Privacy of Information Flashcards
(36 cards)
Acts/ Statues
Most commonly though of form of law (BC Legislation).
PIPA, HPA, HPOA
Regulations
Developed by the government to establish the workings of a regulatory college.
Bylaws
Made by the regulated college to manage internal operations
Case Law
Court decisions used as a guide by lawyers and judges when similar situations arise
Guiding Documents
Document published by the college to guide clinical practice such as Standards of Practice and Policy statements.
These documents are not “law”.
What are some provincial and federal privacy organizations?
Office of the Information & Privacy Commissioner of BC
-enforce the privacy of information
Government of Canada Protection Act
What are the acts under of Office of the Information & Privacy Commissioner of BC?
Freedom of Information and Protection of Privacy Act (FOIPPPA-BC).
Personal Information Protection Act (PIPA-BC).
Freedom of Information and Protection of Privacy Act (FOIPPPA-BC)
protection act used in public health care settings (hospitals, health authorities, MSP).
guarantees the right of the public to gain access to their information and request corrections.
does not apply to information gathered by private sectors.
Personal Information Protection Act (PIPA-BC)
applies to Kinesiologists working in private settings.
BC-based business must comply with this act.
personal information cannot be collected, used, or disclosed without prior informed consent.
What act falls under the Government of Canada Protection Act?
Personal Information Protection and Electronic Document Act (PIPEDA)
-government of Canada enforcement of information privacy
-law giving individuals the right to access and request corrections about their personal information
What are you protecting?
Personal Information
Confidentiality
Personal Information
Any identifiable items about a person including gender, age, ethnic origin, identification numbers, financial information including credit card information, personal health information, religious affiliations, travel and donation history, personal henbits, and personal history.
Any and all information collected from a client (health or othterwise) cannot be shared without informed consent from said client.
Confidentiality
Maintaining confidentiality is fundamental to any practicing Kinesiologist and is central to the client-therapist relationship.
-protecting information through appropriate consent and security means
-disclosing only what have been authorized
-destroying information that is no longer required or has reached its retention limit
How are you protecting?
Use secure files.
Encrypt sensitive data.
Use encrypted communication channels.
User authentication.
Role-based access.
Session management.
Electronic Health Records (EHR) systems
Secure devices.
Encrypt sensitive data
all patient data stored digitally should be encrypted both at rest (stored data) and in transit (data being transmitted) to prevent unauthorized access.
Use encrypted communication channels
utilize secure, encrypted email services or patient portals for communicating sensitive information; has to be HIPA approved.
User authentication
implement strong password policies, multi-factor authentication (MFA), and user authentication protocols to ensure that only authorized personnel can access patient data.
Role-based access
restrict access to patient information based on the user’s role within the organization.
Session management
automatically log out users from systems after a period of inactivity to reduce the risk of unauthorized access.
Electronic Health Records (EHR) systems
use certified and secure EHR systems that comply with relevant legal standards from handling patient data.
paper medical records must be kept in a locked file, at rest or in travel (locked in folder in vehicle).
Secure devices
ensure that all devices used in access patient information (computers, tablets, smartphones) have up to date antivirus software, firewalls, and are configured with security settings.
What are the 10 privacy principles?
Accountability
Identifying Purposes
Consent to Collect, Use and Disclose
Limiting collection
Limiting Use, Discloser, and Retention
Accuracy
Safeguards to Protect Information
Openness
Individual Access
Challenging Compliance
Accountability
Kinesiologists are responsible for the personal information of both the clientele and employees.
Privacy Officer must be appointed to work in compliance with PIPA-BC.
Privacy Officer Contact info needs to be accessible to the public.
Sole proprietor/self-employed Kinesiologists all need their own privacy policy document.
What are the responsibilities of the Privacy Officer?
Help clients understand what happens to their information.
Develop and implement organizations policies and procedures.
Train employees about privacy policies and confidentiality.
Respond to inquiries and complaints.
Oversee privacy practices.
Ensure compliance with government legislation.