Republic of the Philippines • Department of Health
Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)
Hospital Information Management System (HIMS)
Terms and Conditions
System Acceptable Use & Operational Governance Policy
| Document Title | Terms of Use & System Governance | Document Reference | GOV-2026-HIMS-TOU |
|---|---|---|---|
| Release Version | Version 1.0 (Operational) | Effective Date | September 2026 |
| Governing Institution | Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) | ||
| Applicability | All authorized healthcare staff, pharmacy personnel, warehouse custodians, inventory managers, and system administrators. | ||
| Supervising Authority | Hospital IT & Materials Management Division | Statutory Framework | R.A. 10173, R.A. 10175, R.A. 7394 |
1. Terms of Use
These are the terms and conditions of Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) governing authorized access to and use of the Hospital Information Management System (HIMS). These Terms of Use establish the standards, access responsibilities, and operational conditions applicable to all authorized hospital staff, administrators, and designated contractors. Access to the system constitutes an agreement to strictly comply with the administrative rules and institutional directives contained herein.
2. Administrative and Legal Notice
These Terms of Use represent operational rules for hospital inventory and supply chain activities. Institutional policies, hospital executive directives, and applicable Philippine laws (including Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, and Republic Act No. 10175, otherwise known as the Cybercrime Prevention Act of 2012) supersede any software terms.
Sections containing bracketed placeholders must be reviewed and formally authorized by Hospital Management / Institutional Legal Counsel. No individual hospital user may alter, waive, or create unilateral exceptions to these terms.
3. Authorized Access & Credential Responsibility
HIMS is an internal hospital operations platform restricted exclusively to authenticated, authorized personnel of Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS). Every authorized user is subject to strict credential custody standards:
3.1 Individual Responsibility
Each user account shall be assigned to a designated individual. Users are strictly responsible for maintaining the confidentiality of their authentication credentials. Account sharing, credential disclosure, and allowing unauthorized individuals to execute transactions under one's identity are strictly prohibited under hospital administrative policy.
3.2 Multi-Factor Authentication (MFA)
When Multi-Factor Authentication is enabled for an account or role, users must maintain active, exclusive control of their time-based one-time password (TOTP) authenticator device or verified email communication channel. Users must promptly report lost, damaged, or compromised authenticator devices to a system administrator.
3.3 Session Security and Terminal Discipline
In accordance with hospital information security standards, unattended sessions expire automatically after a defined inactivity period. Users must manually log out when vacating shared hospital terminals, dispensary workstations, or warehouse handheld units.
4. Role-Based Authorization & Least Privilege
Access to specific features (such as stock adjustments, batch receipts, purchase approvals, or user management) is strictly bounded by the assigned User Role under the Principle of Least Privilege:
| Assigned User Role | Authorized Functional Scope & Boundaries |
|---|---|
| Pharmacy Staff | Dispensing medicines to hospital wards, viewing medication inventory balances, recording lot numbers, and reporting critical supply shortages. |
| Warehouse Staff | Managing physical stock movements, staging deliveries, receiving supplier shipments, conducting bin putaway, lot tracking, and executing replenishment tasks. |
| Inventory Managers | Maintaining master item catalogs, authorizing procurement requests, reviewing supplier price quotes, generating demand forecasts, and approving verified stock adjustments. |
| System Administrators | User account provisioning, institutional role assignment, system security oversight, audit trail inspection, and technical maintenance. |
Attempting to bypass role boundaries, access unauthorized modules, or tamper with security checks violates institutional governance policy and the Cybercrime Prevention Act of 2012 (Republic Act No. 10175).
5. Data Accuracy & Supply Chain Accountability
Because HIMS manages vital medical commodities, emergency pharmaceuticals, and surgical supplies, accurate record-keeping directly impacts patient care and public safety:
5.1 Accurate Commodity Recording
Users must record accurate quantities, valid manufacturer batch and lot numbers, exact expiration dates, and truthful transaction reasons. Falsification, intentional misrecording, or negligent entry of inventory levels constitutes severe administrative misconduct.
5.2 Physical Stock Adjustments
Balance adjustments following cycle counts or physical inventories must reflect verified physical stock counts and strictly adhere to hospital audit governance and dual-custody verification protocols.
5.3 Procurement Integrity
Procurement requests, supplier quotations, and purchase order records must adhere to hospital procurement standards, Commission on Audit (COA) rules, and statutory government procurement regulations (Republic Act No. 9184) where applicable.
6. System Monitoring & Audit Logging Notice
Users are explicitly advised that all system activities within HIMS are actively monitored, recorded, and attributable:
- Immutable Audit Trail: An append-only audit trail records the identity of the actor, employee ID number, exact action taken, target record, old and new values, client IP address, device and browser context, approximate location, and timestamp.
- Evidence Preservation: Audit logs are preserved permanently for administrative accountability, forensic fraud investigation, and statutory oversight.
- No Expectation of Privacy: No expectation of personal privacy exists with respect to operational or inventory transactions conducted within the hospital inventory system.
7. Account Lifecycle & Offboarding
Upon a change of clinical role, inter-departmental transfer, resignation, retirement, or termination of employment:
- Access Termination: System accounts are immediately deactivated by hospital administrators to prevent unauthorized access.
- Preservation of Chain-of-Custody: Historical inventory records, transaction ledgers, and electronic signatures naming the employee as author or custodian are permanently retained to preserve clinical traceability and audit integrity.
8. Operational Nature & No Consumer Transactions
HIMS is strictly an enterprise institutional management platform. It does not provide consumer retail sales, customer subscriptions, or public payment processing services. Provisions of the Consumer Act of the Philippines (Republic Act No. 7394) concerning commercial consumer transactions, refunds, and warranties do not apply to the internal operational functions of this hospital platform.
9. Institutional Governance & Administration Contact
For inquiries regarding access permissions, credential resets, account provisioning, or policy interpretation, official communications should be directed to:
10. User Acknowledgment and Compliance Undertaking
I hereby acknowledge that I have read, understood, and agree to strictly comply with the HIMS Terms and Conditions, institutional operational governance policies, and statutory mandates governing the custody of hospital inventory. I understand that violation of these terms may result in administrative disciplinary action, revocation of system access, and legal prosecution under applicable Philippine laws.
Printed Name of Authorized Personnel
Employee ID Number
Designated Department / Unit
Signature of Personnel
Date Signed
11. Document Control & Approval Record
| Role / Action | Designated Office / Authority | Formal Verification | Action Date |
|---|---|---|---|
| Prepared By: | Hospital IT & Materials Management Division | [Technical Custodian] | September 2026 |
| Reviewed By: | Office of the Legal Counsel & Compliance Officer | [Legal Compliance Verified] | September 2026 |
| Approved By: | Medical Center Chief / Hospital Administrator | [Executive Directive Approved] | September 2026 |