Mobile Logo in White

Policy News & Updates

In accordance with IHOP policy 2.1.2 Policy Administration for Institutional Handbook of Operating Policies, the University Executive Committee holds final approval authority for new policies, significantly revised policies, and proposals to retire an existing policy.

This page will be updated regularly to reflect recent IHOP updates. A running list of policy updates can be viewed on the running List of all IHOP updates.

September 2026

Revised Policies

11.2.6 Uses and Disclosures of Protected Health Information to or from Personal Representatives

This policy was revised to include a requirement for a court Order of emancipation of emancipated minors and a reference to IHOP 11.1.9 Consent for Treatment of Minor. The scope statement was also updated.

 

11.2.12 Uses and Disclosures of Protected Health Information for Research

This policy was revised to more clearly define the use or disclosure for research activities, the privacy regulations, authorizations, de-identified information, and limited data sets.

 

11.3.4 Notice of Privacy Practices

This policy was revised to include increased clarity in the purpose and scope, as well as revisions to the Requirements for Electronic Notice section for clarity.

 

13.1.6 Consent for Treatment of a Minor

This policy was revised to include a new section on emancipated minors, including the documentation required and the rights of a legally emancipated minor. This policy was also renumbered and moved from Chapter 11 to Chapter 13.

 

Discretionary Edits

The following policies have minor revisions to the scope and/or updated hyperlinks:

August 2026

New Policy

5.9.10 Standard Notice of Artificial Intelligence System

Texas Government Code Section 2054.711 requires this notice for each state agency and local government deploying or using an artificial intelligence system that is public-facing or that is a controlling factor in a consequential decision shall include a standardized notice on all related applications, Internet websites, and public computer systems.

 

Revised Policies

5.1.2 Digital Accessibility

The proposed amendment ensures compliance with upcoming changes to Title II of the Americans with Disabilities Act. Large public entities must meet these requirements by April 26, 2027. Additionally, this amendment will ensure compliance with existing mandates in the Texas Administrative Code (1 TAC §§206 and 213), which also align with Section 508 standards requiring institutions to designate a Digital Accessibility Officer, ensure accessibility in procurement, and provide alternate access when exceptions are granted. This revision also includes a policy name change from “IT Accessibility” to “Digital Accessibility.”

 

5.8.10 Information Resources Acceptable Use and Security Policy

This policy was revised to include a statement pointing to HOP 5.9.10 to raise visibility of the AI standard notice requirement created in Texas Government Code Section 2054.711 and a statement requiring users to adhere to the AI code of ethics defined at TAC Title 1, Part 10, Chapter 219, Subchapter A.

 

11.1.0 Privacy Compliance Program

This policy was revised to include an updated scope statement, updated hyperlinks, expanded oversight activities to capture new regulatory requirements, AI risk oversight, and enhanced Research privacy compliance. Revisions also expand on the standards for confidentiality of substance use disorder patient information, based on 42 CFR Part 2.

 

11.1.1 Notification of Privacy and Security Breaches

This policy was revised to include an updated scope statement, updated amounts for potential penalties, and a new section describing incidents that would require notification of the Texas Attorney General.

 

11.1.4 Photography, Video or Audio Recording, and Other Imaging of Patients

This policy was revised to include an updated scope statement as well as a new section addressing the use of wearable technology capable of recording, monitoring, or biometric identification in patient care, research, clinical, or other restricted settings.

 

11.2.9 De-identification of Protected Health Information

This policy was revised to include an updated scope statement and a new section regarding the use of artificial intelligence, including the required risk assessments prior to use of any AI as well as required authorization for AI use with both identifiable and de-identified PHI.

 

Discretionary Edits

The following policies have minor revisions to the scope and/or updated hyperlinks:

July 2026

Revised Policies

4.3.2 Recruitment and Selection of Classified Employees

The policy has been updated to remove references to outdated processes that are no longer in use. Additionally, the job posting requirement has been revised from five working days to five calendar days to reflect current recruitment practices, recognizing that applicants can access and apply for positions online at any time. While UT System maintains a five working-day posting requirement per its 2022 policy update, this revision aligns the policy with the institution’s operational model and modern, continuous-access job posting environment.

 

4.3.3 Administrative and Professional Employees

The policy has been updated to remove references to outdated processes that are no longer in use. Additionally, the job posting requirement has been revised from ten working days to five calendar days to reflect current recruitment practices, recognizing that applicants can access and apply for positions online at any time. While UT System maintains a five working-day posting requirement per its 2022 policy update, this revision aligns the policy with the institution’s operational model and modern, continuous-access job posting environment.

May 2026

New Policy

4.9.6 Fit For Duty

This new policy establishes expectations for employees to report to work and remain fit for duty to perform their responsibilities safely and effectively. It outlines the process for addressing concerns when an employee may be unfit due to health, behavioral, or substance-related factors and reinforces employee accountability in maintaining a safe and productive work environment.

March 2026

Revised Policies

1.6.6 Institutional Review Board

This policy was updated to reflect regulatory changes requiring each board to include a non-scientific member and limit voting to appointed members. Operational updates add VA representatives as non-voting attendees, remove the Director of Research Protections Programs from voting membership, and correct appointment terms. Clarifications define key terms, confirm the IRB Chair’s voting role, and include minor edits to improve clarity and consistency.

 

7.2.1 Human Research Protection Program Responsibilities

This policy was updated to reflect UT System revisions, replacing individual school names with the unified Health Science Center and including the School of Public Health, which was previously omitted. It shifts some Institutional Compliance & Privacy Office duties to the Office of the Vice President for Research and removes the Office of Clinical Research after its merger with the IRB Office. The update also includes minor administrative edits, updated ERMS‑IRB references, and corrects “Veterans Administration” to “Veterans Affairs” for accuracy.

 

7.2.2 Institutional Review Board Responsibilities

This policy was updated to reflect UT System revisions, replacing individual school names with the unified Health Science Center and adding the School of Public Health. It designates the IRB Director, not the RRP Director, as responsible for IRB policies and meetings. The update also includes the Institutional Official (IO) definition, consistent use of “Institution,” and minor administrative refinements.

February 2026

New Policies

5.8.33 Acceptable Use of Artificial Intelligence Platforms

This policy establishes acceptable use standards for the responsible, ethical, and lawful development and use of Artificial Intelligence (AI) platforms.

 

13.1.5 Central Intake of Payer Audits and Medical Record Requests

This policy establishes a mandatory, centralized workflow for handling physical and electronic correspondence received by clinical departments to meet strict payer deadlines, prevent financial recoupments, and ensure compliance with state and federal regulations.

November 2025

Revised Policies

7.6.1 Research Misconduct

The US Department of Health and Human Services (HHS) issued the 2024 Final Rule that mandates revisions to the research misconduct policy for all institutions that receive PHS funds, with the Office of Research Integrity (ORI) requiring: (i) implementation of the revised policy no later than 01 January 2026; and (ii) submission of the updated institutional policy to ORI as part of the annual assurance process no later than 30 April 2026. These revisions to IHOP 7.6.1 incorporate three new requirements for all institutions: (a) Documentation of subsequent use analysis; (b) Indexing of all records in the “institutional record for all proceedings;” and (c) Documentation of the assessment phase. The revisions also incorporate several amendments to the inquiry and investigation phase of research misconduct proceedings, as well as to reporting templates, as specified in the Final Rule.

 

9.1.3 Use of University Facilities

Minor policy revision to meet compliance with Texas SB 8 and all other applicable laws concerning University Facilities.

October 2025

Revised Policies

5.8 Information Security

Minor revisions to update references.

September 2025

Revised Policies

4.7.6 Flexible Work Arrangements

HB 5196, applicable to all state agencies, and SB 2615, applicable to all institutions of higher education, require updates to flexible work arrangement (FWA) policies. Updates required include faculty being added, prohibiting in-person business while remote, required performance ratings, reasons for the FWA, clarity that a FWA is not a condition of employment, and that an annual renewal is required.

 

5.8.8 Information Resource Security Configuration Management

Revision clarified the compensating controls needed to keep an unsupported operating system on the institutional network. These compensating controls are necessary to reduce the institution’s attack surface and have been in place for many years. This update does not alter existing procedures; it simply sets clear expectations for what will be required.

 

9.1.9 Expressive Activities

Revision to align with Texas Senate Bill 2972 regarding new prohibitions and restrictions, including a clearer definition of expressive activities, a designation of public forums on campus, rules against concealing identity or using percussive instruments during certain times, and a shorter window for approved activities on weekdays. It also outlined new procedures for inviting guest speakers and defined the consequences for disrupting or interfering with others’ expressive activities.