Article I – Summary
- Purpose. The protection of confidential business information and trade secrets is vital to the interests and the success of the RARE Foundation (formerly known as EveryLife Foundation for Rare Diseases and herein referred to as the “Organization”). The Organization’s governing board and its key employees will, by necessity, be exposed to confidential, proprietary, and in some cases, legally privileged information through board meetings and board communications. This policy preserves and protects this sensitive information from premature and unauthorized disclosure. It maintains public trust by ensuring candid and productive internal discussion and by protecting the privacy and security of individuals’ health information.
This policy in no way diminishes the Organization’s duty to remain publicly accountable. The Organization maintains its rigorous commitment to the timely, accurate, and transparent reporting of its financial health, legal standing, and community impact consistent with the highest standards of nonprofit governance.
- Scope. This policy covers the Board of Directors and the Organization’s staff members who attend partial, full, or closed-session board meetings.
- Responsibilities. The ability of directors and officers of the Organization to engage and deliberate privately and freely in board meetings and related correspondence is essential to the Organization’s wellbeing. A breach of confidentiality occurs when sensitive information relating to the board is shared prematurely or disclosed without authorization.
Directors, officers, and Organization employees must therefore become familiar with this policy and continuously maintain a principle of default confidentiality. Any suspected or actual breach of confidentiality must be reported immediately to the Board Chair, Chief Executive Officer (CEO), or Chief Operating Officer (COO).
Article II – Definitions
- Confidential Information. Confidential information is any non-public information—in any format—related to the Organization’s donors, business, operations, stakeholders, personnel, or internal discussions.
Confidential Information includes, but is not limited to, board discussions, data, records, documents, and deliberations relating to the Organization or the Board that are not already publicly available.
Examples include:
- Internal Board Deliberations. All conversations and discussions held during Board meetings, committee meetings, or related communications are deemed confidential and private by default.
- Board Votes. Individual board votes shall be confidential.
- Personnel Matters. Performance reviews, compensation information, disciplinary actions, and contract negotiations.
- Financial Strategy. Detailed budgets, non-public investment strategies, specific fundraising goals, and donor/prospect identification information.
- Legal/Risk Management. Attorney-client privileged communication, impending legal actions, and compliance or audit findings.
- Sensitive Strategic Planning. Drafts of strategic plans, market analysis, merger/acquisition discussions, and proprietary programmatic research and information.
- Patient and Health Records and Information. Personally identifiable information, past, present, and future mental and physical health conditions, delivery of medical, therapeutic, or assistive services and supplies, and general health information.
- Internal Board Deliberations. All conversations and discussions held during Board meetings, committee meetings, or related communications are deemed confidential and private by default.
- Breach. A breach is defined as any unauthorized access, use, disclosure, loss, destruction, or alteration of the Organization’s confidential information or privileged information, whether intentional or unintentional, electronic, or physical.
- A minor breach is an unintentional or low-impact disclosure that does not materially harm the organization.
- A significant breach is a disclosure of sensitive information that results in tangible harm—financial, legal, reputational, or strategic.
- A minor breach is an unintentional or low-impact disclosure that does not materially harm the organization.
Article III – Default Principle of Confidentiality
Treatment of Information
- All Board conversations, discussions, materials, and related deliberations are deemed confidential and private unless declassified under Article IV of this policy.
- Directors, officers, and any staff member attending a Board meeting are prohibited from disclosing confidential information with any person who is not authorized to receive it. Confidential information may only be shared within the Organization on a legitimate need-to-know basis, as required by law, as necessary to consult with legal counsel, auditors, or other advisors retained by the Organization, or as declassified under this policy.
- No implied release. Unless explicitly designated as public, all issues and related discussions remain confidential.
Article IV – Declassification and Releases
- Only the Board Chair (in matters of governance) or the CEO (in matters of management) has the authority to explicitly release or declassify confidential information. To declassify confidential information, the Board Chair or CEO shall:
- Document the rationale in writing.
- Seek legal review if warranted.
- Disclose the declassification to the Board.
- File and preserve the document to serve as the permanent record of the declassification.
- The authorized party must specify exactly which information is being released and to whom.
- If the release involves highly sensitive material, the decision must be made in consultation with legal counsel.
- The authorized party must recuse themselves from making a release decision if they have a conflict of interest.
- If the Board Chair or CEO has a conflict of interest and must recuse themselves from a release decision, the authority shall pass as follows:
- For governance matters, to the Vice Chair.
- For management matters, to the COO.
- If the Vice Chair or COO is also conflicted, the decision shall be made by the Governance Committee (for governance matters) or the Executive Committee (for management matters).
- If the Governance Committee/Executive Committee determines that the matter warrants full board consideration, the committee may refer the decision to the full Board of Directors.
Article V – Obligation and Duration
The obligation to maintain confidentiality is a continuing duty:
- During Service: The duty applies continuously throughout the individual’s term on the board or employment.
- Post-Service: The duty to protect the Organization’s confidential information continues indefinitely after a board member’s term ends, or an employee leaves the Organization.
Article VI – Procedures
Typically, a breach is identified when a board member, employee, or third party reports the unauthorized disclosure. All individuals who report suspected or actual breaches of confidentiality in good faith are protected under the Organization’s Whistleblower Policy. Retaliation against any person making such a report is strictly prohibited. For details, refer to the Organization’s Whistleblower Policy.
Protocols
- Assessment. The Board Chair, CEO/COO assesses scope, damage, and reporting needs.
- Minor Breach. The CEO/COO (in consultation with the Board Chair) documents their due diligence and communicates the impact of the breach to the violator. The policy is reviewed and re-signed.
- Legal Consultation. If applicable, the CEO/COO will engage legal counsel.
- Organization Operations. If applicable, the Executive Leadership Team manages internal strategy and recovery operations.
- Major Breach Investigation. In the event of a significant breach, the Board Chair shall appoint a disinterested person(s) to investigate and prepare draft findings and task the Executive or Governance Committee (for board breaches) or the CEO/COO (for employee breaches) with making the final determination.
- Board Report. After gathering documentation, reviewing bylaws, and interviewing the accused, the disinterested person(s) will present findings to the committee or CEO/COO—ensuring the accused is absent from deliberation. The accused may make a formal defense to the committee.
- Final Determination. The board committee or CEO/COO reviews the evidence to determine if a material violation of the policy occurred and the appropriate remedy.
- When the accused is a board member, the board committee makes the final decision and determines the consequences. If necessary, the committee may escalate the final determination to the full board.
- When the accused is an employee, the CEO or COO makes the final decision to determine if a material violation of the policy occurred. The board committee’s role is limited to determining whether the matter constitutes a significant breach that has governance, legal, or fiduciary implications requiring board notification or action. The CEO, in consultation with the Board Chair, will identify the appropriate consequences.
Article VII – Compliance and Consequences
Violation of this Board Meeting Confidentiality Policy is considered a breach of fiduciary duty and may cause severe harm to the Organization’s reputation, legal standing, and finances.
- Board Members: Any board member who violates this policy may be subject to sanctions, including censure, required training, and ultimately, immediate removal from the Board of Directors in accordance with paragraph 3.07 of the Organization’s Bylaws.
- Key Employees: Any key employee who violates this policy is subject to disciplinary action, up to and including termination of employment.
Article VIII – Governance and Review
The Board of Directors reviewed and adopted this policy on December 8, 2025. Each year, all Board members and key employees will review and sign this policy to reaffirm compliance. New Board members will be introduced to these protocols during onboarding.
Governance
- Officer, Director, and Key Employee Conflict of Interest Policy
- Board Meeting Confidentiality Policy
- Bylaws
- Diversity Policy
- Fundraising Disclosure Statement
- Funding Policy
- IRS Determination Letter
- Whistleblower Policy