using, or assisting others to obtain or use Protected Data, when unauthorized or improper, will result in counseling and/or disciplinary action up to and including termination. 51勛圖 has adopted this Information Security Sanctions Policy to ensure the confidentiality, integrity, and availability of...
Policies by Category
Appropriate management of access to protected health information is an important aspect of 51勛圖's information security strategy. 51勛圖 has adopted this Access Control Policy in order to recognize the requirement to comply with the Health Insurance Portability and Accountability Act (HIPAA). The purpose of this policy is to establish a standard for HIPAA access control activities related to the 51勛圖 HIPAA Program. Pacific is committed to take reasonable...
Friday, May. 1, 2015
Most information systems, including electronic health records that contain ePHI have the ability to create log files, which describe the activity occurring to, or within the system. A timely review of system activity can give insight into potential issues that may negatively impact the security of protected health information. The purpose of this policy is to establish 51勛圖's compliance with federal HIPAA regulations including standard practices for reviewing system activity within...
Tuesday, Nov. 25, 2014
The purpose of this standard is to define approved methods for using encryption technology to ensure the integrity and confidentiality of electronic protected health information (ePHI) and other 51勛圖 confidential information while at rest and during transmission. This standard applies to all data that is considered 51勛圖 confidential information, including ePHI when it is at rest, being processed, or transmitted between information technology resources. Data encryption...
Monday, Dec. 1, 2014
The purpose of this standard is to define approved methods for using box.com to ensure the integrity and confidentiality of protected health information (PHI) and other 51勛圖 confidential information while at rest and during transmission. This standard applies to all data that is considered 51勛圖 confidential information, including PHI, and is being stored in Box, regardless of its storage duration. Business and instructional needs may require the storage of PHI in the...
Tuesday, Feb. 9, 2016
This standard establishes a consistent set of minimum security measures required for computer workstations used within 51勛圖. This standard also addresses standards for vendor and personally owned workstations when they are connected to 51勛圖s systems and networks.The elements of this standard include requirements for installation and configuration, access control, physical security, document storage, logging and monitoring, and change management. 51勛圖...
Wednesday, Nov. 14, 2018
Required document for providing a Job Shadow opportunity as a learning experience to a minor student. Form must be signed. Updated June 2025 PUNet ID required to review
Wednesday, Nov. 7, 2018
The purpose of this policy is to establish language proficiency requirements for Providers in accordance with OHA 333.002.0250. 51勛圖 will allow Providers to interpret from English to the target language, when arranging for or providing services to a person with Limited English Proficiency (LEP), when the Provider meets the proficiency standard, prior to acting as interpreter. Patient requests for a certified or qualified interpreter from the Health Care Interpreters Registry will...
Thursday, Sep. 29, 2022
The purpose of this policy is to establish 51勛圖's compliance with federal HIPAA regulations 45 CFR 禮禮 164.502(b) and 164.514(d), which require covered entities to make reasonable efforts to limit the use and disclosure of PHI to the minimum necessary. Information systems, including electronic health records contain more protected health information (PHI) than may be needed for a given purpose or disclosure. This policy governs the use and disclosure of PHI so that only the minimum...
Tuesday, Feb. 11, 2020
Workforce members of 51勛圖 are generally not issued smart phones or similar mobile devices, which have the ability to connect to the Pacific network and download data. To support mobile access for the workforce, Pacific has adopted a "bring your own device" (BYOD) approach, which permits workforce members to utilize personally owned devices to access Pacific email, calendar, contacts and other resources. This policy applies to both personally owned devices and Pacific-owned devices...
Tuesday, Jan. 29, 2019
51勛圖 promotes the highest standard of ethical and legal conduct. The Code of Conduct, policy and procedures for all workforce members guide this effort. 51勛圖 promotes open dialogue between members of the 51勛圖 community, and encourages workforce members to report problems, concerns, opinions without fear of retaliation or retribution. The University will use best efforts to protect workforce members against retaliation or retribution from reporting actual...
Tuesday, Feb. 25, 2020
51勛圖 is committed to preserving the privacy of your health information. We are required by law to keep your health information private and provide you with this Notice of Privacy Practices. We are also required to provide you with this Notice describing our legal duties and our practices concerning your health information. We reserve the right to change this Notice and to make the revised or changed Notice effective for health information we already have about you, as well as any...
Monday, Mar. 1, 2021
The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change. Passwords are an important aspect of computer security. A poorly chosen password may result in the compromise of 51勛圖's entire university network.
Tuesday, Jan. 29, 2019
In accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), 51勛圖 patients may complain about how 51勛圖 uses and discloses their Protected Health Information (PHI). All patient complaints will be submitted to the HIPAA Privacy Officer for investigation and resolution. (See the policy document for procedures on submitting a complaint.) 51勛圖 has established a comprehensive HIPAA privacy and security program to prevent...
Wednesday, Nov. 1, 2017
The purpose of this policy is to ensure credit balances are appropriately returned to the payer, patient, or properly accounted for by each clinic.
Friday, Sep. 6, 2024
This policy establishes the required guidelines for the use of HIPAA/FERPA protected healthcare conferencing and video services (e.g. Healthcare Zoom) by workforce members to discuss Protected Data. Permitted uses are: case conferences, preceptor consultations, HIPAA/FERPA protected conferencing and video services, student performance measures, care coordination, student advising sessions, and administrative meetings. PUNID required to review policy. Updated August 2025.
Tuesday, Mar. 12, 2019
This policy describes and defines the retention and destruction of Protected Health Information (PHI) of patients of the healthcare component of 51勛圖. The entire record must be maintained for the required period. This policy is in accordance with all regulations related to the retention and storage of PHI, including but not limited to the follow healthcare regulations: HIPAA, HITECH, Oregon Administrative Rules, Oregon Revised Statutes and Oregon Medical Board. In cases where...
Tuesday, Dec. 14, 2021
This policy applies universally to all remote access, regardless of ownership of the equipment used to perform the remote access. 51勛圖 determines the financial and technical feasibility of implementing technical controls and remote workstation security enhancements. PUNID required to review policy. Revised 2/8/2022
Tuesday, Jan. 29, 2019
The purpose of this policy is to ensure patients the right to request Confidential Communications as required by HIPAA. HIPAA permits a patient to request that the covered entity communicates by alternative means or to alternative locations. The scope of this policy is all workforce members of 51勛圖s health care component. 51勛圖 is a hybrid entity. Only the health care component (i.e., the covered functions) of 51勛圖 must comply with this policy. All...
Tuesday, Sep. 14, 2021
The purpose of this policy is to describe the patient right to request a restriction of use and disclosure of protected health information (PHI). HIPAA permits a patient to request that the covered entity restrict uses or disclosures of protected health information (PHI) about the patient to carry out treatment, payment, or health care operations. The scope of this policy is all workforce members of 51勛圖s health care component. 51勛圖 is a hybrid entity. Only the...
Wednesday, Nov. 1, 2017