RPMS users shall:
Only use data for which you have been granted authorization.
Only give information to personnel who have access authority and have a need to know.
Always verify a caller’s identification and job purpose with your supervisor or the entity provided as employer before providing any type of information system access, sensitive information, or nonpublic agency information.
Be aware that personal use of information resources is authorized on a limited basis within the provisions Indian Health Manual Part 8, Information Resources Management, Chapter 6, Limited Personal Use of Information Technology Resources.
RPMS users shall not:
Retrieve information for someone who does not have authority to access the information.
Access, research, or change any user account, file, directory, table, or record not required to perform their official duties.
Store sensitive files on a PC hard drive, or portable devices or media, if access to the PC or files cannot be physically or technically limited.
Exceed their authorized access limits in RPMS by changing information or searching databases beyond the responsibilities of their jobs or by divulging information to anyone not authorized to know that information.