myBAMSI Privacy Notice

Effective Date: December 16, 2024

 

Purpose

This policy governs the use of BAMSI’s intranet (“myBAMSI”), particularly in handling Protected Health Information (PHI) and Personally Identifiable Information (PII). It ensures compliance with applicable federal and Massachusetts state laws, including:

 

Scope

This policy applies to all employees, volunteers, and contractors who access or use myBAMSI, mainly if they handle PHI, PII, or other sensitive data.

 

Data Governance

  1. Types of Data Covered:
  1. Permitted Uses and Disclosures:

 

Security and Access Controls

  1. Access Restrictions:
  1. Encryption and Storage:
  1. Audit Trails:
  1. Training:

 

User Responsibilities

 

Data Sharing and Disclosure

  1. HIPAA Compliance:
  1. 42 CFR Part 2 Compliance:
  1. FERPA Compliance:

 

Third-Party Vendors

All third-party vendors with access to the intranet must sign Business Associate Agreements (BAAs) to ensure compliance with HIPAA and other applicable regulations.

 

Incident Response and Breach Notifications

  1. HIPAA Breaches:
  1. 42 CFR Part 2 Breaches:
  1. FERPA Breaches:

 

Data Retention

 

Use of the Intranet

myBAMSI is provided solely for operational purposes, such as accessing policies, standard operating procedures, metrics, forms, and other business-related information. Employees, volunteers, and contractors do not have rights to privacy or ownership of any activity conducted on myBAMSI.

 

Monitoring and Privacy Notice

myBAMSI is a BAMSI-owned system provided for business purposes. As such:

By accessing the intranet, you acknowledge and consent to these terms.

 

Policy Updates

This policy may be updated to reflect changes in federal or state laws, regulatory guidance, or BAMSI practices. Users will be notified of significant updates.

 

Contact Information

For questions or concerns about this policy, contact:

Compliance and Privacy Office

BAMSI

10 Christy’s Drive

Brockton, MA 02301

Phone: (508) 580-8700