12VAC5-115-40. Patient confidentiality.
A. A participant may only access individual immunization information within VIIS that is required to perform the participant's job function.
B. No participant may conduct any activity that jeopardizes the proper function or security of VIIS, including sharing of sign-on information, allowing unauthorized view of VIIS screens, or failing to log off VIIS when leaving a workstation. A participant may only use VIIS patient-level data for a purpose listed in § 32.1-46.01 A of the Code of Virginia and must immediately notify the patient and VDH of any breach of personal privacy or confidentiality.
C. No employer may access an employee's patient-level data in VIIS for the purpose of determining if the employee is in compliance with the employer's immunization policies.
D. A patient may opt out of VIIS by completing the electronic VDH Opt-Out Form specifying the patient's opt-out preferences.
E. Patient immunization records may not be copied except for authorized use. The copies may not be left where they are visible by unauthorized personnel and shall be shredded, pulped, or incinerated before disposal.
F. VIIS records shall be treated with the same confidentiality and privacy as any other health record. VDH shall immediately suspend a participant's system access privileges for inappropriate use of VIIS records and shall conduct an investigation. VDH may take additional actions pursuant to § 32.1-27 of the Code of Virginia. The VIIS program manager may reinstate privileges.
G. Nothing in this chapter alters the provision in 45 CFR Part 164 that permits covered health care entities to disclose protected health information to a public health authority without individual authorization.
Statutory Authority
§ 32.1-46.01 of the Code of Virginia.
Historical Notes
Derived from Virginia Register Volume 31, Issue 22, eff. July 31, 2015; amended, Virginia Register Volume 42, Issue 22, eff. August 13, 2026.