Privacy Legislation Flashcards
(32 cards)
Why was the Personal Information Protection and Electronic Documents Act (PIPEDA) created?
- to protect personal information from being used for another purpose other than what it was collected for
- ensure that personal information is protected by the appropriate safeguards
What is the purpose of the Federal Privacy Act?
extend the present laws of Canada that protect the privacy of individuals with respect to personal information held by government institutions as well as providing individuals the right to access that information
What is the purpose of the anti-spam legislation (CASL)?
-protect consumers and businesses from the misuse of digital technology (includes spam and electronic threats)
- help businesses stay competitive in a global digital marketplace
What is the Personal Health Information Protection Act of Ontario (PHIPA)?
Ontario’s health-specific privacy legislation
What is the purpose of PHIPA?
- governs how personal health information may be collected, used, and disclosed within the health sector
- creates a consistent approach to protecting information across the health sector
- gives individuals greater control over how their personal information is collected, used, or disclosed as well as the right the access and request corrections to their information
- provides a means for review and resolution of complaints when privacy rights have been violated
Who does PHIPA regulate?
health information custodians, individuals, and organizations
How does PHIPA define collect?
gather, acquire, receive, or obtain the information by any means from any source
How does PHIPA define use?
view, handle, or otherwise deal with the information
How does PHIPA define disclose?
make the information available to another health information custodian or another person
What is a health information custodian (HIC)?
person who operates an organization that delivers healthcare as a solo practice, group practice, or organization that has a reason to know personal health information
What is a agent of a HIC?
person that acts for or on behalf of the custodian
What is considered personal health information?
information that can identify an individual that relates to:
- physical or mental health
- family health history
- care provided to the individual
- payment
- eligibility
- health card number
- donation or testing of body parts/body substances
- identification of the substitute decision maker
- non-health care related personal information
How many PHIPA principles are there?
10
What is PHIPA principle 1?
Accountability - HIC’s must take steps to ensure that records are kept in a manner that ensures that legislation and professional standards are respected
What is PHIPA principle 2?
Identifying purpose - HIC’s and agents must ensure that the purpose for collecting, using, disclosing, or retaining personal health information is clear to the individual
What is PHIPA principle 3?
Informed consent - there must be informed consent by the individual or by their substitute decision-maker when information is being collected, used, or disclosed
What is PHIPA principle 4?
Limiting collection - HIC’s must ensure that all forms of personal health information are collected for:
a) the purposes for which they are required
b) the purposes for which individuals provide consent
What is PHIPA principle 5?
Limiting, use, disclosure, and retention - HIC’s must ensure that use, disclosure, and retention policies and standards are followed
What are legally permitted uses of personal health information?
- for the purposes that is was created/collected
- for planning, delivering, or monitoring services for which the custodian allocates funding or other resources
- for risk management or other activities to maintain quality of care
- for educating agents
for obtaining payment and verifying or reimbursing claims - for research conducted by the custodian
What are legally permitted disclosures of personal health information?
- within the circle of care
- outside the circle of care with consent of the patient
- to the substitute decision maker
within the organization for audit or accreditation purposes - to a successor
What is PHIPA principle 6?
Accuracy - HIC’s are responsible for ensuring records are accurate, complete, and up to date
What is PHIPA principle 7?
Safeguards - HIC’s must take steps against theft, loss, and unauthorized use or disclosure as well as ensuring records are protected against unauthorized copying, modification, or disposal
What is PHIPA principle 8?
Transparency - HIC’s must display/have an available written public statement about their privacy policies and patient/client rights
What is an example of a privacy breach?
- records are seen by someone who should not see them
- emails, texts, phone calls are sent to the wrong person
- paper records are stolen
- electronic records are accessed by people who should not have access
- conversations being overheard by people outside of the circle of care