Any user signing into UNC School of Medicine Webex will be assumed to understand and agree with the user agreement and PHI Video Conferencing Policy.

UNC School of Medicine IT
Academic Technology Services

User Agreement and Acceptable Usage Policy for UNC School of Medicine Webex
Effective November 12, 2018

Acceptance of Agreement

Webex is a web and video conferencing service provided by the UNC School of Medicine IT (SOM IT), Academic Technology Services (ATS). This agreement governs the use of the Webex service and is in place to ensure compliance with all applicable University of North Carolina At Chapel Hill (UNC) security policies and standards.


Any User who does not understand or agree with the policy should not login to the system. For clarification of policies, please contact ATS Video Conferencing at or call 919-843-9086.

Updates to Agreement

ATS may update this User Agreement at any time and without notification to reflect its organizational needs.

Service Description

Webex is a service provided by ATS for the UNC School of Medicine.

Services to be provided include:

  1. Secure web and video conferencing and telepresence.
  2. Prescheduled conference set up and support.
  3. Password protected meetings.
  4. Permanent personal Webex rooms, which are always open and do not require prescheduling of conferences.
  5. Meeting recording and secure streaming playback.

Acceptable Usage Policy

  1. Use of Webex is for the purpose of university business only.
  2. User will not use or present any content that is in violation of state or federal laws or UNC policies.
  3. When recording, it is the responsibility of the User to make all attendees aware in advance of any conference being recorded.
  4. Inclusion and sharing of Protected Health Information (PHI) must adhere to all HIPAA policies and guidelines.
  5. User must obtain consent from appropriate parties prior to including, recording, or sharing any content containing sensitive information (e.g. protected health information, intellectual property, copyright material). If needed, our Patient Release and Authorization Form and General Recording and Release Form can be downloaded from our website at
  6. Any use of this service is the responsibility of the User. SOM IT will not assume responsibility for the misuse of content.
  7. User agrees to comply with all applicable UNC security policies and procedures.
  8. SOM IT will not assume responsibility for content that is reported or discovered to be in violation of any aforementioned policies or laws. Any recorded content will be removed pending review, and appropriate action taken if necessary.

Limitation of Liability

SOM IT will have no liability or responsibility in the event of any loss or interruption of the services and/or media content described within this agreement due to causes beyond its reasonable control or ability to foresee.

Denial or Termination of Service

While generally available to all UNC affiliates, the following are potential conditions that may require the denial or termination of service.

  1. Denial of service will be at the discretion of SOM IT Management based on the following:
    1. The intended use of the service by the client is not for university business.
    2. The intended use of the service by the client causes a situation where SOM IT resources are overwhelmed technically, in terms of necessary staffing or otherwise.
    3. The intended use of the service by the client does not match the services that ATS is approved to support.
    4. The client has not followed through with the proper procedure for requesting the necessary service.
    5. The client has been previously found to be in violation of any IT policy within the university such that the action could be repeated.
    6. Any other reason agreed to be appropriate by SOM IT management.
  2. Termination of service will be at the discretion of SOM IT management based on the following:
    1. Violation of the effective User Agreement or any Service Level Agreement (SLA) in place.
    2. It has been determined that the client’s use of the service is matching circumstances that would have ordinarily caused a denial of service.
    3. The client’s use of the service is directly causing a negative impact on the quality of service for other users.
    4. Any other reason agreed to be appropriate by SOM IT management.



  1. Users can request support for video conferencing by contacting ATS Video Conferencing at or by calling 919-843-9086.
  2. Information is available on the video conferencing site at

Policy for Including Protected Health Information (PHI)

Within a Video Conference

When including patient Protected Health Information (PHI) in a video conference, you must adhere to the following measures to ensure the security of the information:

  1. You must have patient consent to share their information and be able to provide consent documentation if requested.
  2. You may not invite or include anyone in the conference with whom you do not have permission to share the patient information.
  3. The ability to join the conference cannot be made publicly available.
  4. You may not include PHI in the meeting title or in the email invitation.
  5. Limit your data! Only include patient information relevant to the conference meeting.
  6. Computers used to access conferences containing PHI should be encrypted.
  7. PHI will not be used for research without appropriate authorization from the Institutional Review Board.
  8. Emails sent to and from email addresses are considered secure, as well as HIPAA and FERPA compliant.
  9. PHI, excluding scheduling information, sent to a non email must be encrypted via the following: .
  10. If the conference is recorded, the recording must be treated as patient record and can only be shared with anyone who has permission to view the patient information. Please make sure recipients understand that the link and password may not be forwarded.
  11. When sharing a recording, your Recorded Meeting Access Security Settings must be set to:
    1. Require users to sign in
    2. Prevent downloading
    3. Require password protection
  12. If you reassign your recording to another user, the user must have permission to view the patient information and be responsible for managing the recording as stated in 10 and 11 above.

UNC Security Policies and Procedures

  1. UNC School of Medicine, UNC Healthcare, UNC ITS Information Security & Privacy Policies
  2. UNC ITS Policies, Procedures and Guidelines
  3. UNC ITS Information Security Policy Summaries
  4. UNC-Chapel Hill Standard on Transmission of PHI and SI over an External Network or an Unsecure Medium
  5. UNC-Chapel Hill Information Security Controls Standard
  6. UNC-Chapel Hill Privacy of Protected Health Information Policy
  7. UNC-Chapel Hill Standard on HIPAA Sanctions
  8. UNC-Chapel Hill Employee Policies & Procedures
  9. UNC School of Medicine IT, Information Security & Privacy, HIPAA Security Policies
  10. UNC School of Medicine IT, Information Security & Privacy, HIPAA Online Training
  11. UNC Libraries Scholarly Communications Office – Copyright and Fair Use
  12. UNC School of Medicine Patient and General Recording Release Forms