Privacy and Health Information Act Flashcards
Health Information
- Disclosing
Needs consent
Exceptions:
- To another custodian for proper use of health information (Section 27)
- Sometimes family members
- Quality Assurance
- Court
Health Information Act
Provincial
How Custodians and Affiliates collect and disclose health information
- AHS
- Employee/Contractors of AHS
Health Information
Diagnostic Information
- Heath service, amount paid for service
Registration Information
- Demographic, Billing, Location
Health Information
- Collecting
Have to be directly provided by individual
Some exceptions:
- Authorized by another enactment
- Necessary to carry out a purpose
Health Information
- Uses
- Providing Health Services (Preventing disease, Diagnosing)
- Determining Eligibility
- Conducting Investigations
- Quality Assurance
Freedom of Information and Protection of Privacy Act
Public Provincial
How Public bodies collect and disclose personal information
FOIPPA
- Collecting Information
Provincial Public
Can only collect personal information if:
- Authorized by legislation
- Law enforcement
- Necessary for action of public body
PIPA
- Collecting Information
Provincial Private
Can only collect personal information if:
- Consent is given by individual
- No consent in specific cases
Health Information
- Correction
Individual can request a correction if they believe an error has been made or info has been omitted
- Has to be responded to within 30 days
Who is notified when a breach occurs
- Office of the Information and Privacy Commissioner
- Privacy Commissioner
- Minister
- Individual’s whose information was leaked
Personal Information
Any information that can be used to identify an individual
- Name
- Sex
- Race
Personal Information Protection and Electronic Documents Act
Private Federal
Affiliates
Ones hired or contracted by the Custodians
- IT Workers
- Employees
- Volunteers
Personal Information Protection Act
Private Provincial
How Private bodies collect and disclose personal information
When do breaches have to be reported
Reasonable person would consider there to be a risk of harm to individuals whose information was breached