UOSH access to employee medical records will in certain circumstances be important to the agency's performance of its statutory functions. Medical records, however, contain personal details concerning the lives of employees. Due to the substantial personal privacy interests involved, UOSH authority to gain access to personally identifiable employee medical information will be exercised only after the agency has made a careful determination of its need for this information and only with appropriate safeguards to protect individual privacy. Once this information is obtained, UOSH examination and use of it will be limited to only that information needed to accomplish the purpose for access. Personally identifiable employee medical information will be retained by UOSH only for so long as needed to accomplish the purpose for access, will be kept secure while being used, and will not be disclosed to other agencies or members of the public except in narrowly defined circumstances. This section establishes procedures to implement these policies.
The UOSH medical records officer shall, as appropriate , assure that the results of an agency analysis using personally identifiable employee medical information are communicated to the employees whose personal medical information was used as a part of the analysis.
Utah Admin. Code R614-1-10