Automated License Plate Reader (ALPR) Program
APPLICATION:
PIH Health Whittier Hospital (PHWH), PIH Health Downey Hospital (PHDH), PIH Health Good Samaritan Hospital (PHGSH), and PIH Health Physicians (PHP)
PURPOSE:
Establish standards for collection, use, retention, sharing, auditing and protection of ALPR information to support safety, security, parking management and investigations. PIH Health currently only operates an ALPR system on the PHWH campus but reserves the right to expand use to other PIH Health campuses and properties as the needs of the organization require. This policy would govern any such expanded use.
DEFINITIONS:
Automated License Plate Reader (ALPR) System: A searchable computerized system resulting from the operation of one or more fixed or mobile cameras combined with computer software capable of capturing images of vehicle license plates and converting the plate characters into machine-readable data.
Automated License Plate Reader (ALPR) Information: Data or information collected or generated through the operation of an ALPR system, including license plate numbers, images, date and time stamps, and vehicle location information.
Authorized User: An employee or contractor who has received written authorization and training permitting access to ALPR systems or ALPR information.
ALPR Program Administrator: The designated PIH Health leader responsible for oversight, administration, security, and compliance of the ALPR program.
Hit: A system-generated notification indicating a detected license plate matches information contained in an authorized law enforcement, hospital security, or approved watch list database.
Watch List: A list of license plates associated with authorized security concerns, investigations, restraining orders, trespass advisories, law enforcement notices, or other legitimate safety-related purposes.
POLICY:
Establishes requirements for the use, protection, retention, and sharing of Automated License Plate Reader (ALPR) data to support PIH Health security operations and legal compliance.
PROCEDURE:
A. Program Oversight
- The Parking Operations Manager shall serve as the ALPR Program Administrator or may designate an appropriate management representative.
- The ALPR Program Administrator is responsible for:
- Oversight of ALPR operations. Approval of authorized users.
- Security and protection of ALPR information.
- Ensuring compliance with applicable laws and PIH Health policies.
- Conducting periodic reviews and audits of the program.
- ALPR systems may only be installed and operated with approval from PIH Health leadership.
B. Authorized Uses
- ALPR systems and ALPR information shall be used only for legitimate hospital business purposes, including:
- Protection of PIH Health patients, visitors, physicians, staff, volunteers, and property.
- Monitoring vehicle access to hospital campuses and parking facilities.
- Parking enforcement, occupancy analysis, and parking resource management.
- Investigation of criminal activity occurring on or affecting PIH Health property.
- Identification of vehicles associated with:
- Workplace violence concerns
- Active restraining orders
- Criminal trespass advisories
- Threat assessments
- Missing persons investigations
- Law enforcement bulletins
- Other documented safety concerns
- Assistance to law enforcement agencies in accordance with applicable legal requirements.
- ALPR systems shall not be used:
- For personal purposes.
- To monitor individuals based on race, ethnicity, religion, gender, sexual orientation, national origin, disability, or other protected classifications.
- For unauthorized surveillance unrelated to legitimate business or security purposes.
C. Authorized Users
- Access to ALPR systems and ALPR information is limited to employees who require such access to perform assigned job responsibilities.
- Authorized users may include:
- Parking Attendants
- Parking Managers
- Parking Supervisors
- Security Officers
- Security Supervisors
- Security Managers
- Director of Security
- Emergency Management personnel with approved access
- Information Technology personnel supporting system operations
- Other personnel specifically approved by the ALPR Program Administrator
- Enterprise Risk Management for the facilitation or performance of investigation
- Authorized users shall access ALPR information only for approved business purposes.
- Unauthorized access, use, disclosure, or dissemination of ALPR information may result in disciplinary action up to and including termination.
D. Data Collection and System Operations
- ALPR cameras may be deployed at:
- Hospital entrances and exits
- Medical office buildings and exits
- Parking structure entrances and exits
- Surface parking lots
- Emergency Department vehicle access points
- Other locations approved by Security leadership
- ALPR systems shall collect only information reasonably necessary to support authorized purposes.
- The presence of ALPR systems may be communicated through signage where appropriate.
- The ALPR system shall operate in a manner consistent with applicable federal, state, and local laws.
E. Data Security
- ALPR information shall be maintained in secure systems with appropriate administrative, technical, and physical safeguards.
- Access shall be controlled through user authentication, role-based permissions, and password security measures.
- Any suspected unauthorized access, disclosure, or breach involving ALPR information shall be immediately reported to:
- Security leadership
- Information Security
- Compliance, as applicable
- Audit logs shall be maintained to document user activity and access to ALPR information.
F. Retention of ALPR Information
- ALPR information shall be retained for no longer than twelve (12) months unless needed for:
- Criminal investigations
- Workplace violence investigations
- Internal security investigations
- Litigation holds
- Regulatory requirements
- Law enforcement purposes
- Other documented operational needs approved by the ALPR Program Administrator
- Information retained beyond twelve (12) months shall be documented and justified.
- Upon expiration of the retention period, ALPR information shall be securely deleted or destroyed in accordance with PIH Health information management standards.
G. Access Documentation and Auditing
- Records shall be maintained or accessible identifying:
- User accessing information
- Date and time of access
- Purpose of access
- Search criteria utilized
- Any information shared externally
- Security leadership shall conduct periodic audits to verify:
- Appropriate use of the ALPR system
- Compliance with retention requirements
- Accuracy of user permissions
- Adequacy of system safeguards
3. Findings of audits shall be documented if applicable and corrective action taken when necessary.
H. Information Sharing
- ALPR information may be shared:
- Within PIH Health for approved operational and security purposes.
- With law enforcement agencies when legally authorized or required.
- In response to subpoenas, court orders, or other lawful requests.
- Any sharing of ALPR information shall be limited to the minimum information necessary to accomplish the authorized purpose.
- ALPR information shall not be sold under any circumstances.
I. Privacy Protections
- ALPR information shall be treated as sensitive information.
- Images and data captured by ALPR systems are collected from areas generally visible to the public where there is no reasonable expectation of privacy.
- PIH Health shall take reasonable measures to protect against unauthorized:
- Access
- Use
- Modification
- Disclosure
- Destruction
- Employees shall comply with all applicable privacy, confidentiality, and information security requirements.
J. Compliance
- Violations of this policy may result in:
- Revocation of ALPR access.
- Corrective action.
- Disciplinary action up to and including termination.
- Referral to law enforcement when appropriate.
- All personnel are expected to report suspected misuse of ALPR systems or ALPR information.
REFERENCES:
External References:
California Civil Code §§ 1798.90.5 through 1798.90.55 (Automated License Plate Recognition Systems)
California Civil Code § 1798.29
HIPAA Privacy and Security Rules, as applicable
California Health and Safety Code requirements, as applicable
Internal References:
Parking Management Procedures
Information Security Policies