STATE OF IOWA
Department of Public Health
Employee Manual of Policies and Procedures
Effective Revision Date 10/2019
Page 1 of 25
Purpose
This policy provides guidance to Iowa Department of Public Health (IDPH) employees regarding
appropriate disclosures of IDPH data, including confidential public health records, and use of
aggregate counts and statistics in public health reports and publications. This policy also provides
guidance to local boards of health and health departments (including county, city, and district
boards and departments) regarding the release of data and reportable disease information, and
to persons external to IDPH who have access to confidential or implied confidential public health
data through a contract, data sharing agreement or research agreement with IDPH.
The Iowa Department of Public Health is governed by Iowa’s Public Records law and generally
provides public access to records it collects under IDPH legal authority (Iowa Code Chapter 22,
IDPH Policy # IM 11-04-015, Public Records). In addition, IDPH is committed to providing
information, data, and records to the public and the media to protect and improve the health
of the population. However, Iowa law also provides that certain information, data, and
records collected under IDPH legal authority are confidential and may not be disclosed to the
public. Examples of some, but not necessarily all, records and data IDPH is required by law to
maintain as confidential can be found in Appendix A.
The guidelines below are generally applicable to all public health information, records, or data collected
under the legal authority of IDPH that are confidential or that could lead to the identification of an
individual named in a confidential public health record when combined with other known sources of
information. However, certain confidential public health records are governed by additional regulations
as well as specific exemptions. Please see Appendix B for a list of some of the limited exceptions which
authorize release of confidential or personally identifiable information without a data sharing
agreement, research agreement, or contract.
Definitions
Business: Business means and includes every trade, occupation, or profession. This includes
organizations or entities with identifiable proper names. Examples include, but are not necessarily
limited to, schools, non-profit organizations, restaurants, companies, hospitals, or health care clinics.
Confidential Public Health Information, Record, or Data: A record, certificate, report, data, dataset, or
information which is confidential under federal or state law. As a general rule, public health records
which contain personally identifiable information of a health-related nature are confidential under Iowa
law. Examples of some, but not necessarily all, records IDPH is required by law to maintain as
confidential can be found in Appendix A.
Data Sharing Agreement: A legal contract between IDPH and any external entity (including other
departments within state government and Regent’s institutions), or between two internal IDPH
programs in which parties agree to the exchange of specified variables within an IDPH dataset, and use
of the data does not meet the definition of research constituting a need for a research agreement. Data