External User Access and Acceptable Use Agreement
For vendors, contractors, consultants, service providers, business partners, and other authorized non-employee users
Purpose and Scope
This Agreement establishes the conditions under which an external user may access Kaleida Health information systems, applications, networks, devices, facilities, or information. Access is granted only for an approved business purpose and is subject to this Agreement, Information Security Policy IS-02, applicable contracts, and applicable legal and regulatory requirements.
For this Agreement, “Kaleida Health Information” means patient, workforce, business, operational, financial, technical, security, or other confidential or proprietary information owned by, maintained for, or entrusted to Kaleida Health.
1. Authorized Access and Minimum Necessary Use
Access is limited to the systems, information, functions, and time period approved by Kaleida Health.
Users may access only information necessary to perform their authorized responsibilities and must not browse, search for, or use information for curiosity, personal interest, or any unapproved purpose.
Access to patient, workforce, or other sensitive information may be logged, monitored, and audited.
Users must follow instructions issued by Kaleida Health regarding access methods, security controls, and handling of information.
2. Confidentiality and Ownership
Kaleida Health Information accessed, received, created, transmitted, processed, or stored in connection with authorized access remains the property of Kaleida Health or the applicable lawful owner. Users must protect it against unauthorized access, use, disclosure, alteration, loss, theft, or destruction.
Nothing in this Agreement transfers ownership of a vendor’s software, source code, equipment, documentation, data, trademarks, patents, copyrights, trade secrets, or other proprietary materials to Kaleida Health.
Confidentiality obligations continue after access ends. Information may be disclosed only as authorized by Kaleida Health and permitted by applicable contract and law.
3. Accounts, Credentials, and Authentication
Accounts and credentials are assigned to an individual and may not be shared, loaned, disclosed, transferred, or used by another person.
Users must safeguard passwords, multifactor authentication methods, tokens, certificates, keys, and other authentication factors.
Users are responsible for activity performed through their assigned account and must promptly report suspected credential compromise or unauthorized account activity.
Users must not bypass security controls, conceal activity, elevate privileges without authorization, or attempt to access systems or data outside their approved scope.
4. Acceptable Use
Kaleida Health resources may be used only for approved business activities. Users must not:
Use Kaleida Health systems for personal gain, unauthorized commercial activity, harassment, unlawful conduct, or any purpose unrelated to the approved engagement.
Introduce malicious code, conduct unauthorized scanning or testing, disrupt operations, or interfere with the availability or integrity of systems and information.
Connect unauthorized devices, applications, storage services, remote-access tools, artificial intelligence services, or cloud services to Kaleida Health systems or information.
Copy, print, photograph, record, download, transmit, or store Kaleida Health Information unless necessary for the authorized work and permitted by Kaleida Health.
Permit another person to observe or use an authenticated session, including through unattended or shared devices.
5. Devices, Remote Access, and Physical Security
Access must occur only through devices, networks, and connection methods approved by Kaleida Health.
Users must maintain reasonable security safeguards, including supported software, security updates, malware protection, encryption where required, and screen locking.
Remote sessions must be closed or disconnected when work is complete. Devices must not be left unattended while connected to Kaleida Health resources.
Printed materials, removable media, and locally stored copies containing Kaleida Health Information must be minimized, secured, and disposed of using approved methods.
Loss, theft, unauthorized use, or suspected compromise of a device used for Kaleida Health access must be reported immediately.
6. Data Handling and Transmission
Kaleida Health Information must be handled according to its sensitivity and only within approved systems and locations. Confidential or regulated information sent over public or external networks must use Kaleida Health-approved safeguards. Users may not forward, upload, or transfer Kaleida Health Information to personal accounts or unapproved services.
7. Electronic Communications and Internet Use
Kaleida Health email, messaging, collaboration, Internet, and file-sharing services are provided for authorized business purposes. Users must communicate professionally and must not use these services to disclose information without authorization, distribute unlawful or harmful content, misrepresent Kaleida Health, or conduct unauthorized activity.
Messages, files, logs, and other activity created, transmitted, received, or stored using Kaleida Health systems may be retained, reviewed, monitored, audited, or disclosed for legitimate business, security, legal, regulatory, and operational purposes, as permitted by law.
8. Software and Intellectual Property
Users must comply with applicable copyright, trademark, patent, license, confidentiality, and other intellectual property obligations.
Only software, scripts, utilities, browser extensions, applications, and tools approved by Kaleida Health may be installed, executed, or connected to Kaleida Health systems.
Kaleida Health software or licensed materials may not be copied, removed, modified, reverse engineered, or redistributed except as expressly authorized.
Vendor-owned intellectual property remains subject to the applicable contract and is not assigned to Kaleida Health by this Agreement.
9. Monitoring, Audit, and Privacy Expectations
Kaleida Health may monitor, record, inspect, and audit access to its systems, networks, applications, devices, and information assets. Monitoring may include authentication, system activity, network traffic, communications, file transfers, remote sessions, and administrative actions, as permitted by law.
Users should have no expectation of personal privacy when using Kaleida Health systems or when storing information on Kaleida Health owned or managed resources.
10. Security and Privacy Incident Reporting
Users must immediately report any actual or suspected event involving Kaleida Health access or information, including:
Lost, stolen, or compromised credentials or devices;
Unauthorized access, use, disclosure, alteration, transmission, or deletion of information;
Malware, phishing, suspicious messages, unexpected authentication prompts, or other suspected compromise;
Misdirected email, improper sharing, accidental exposure, or loss of printed or electronic information;
Any attempt by another person to obtain credentials or gain access outside the approved process.
Users must preserve relevant information, cooperate with investigation and response activities, and must not independently notify affected individuals, regulators, law enforcement, or the media unless authorized by Kaleida Health or required by law.
11. Access Changes, Suspension, and Termination
The external user and sponsoring organization must promptly notify Kaleida Health when access is no longer needed, when responsibilities change, or when the user separates from the organization supporting the engagement. Kaleida Health may modify, suspend, or revoke access at any time based on business, security, legal, contractual, or operational requirements.
Upon request or termination of access, the user must stop using Kaleida Health resources and return or securely dispose of Kaleida Health Information and property as directed, subject to applicable retention obligations.
12. Violations and Enforcement
Violation of this Agreement, Information Security Policy IS-02, applicable contracts, or law may result in immediate suspension or revocation of access, notification to the sponsoring organization, contractual remedies, financial liability, and referral for civil or criminal action where appropriate.
User Acknowledgment
By electronically accepting this Agreement, I acknowledge and agree that:
1. I have read and understand this Agreement and will comply with Information Security Policy IS-02 and applicable Kaleida Health requirements.
2. I will use access only for authorized business purposes and will access only the minimum information necessary for my approved responsibilities.
3. I will protect Kaleida Health Information and my credentials and will immediately report suspected security or privacy incidents.
4. I understand that my activity may be monitored, logged, retained, reviewed, and audited as permitted by law.
5. I understand that Kaleida Health may modify, suspend, or revoke my access and that violations may result in contractual, civil, or criminal consequences.
6. I understand that this Agreement does not transfer ownership of my organization’s intellectual property or proprietary materials to Kaleida Health.
I have read, understand, and agree with the terms and conditions as stated in this document.