Current through October 16, 2024
Section 17a-210-14 - Disclosure of personal data(a) Within ten (10) business days of receipt of a written request for disclosure of personal data, the department shall mail or deliver to the requesting individual a written response, informing him as to whether or not the department maintains personal data on that individual, the category and location of the personal data maintained on that individual and procedures available to review the records, including the records kept under subsection (h) of this section.(b) Except where nondisclosure is required or specifically permitted by law, the department shall disclose to any person upon written request all personal data concerning that individual which is maintained by the department. The procedures for disclosure shall be in accordance with Section 1-15 through 1-21, inclusive, of the Connecticut General Statutes. If the personal data is maintained in coded form, the department shall transcribe the data into a commonly understandable form before disclosure.(c) The department is responsible for verifying the identity of any person requesting access to his or her own personal data.(d) The department is responsible for ensuring that disclosure made pursuant to the Personal Data Act does not disclose any personal data concerning persons other than the person requesting the information.(e) The department may refuse to disclose to a person medical, psychiatric or psychological data on that person if the department determines that such disclosure would be detrimental to that person.(f) In any case where the department refuses disclosure, it shall advise that person of his or her rights to seek appropriate relief, including judicial relief, pursuant to the Personal Data Act.(g) If the department refuses to disclose medical, psychiatric or psychological data to a person based on its determination that disclosure would be detrimental to that person and disclosure is not mandated by law, the department shall, at the written request of such person, permit a qualified medical doctor to review the personal data contained in the person's record to determine if the personal data should be disclosed. If disclosure is recommended by the person's medical doctor, the department shall disclose the personal data to such person; if nondisclosure is recommended by such person's medical doctor, the department shall not disclose the personal data and shall inform such person of the judicial relief provided under the Personal Data Act.(h) The department shall maintain a complete log of each person, agency or organization who has obtained access to or to whom disclosure has been made of personal data under the Personal Data Act, together with the reason for such disclosure or access. This log shall be maintained for not less than five years from the date of such disclosure or access or for the life of the personal data record, whichever is longer.Conn. Agencies Regs. § 17a-210-14
Adopted effective April 9, 1998