Week 4: Privacy Legislation Flashcards
Personal Information Protection and Electronic Documents Act (PIPEDA)
Federal privacy law for private-sector organizations
What does the PIPEDA law apply to?
Collection, use and disclosure of personal info
What is the purpose of PIPEDA?
- people have the right to access personal info and to challenge its accuracy
- personal info can only be used for the purposes for which it was collected
- must obtain consent again if being used for diff purpose
- personal info protected by safeguards
What is meant by “substantially similar”?
Some provinces have privacy laws deemed substantially similar to PIPEDA and this means that in some circumstances the provincial law applies instead of the federal law but this may differ based on the case
Federal privacy act purpose
Extend the present laws of Canada that protect the privacy of individuals personal info held by a governmental institution and that provide individuals w a right to access that info
In which selected domains does the federal government run health care?
- department of national defence
- correctional service of canada
Canada’s anti-spam legislation (CASL) purpose
- to protect consumers and businesses from the misuse of digital technology, including spam and other electronic threats
- to help businesses stay competitive in a global digital marketplace
How can you make sure you’re complying with CASL?
- dont send messages without consent
- provide an opportunity for clients to say no to commercial electronic messages
- clearly identify yourself and the organization (ie. business name, your name, current mailing address, phone number/email, an unsubscribe mechanism)
- be truthful in advertising (ie. specify whether taxes are included)
What is the Personal Health Information Protection Act of Ontario (PHIPA)?
Ontario’s health-specific privacy legislation
What is the purpose of the Personal Health Information Protection Act of Ontario (PHIPA)?
- governs how personal health info may be collected, used and disclosed within the health sector
- regulates health info custodians, individuals and organizations that receive health info from custodians
- gives individuals greater control of how personal info is collected, used and stored
PHIPA terms
Collect
Use
Disclose
Collect
Gather, acquire or obtain the info by any means from any source
ex. referral
Use
View, handle or otherwise deal w the info
Disclose
Make the info available to another health info custodian or another person
What does PHIPA require health info custodians to do before personal health info is collected, used or disclosed?
Obtain consent!!
What rights does PHIPA provide for indivduals?
- right to access and request correction to personal health info
- independent review and resolution of complaints through the Office of the Information and Privacy Commissioner of Ontario (IPS) when privacy rights have been violated
What is a health information custodian (HIC)?
A person who operates an organization that delivers healthcare as a solo practice, group practice or organization (ie.hospital, LTC) that has a reason to know personal health info
Examples of HICs
- health care practitioners
- LTC homes
- hospitals
- pharmacies
- psychiatric facilities
Agent of a HIC
A person that with the authorization of the custodian, acts for or on the behalf of the custodian in respect of personal health info for the purposes of the custodian, not the agent’s own purposes
Examples of agents of a HIC
- front desk clerk at a clinic
- students
Administrative duties of HICs
- develop and comply with policies with respect to when, how and the purposes for collection, use, modification and disclosure of PHI and the administrative, physical and technical safeguards that are maintained
- designate a contact person
- display a written public statement