The Utah County Board of Commissioners approved emergency-management access to a state special‑needs registry while directing staff to tighten privacy safeguards and work with civil attorneys on language. The request would assign three logins for county emergency-management personnel so responders can identify and assist vulnerable residents in emergencies.
An emergency-management representative told the commission the access would be limited and that the three individuals are vetted and background-checked. "We currently maintain our own notification system that we have to hold a lot of, individual information. And so we do treat that with sensitivity and understanding," the representative said.
Commissioners voiced concern about protecting personally identifiable information and whether those records could be released under GRAMA. The emergency-management staff and county attorney staff said the registry entries would not be generally available via public records requests and recommended limited-logins and redaction where appropriate. Ben Benoit (identified during the discussion) confirmed protections and said the registry would remain private for operational use.
Several commissioners recommended formalizing training or nondisclosure protocols for anyone with access to sensitive databases. One commissioner suggested using an existing county learning-management system (Relias) to provide annual training for employees with access to personally identifiable information. Emergency-management staff said federal and state cybersecurity grant funding opportunities might be available to support training and technical protections.
The commission approved the item after a motion and second; commissioners asked staff to follow up with the civil division to refine the final language and noted the county may adopt or adapt sheriff's-office policies to provide consistent countywide protections.
The approval included direction to confirm vetting procedures for account holders and consider a county-level training requirement for employees who handle sensitive personal data, and staff agreed to pursue cybersecurity grant opportunities to strengthen protections.