
Acceptable Use Policy (AUP)
Last update: November 21st, 2025
1. Introduction
This Acceptable Use Policy (“AUP”) forms part of the overall Service Agreement, including the Terms & Conditions, Privacy Policy, and Data Processing Addendum (“DPA”) between The Unforsaken house of Hephzibah (“Hospital”) and Users, which may include patients, staff, contractors, third-party service providers, and authorised visitors (“Users”).
This AUP governs your use of all hospital systems, digital platforms, communication channels, tele-mental health services, electronic medical records (EMR), and any other technology, device, or network operated by or on behalf of the Hospital (“Hospital Systems”).
Use of Hospital Systems indicates your acceptance of this AUP.
2. Purpose of the AUP
The purpose of this policy is to:
- Protect patient confidentiality and clinical data
- Ensure safe and lawful use of digital and physical resources
- Support a therapeutic environment
- Promote compliance with relevant Nigerian laws including
3. Acceptable Use Requirements
Users must:
- Use Hospital Systems solely for legitimate clinical, operational, administrative or authorised personal purposes.
- Access only the data and systems for which you have been granted authorisation.
- Maintain strict confidentiality of patient information, including written records, EMR, telehealth recordings and psychological assessments.
- Use secure passwords and protect devices from authorised access.
- Comply with all hospital policies relating to security, privacy, professional conduct, and clinical governance.
- Ensure that any online communication with patients or colleagues is respectful, professional, and compliant with relevant laws.
- Report suspected breaches, data loss, or inappropriate behaviour immediately to the Hospital Administrator or Data Protection Officer (DPO).
4. Prohibited Activities
Users are strictly prohibited from:
4.1 Misuse of Patient Information
- Accessing, sharing, or storing patient data without authorisation
- Taking screenshots, photos or recordings of patient information
- Using patient data for research without National Health Research Ethics Committee (NHREC) approval.
- Discussing cases in public areas or on social media
4.2 Misuse of Hospital Systems
- Using Hospital systems to access pornography, violent content, illegal material, or unapproved social networks.
- Attempting to bypass security systems or firewalls
- Introducing malware, unauthorised software, or unapproved devices
- Using hospital email for harassment, abusive language, or personal business activities
4.3 Fraud, Financial Abuse & Misrepresentation
- Submitting false information
- Misrepresenting your identity
- Attempting unauthorised billing, fee alteration, or fraudulent claims
4.4 Disruptive Behaviour
- Any action that compromises patient safety or interferes with therapeutic services
- Aggressive, threatening, or abusive conduct toward staff or patients
5. Communications & Electronic Messaging
By using Hospital Systems, you consent to monitoring of communications strictly for:
- Security and fraud prevention
- Compliance auditing
- Protection of patient confidentiality
Hospital-provided communications channels may not be used for:
- Personal business enterprises
- Political campaign activity
- Unlawful solicitation
- Unapproved mass emailing
6. Security & Data Protection
Users must comply with:
- Nigeria Data Protection Act (NDPA) 2023
- Hospital's Data Protection Addendum (DPA)
- All cybersecurity protocols
Users must immediately report:
- Loss or theft of a device.
- Suspected hacking or phishing.
- Data leak or confidentiality breach.
The Hospital reserves the right to restrict or suspend accounts for security reasons.
7. Telehealth & Remote Services
Users must:
- Use only approved tele-therapy platforms
- Ensure private, confidential environments during virtual sessions
- Avoid recording any clinical session unless expressly approved and documented
Patients must not:
- Share telehealth links publicly
- Record sessions without consent
- Permit third parties to join without approval
8. Third-Party Services & Payments
If you make any payment for hospital services, you warrant that:
- You have legal authorisation to use the payment method
- Information provided is true and accurate
The Hospital may use the third-party providers. Your information may be shared with them according to the Privacy Policy.
We reserve the right to refuse or cancel a transaction where fraud, unlawful activity, or system misuse is suspected.
9. Consequences of Violating the AUP
Violations may result in:
- Access restrictions
- Termination of accounts
- Clinical discharge (for patients)
- Disciplinary action (for staff/contractors)
- Reporting to regulatory authorities
- Legal action under Nigerian law
10. Modification of the AUP
The Hospital may update or amend this AUP periodically. Continued use of Hospital Systems continues acceptance of the updated policy.
11. Contact Information
For questions, reporting breaches, or DPA inquiries:
Data Protection Officer (DPO) ____________________
Administration office ___________________________
Email ______________________________________
Phone ______________________________________