Indiana University Indiana University

Indiana University


Policies for All Staff and Temporary Employees

Confidentiality of Student, Medical, and Personnel Records
AFSCME(IN) 5.7 • PA/SS 5.7 • Temporary 3.9

Revised March 1, 2003

This policy has moved to the University Policies web site.


Employees covered by this policy
This policy applies to all Staff and Temporary employees at IU.

A. Definition

Confidential information refers to nonpublic information about students, faculty, and employees. Some examples of confidential information include grades, financial aid, performance evaluations, family data, and medical records

B. Policy and related laws

  1. Employees cannot use confidential information for personal reasons. For example, employees cannot use someone's address to seek political contributions or to present information about a sales campaign.

  2. A federal law, Family Educational Rights and Privacy Act (FERPA), classifies most student record information as private. This information cannot be released to third parties (including parents) without signed consent from the student.

  3. Personal health information created or used by employee- sponsored health plans also has special protection under the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

  4. Employees are to follow any additional policies and procedures specific to their position and any work applications used in the position.

C. Procedure

  1. Employees who receive requests for confidential information must follow the specific policy that applies to that request.

    1. For policy clarification and details, employees are to consult departmental procedures and an expert in the respective area of information.

  2. Proper handling of confidential information includes not releasing such information to anyone unless that person has authorization.

  3. The consequences of mishandling confidential information (intentionally or unintentionally) range from receiving instruction on proper handling of such information to corrective action or discipline.

D. Employee access to files

  1. Upon request, a university employee or his/her designated representative will have timely access to all information found in the employee's personnel and medical files.

    1. The designated representative must present a written authorization signed by the employee that clearly and specifically describes the information the representative may inspect or copy

  2. At no time during the access of an employee's file will the file be out of the direct supervision of the university record keeper.

Back to top


University Human Resources
Last updated: 28 June 2013
Comments concerning content and the Web site:
Privacy Statement