Save Online law articles on social network:
Showing posts with label health information. Show all posts
Showing posts with label health information. Show all posts

Article: B.C. residents' health records will be secure with U.S. company, Collins says

The British Columbia finance minister has waded into the privacy/outsourcing debate to try to reassure the public that privacy will be protected if the BC government outsources medical records management to a subsidiary of a US company.

B.C. residents' health records will be secure with U.S. company, Collins says

Thu Aug 19, 8:52 PM ET

VICTORIA (CP) - The privacy of British Columbians will be protected if Victoria allows a U.S.-based firm to manage the province's medical records, says Finance Minister Gary Collins.

The government is considering giving the contract to the Canadian subsidiary of a company called Maximus.

"We are dealing with a 100 per cent Canadian subsidiary of the company," Collins said. "The entire board of directors are Canadian citizens.

"We also are working with the privacy commissioner but our number one issue is the security of people's private information and government will not sign a contract unless we're completely comfortable that British Columbia citizens medical records are completely private," Collins said.



More of the story can be found here.


Read more from this post in Online law articles »

Report from the CBA in Winnipeg

I just returned from a very good few days at the Canadian Bar Association’s annual get-together
in Winnipeg, Manitoba. There were quite a few privacy-related events during the
two-day substantive program.



The first event was more administrative than anything. It
was the meeting of the CBA Privacy Law subsection. The meeting was chaired by Brian Bowman, the section
secretary who is also a privacy lawyer at Pitblado
in Winnipeg. We reviewed the privacy-related resolutions passed by the CBA
general meeting and the extensive activity undertaken by the section during its
first year. (I’m told that it has an unprecedented level of activity for a
brand-new section.) The next year should be just as busy.



David
Young
, who chairs the Advocacy and Government Relations subsection led a
discussion of the contribution that can be made when the Personal Information Protection
and Electronic Documents Act
(Canada) comes up for full review in 2006.
I expect there will be no shortage of suggestions. Ann Goldsmith, legal counsel
to the Office of the Privacy Commissioner
mentioned they have many suggestions already, with deemed consent for due
diligence review in the course of sales of businesses near the top of their list.



Cross-border privacy issues



The second event was also on Monday: a panel discussion of
cross-border privacy issues. Moderated by David Young of Lang Michener, the panel was composed
of Simon
Chester
of McMillan Binch,
Evelyn Sullen of Volkswagen of America Inc.
and me. The presentation that I gave is available here and I’ll try to
get permission to post Simon and Evelyn’s powerpoints.



Simon Chester began with a presentation on European privacy
law, using three European women as illustrations of the law’s development and
enforcement: (a) Bodil Lindqvist,
(b) Naomi Campbell (see Campbell v. MGN Limited, [2004] UKHL 22) and (c)
Princess
Caroline of Monaco
. The first example demonstrates how some authorities in Europe
are being much more aggressive in enforcing the Data Protection Directive,
including against clearly non-commercial and “domestic” use of personal
information. The latter two examples show how the balance between privacy and
freedom of the press are moving clearly towards privacy in Europe. (We will not
likely see any of the Campbell/Caroline examples in Canada soon, as PIPEDA
specifically does not apply to information collected for “artistic, literary or
journalistic purposes. Any similar complaints against paparazzi will have to be
grounded in the independent tort of “invasion of privacy”, which is being
slowly developed in the Canadian provinces that do not have a statutory tort.) Interested readers should take a look at Simon's comprehensive paper, which is available here.



Evelyn’s presentation included an overview of the sectoral
laws in the United States (COPPA, HIPAA, GLB, etc.) and a look at Volkswagen USA’s
experience in addressing PIPEDA and the European privacy rules. It was
estimated that VW spent about $500K in complying with PIPEDA, including postage
for sending a “grandfathering/opt-out” letter to all customers in their
database.



One of the questions posed was whether to adopt a fragmented
privacy management system within an international company or should one try to
develop a policy that complies with all legal regimes in which the company
operates. Much of what was discussed in the international context is also
applicable within the Canadian federal system. We are dealing with a number of
privacy regimes in this country, including the present 100% overlap between
federal and provincial laws in Alberta and British Columbia. (I am told that
the Order-in-Council to declare AB and BC’s laws “substantially similar” to
PIPEDA is on the agenda for the next meeting of the federal cabinet.) We also
have an interesting overlap in the health privacy arena. Alberta, Saskatchewan
and Manitoba each have provincial health information laws and none of them are
expected to be declared substantially similar. This means that physicians in
private practice, who are engaged in “commercial activities”, must comply with
PIPEDA and with the local health information law. In most cases, the healthcare
professionals can design their programs to comply with the most demanding
individual rules and principles. In some cases, this is not always possible as
some contradictions may appear between the laws.



Update on Canada’s Privacy Laws



On Tuesday, Brian Bowman moderated a panel of
representatives from various privacy commissioners’ offices. On the panel was
Heather Black, Assistant Privacy Commissioner of Canada; Brian Loukidelis,
Information and Privacy Commissioner from British Columbia, Barry Tuckett, Manitoba’s
Ombudsman and Mary O'Donoghue, legal counsel to the Information and Privacy Commissioner of Ontario.
Each of the panelists gave an update on developments in their respective
jurisdictions, beginning with Heather Black’s overview of the roll-out of
PIPEDA. Heather made an interesting distinction between systemic and more
accidental violations of PIPEDA. Systemic violations are those which
demonstrate a systemic problem, such as a lack of awareness, policies or
procedures. Accidental ones are simply where a company’s established – and otherwise
compliant – procedures and policies are not followed, resulting in a breach.
Both are problems, but the balance of complaints is leaning further away from
systemic breaches. Heather also mentioned that the number of complaints that
are “well founded” has declined (to the end of 2003) to around 20% from 45% a
couple of years before.



Mary O'Donoghue, from the Ontario Information and Privacy
Commissioner’s Office, provided a very good and brief overview of the Personal Health
Information Protection Act
, 2004.



At the moment, I’m a little jetlagged. I’ll try to write
more about the conference when I’ve got a few more minutes and once I’ve heard
back from my co-panellists about posting their materials.


Read more from this post in Online law articles »

IPC - Health Information Protection Act - Frequently Asked Questions

The Ontario Information and Privacy Commissioner has just released a very useful list of frequenly asked questions related to the Personal Health Information Protection Act (Bill 31 or PHIPA). A good starting point for anyone who wants to understand this complicated statute ...

IPC - Health Information Protection Act - Frequently Asked Questions:

"Note: This FAQ provides a general overview of the Health Information Protection Act, 2004, S.O. 2004, c.3.. This document does not include references to the Regulations, since currently there are no Regulations under the Act. As such, this document should be read in conjunction with the Act and any Regulations that will be made under the Act. The information contained on this web page is for general reference purposes only and should not be construed as legal advice. You should consult with your own solicitor for all purposes of interpretation."

Read more from this post in Online law articles »

Task Force recommends sharing personal health information with police in Newfoundland

The Newfoundland governnment established a task force in December 2003 to address the abuse of OxyContin (aka Hillbilly Heroin). The Task Force has released its report , which notably includes recommendations about information sharing between healthcare professionals and the police where abuse is suspected. The Task Force reccomends that existing monitoring programs be expanded and that legislation be passed to allow sharing information with law enforcement and professional regulators:



46) The Task Force recommends that the Provincial Government make
the necessary legislative changes to the Medical Act to permit the release
of appropriately screened information sharing from MCP [Medical Care Plan]and the
NLPDP [Newfoundland and Labrador Prescription Drug Plan] to law enforcement agencies in the province, when there is a
reasonable belief of fraudulent or criminal activity. The results of this
information sharing should be evaluated to determine its effectiveness.




In addition, the Provincial Government should consider laying the framework for a realtime
monitoring program. This program is already built into the current proposal for the
Newfoundland and Labrador Pharmacy Network. The proposed Pharmacy Network is the
second component in the development of the Health Information Network and Electronic
Health Record for the province. It is an information system that will create individual
prescription profiles for everyone who receives medications in the province. Extensive
consultations with over 800 stakeholders including health care professionals from many
different disciplines (e.g. physicians, pharmacists, social workers, and nurses), regional
health boards, regulatory bodies, and the DHCS, informed the work of the Project team.


Pharmacies in the province maintain computerized medication histories for patients;
however, these histories are fragmented across all pharmacies, hospitals, and physicians
that patients use. The proposed pharmacy network will help health care providers make
better-informed and timely decisions about each patient’s care. The network will provide
tools and processes to support electronic prescribing, medication dispensing, compliance
monitoring, research, and policy development. Increased access to, and use of,
appropriate medication information may enhance the quality of care, improve patient
safety, facilitate accountability, and promote the cost effective use of medications.


The Pharmacy Network will provide health care providers with the opportunity to deliver
better patient care and provide increased patient safety.


It is recognized that the collection of this information is only one step toward addressing
the problem. Legislation will be required to ensure complete submission of data by
pharmacies, allow for reporting to the police of individuals who fail to respond to other
interventions, and to ensure that physicians identified as having concerning prescribing
patterns are thoroughly investigated. Human resources will be required to support such a
monitoring program, so that the information collected is acted on in a timely and
appropriate manner.




Here is the provincial government's press release on the topic:


OxyContin Task Force report released:

"August 3, 2004

(Health and Community Services)






OxyContin Task Force report released


Greater education and public awareness, improved mechanisms for information sharing and stronger collaboration among the medical and policing communities are some of the findings and recommendations outlined in the final report from the OxyContin Task Force. Elizabeth Marshall, Minister of Health and Community Services, joined her colleagues Tom Marshall, Minister of Justice and Attorney General, and Tom Hedderson, Parliamentary Secretary to the Minister of Education, today in releasing the report.


"The misuse and abuse of prescription drugs, like OxyContin, is complex and addressing the problem will require more work with our partners," said Minister Elizabeth Marshall. "I would like to thank the task force members for their dedication, contributions and continued efforts. All of the recommendations put forward will be given serious consideration."


The task force final report outlines areas in which OxyContin is most prevalent in the province, including rising access to the drug among adolescents, an increase in the number of prescriptions and increased criminal activity to access OxyContin. It also states there is no mechanism for sharing information with police when double-doctoring is suspected.


"Our recommendations reflect the information its members have gathered from professionals, community groups and individuals directly affected by this drug," said Beverley Clarke, chair of the OxyContin Task Force. "The task force believes a comprehensive approach will help address the numerous issues arising from the misuse and abuse of OxyContin and other narcotics. A collaborative effort is necessary to achieve and sustain long-term results."


The report offers 50 recommendations including the need for further education and prevention initiatives, additional treatment options, harm reduction strategies and legislative amendments.


Government intends to act immediately on several recommendations including the implementation of tamper-resistant prescription pads, continuing education for health professionals and youth and establishing provincial guidelines for methadone treatment. Other recommendations will require further analysis added Minister Elizabeth Marshall.


The Department of Justice supports recommendations relating to policing including continued focus on law enforcement training and allocation of police officers. "Policing plays a significant role in drug prevention, enforcement and investigation," stated Minister Tom Marshall. "The Department of Justice remains committed to providing officers with the proper training to strengthen the fight against not only OxyContin abuse and related crimes, but for all controlled substances."


"The long-term strategy for drug abuse prevention and education in schools will be developed as part of the Department of Education's Safe and Caring Schools Initiative," said Tom Hedderson. "This initiative, through interagency cooperation, provides leadership to schools on matters relating to substance abuse, violence and other health and safety issues."


The Government of Newfoundland and Labrador established the task force in response to concerns about OxyContin abuse put forth from law enforcement, health professionals, community advocates and the media. The task force was a collaborative partnership of the Departments of Health and Community Services, Education and Justice.


The final report of the task force is available on-line at .
http://www.gov.nl.ca/health/publications/.



See additional coverage from the CBC here: CBC News: Give police medical info to curb 'hillbilly heroin': Report.

Read more from this post in Online law articles »

CBC News: P.E.I. to track prescription drug abuse

Prescription drug abuse has consistently presented one of the greatest challenges to the privacy of patient prescriptions. Health Canada has recently required many pharmacists to report prescriptions of certain drugs. Now it looks like the government of Prince Edward Island is proposing to introduce a province-wide computer system to drack prescriptions. Privacy is obviously an issue. Pharmacists and private practice physicians are subject to PIPEDA and are unable to disclose personal information without consent.

CBC News: P.E.I. to track prescription drug abuse:

"Last Updated Fri, 23 Jul 2004 15:22:45 EDT

The government's software could let doctors, hospitals and pharmacists share information on what prescriptions their patients are pocketing, but it's unlikely they will have access when the system launches in the fall.

Under the privacy act, doctors and pharmacists are not allowed to trade information about a patient without that person's consent."


One thing to remember is that PIPEDA has a catch-all exception to the consent principle buried in the end of section 7:

(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is ...

(c.1) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that ...

(iii) the disclosure is requested for the purpose of administering any law of Canada or a province;


...

(i) required by law.



If the pharmacist is "required by law" to disclose the information, the pharmacist arguably may dispense with consent.


Read more from this post in Online law articles »

Bill 31 (PHIPA) Training

National Privacy Services Inc. and ClinCoach Inc. have officially announced a series of training courses designed to assist physicians and other regulated healthcare professionals in addressing the Personal Health Information Protection Act, also known as Bill 31 and PHIPA.

Thanks to the alliance between NPSi and ClinCoach, the program will include a very comprehensive and practical course for those engaged in clinical research.

The updated brochure is available at http://www.privacylaw.ca/privacy/Bill_31_training.htm, which also includes an outline of the program.

More information is available on NPSi's training page, and you can register online here.




Read more from this post in Online law articles »

Bill 31 Training - Personal Health Information Protection Act (Ontario)


An Unprecedented Training Opportunity



ClinCoach and National Privacy Services have developed a range of training courses to assist health and health research professionals in adapting to and complying with Ontario's new Bill 31, the Personal Health Information Protection Act (aka PHIPA). This law comes into force on November 1, 2004 and has significant requirements for "health information custodians", including all regulated health professionals (physicians, physiotherapists, etc.), hospitals, nursing homes, and more.

The administrative requirements are similar to those of PIPEDA (hopefully the federal cabinet will deem the entire statute to be "substantially similar" to PIPEDA), and there are limited resources available to get healthcare professionals in compliance by the November 1 deadline. No matter what, it is not business as usual. The consent requirements are more specific for healthcare, but they are not exactly user friendly.

The new law also contains specific requirements for clinical researcher and Paula's years of experience in clinical research and clinical research education will prove to be a tremendous asset to attendees of our course designed for clinical research professionals.

From August to October, we will be offering our PHIPA training courses in Ottawa and Toronto. We will likely be hitting other centres in the rest of Ontario through late October and into the fall.

Training for Bill 31 - Personal Health Information Protection Act (Ontario):

"On November 1, 2004, the Personal Health Information Protection Act comes into force for Ontario's healthcare community. The new regime means it is no longer "business as usual" for regulated health professionals, hospitals and clinics. The rules have also changed for clinical research.

National Privacy Services Inc. (NPSi) and ClinCoach each have proven track records in delivering practical and effective privacy training for the healthcare sector. Together, we have designed a range of Bill-31 training courses specifically tailored for the medical community's varied roles and environments. Unlike other workshops and conferences you may have seen elsewhere, NPSi and ClinCoach provide solid training: in-depth, concise guidance on how to implement Bill 31 in your practice, all of which will be sufficient for continuing education credits. "



For more information, check out our brochure (advance copy available here) and the websites of National Privacy Services and ClinCoach.

Read more from this post in Online law articles »

ClinCoach and NPSi Alliance for Clinical Research Privacy


National Privacy Services Inc. and ClinCoach Inc. are going to announce tomorrow the establishment of a unique alliance to provide privacy training services for those involved with clinical research. ClinCoach is a leading, international provider of training for clinical research best practices, including the provision of Clinical Research Standard Operating Procedures. With NPSi, ClinCoach is developing a Standard Operating Procedures for interjurisdictional privacy best practices, designed to assist clinical researchers in complying with PIPEDA, PHIPA and other privacy laws.



ClinCoach and NPSi Alliance for Clinical Research Privacy:

"Standard Operating Procedures for Clinical Research

ClinCoach and NPSi have developed standardized means of integrating privacy best practices and legal requirements into clinical research, offering the first-of-its-kind Privacy Standard Operating Procedures for clinical trials. The best practices contained in the Privacy SOPs are designed to be compliant with Canada's multiple health privacy regimes, including PIPEDA, PHIPA: the Personal Health Information Protection Act and various laws in all Canadian provinces. These SOPs offer a privacy solution to sponsors in multi-centre trials located at sites across Canada."



You can check out the announcement at the websites of National Privacy Services Inc. and ClinCoach Inc. starting tomorrow.


Also, stay tuned for an announcement about Bill 31 training of Ontario's health professionals and institutions.


Read more from this post in Online law articles »

Correction: Coming into force of Bill 31

In an earlier blog entry, I suggested that the bulk of Ontario's Personal Health Information Protection Act will come into force on January 1, 2005. That was incorrect. The version of the bill passed by the legislature had November 1, 2004 as the effective date:

PART IX

COMMENCEMENT AND SHORT TITLE

Commencement

99. (1) Subject to subsection (2), this Schedule comes into force on the day the Health Information Protection Act, 2004

receives Royal Assent.

Same

(2) Sections 1 to 72 and 75 to 98 come into force on November 1, 2004.

Short title

100. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.



Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Proposed Bill 31 Regulations published

The Ontario Ministry of Health and Long-Term Care has published
a notice of proposed regulations under Bill 31. The public and
interested parties are invited to comment on the proposed regulations (deadline: September 3, 2004):

Notice of Proposed Regulations- Invitation to Provide Comments on Proposed Regulations:

"The Minister of Health and Long-Term Care on behalf of the Government of Ontario invites public comments on proposed regulations for the Personal Health Information Protection Act, 2004 and the Quality of Care Information Protection Act, 2004.

The public is invited to provide written comments on the draft regulations over a 60-day period, commencing on July 3, 2004 and ending on September 3, 2004.

Please be as specific as possible, and provide reasons for any suggested changes or additions. All comments and submissions received during the comment period will be considered during final preparation of the regulation.




The proposed regulations are available at this link.

Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Campaign in BC to prevent outsourcing of medical info management to US company

The BC Freedom of Information and Privacy Association has a report about a campaign launched to prevent the BC government from ousourcing the management of the BC Medical Services Plan to an American company. The fear is that once the info is in the hands of an American firm, it will be within easy reach of the FBI and others, thanks to the USA PATRIOT Act.

'Right to Privacy Campaign' launched to protect individuals' privacy by stopping Maximus deal:

A diverse and growing group of rights, health, union and other organizations has launched a province-wide campaign to demand that the BC government drop its proposed deal with the Maximus corporation because of the privacy implications of the USA PATRIOT Act.

The Right to Privacy Campaign (RPC) believes that contracting out the administrative functions of BC's Medical Services Plan and PharmaCare to the American corporation Maximus Inc. will place British Columbians' confidential health and related information within easy reach of the FBI and, through the FBI, the entire array of American government agencies.

The primary goal of the RPC is to ensure that there is 'no contracting out by the Government of BC of information or information management, such as MSP or PharmaCare, to any company subject to foreign laws that violate the privacy rights of Canadians, like the USA PATRIOT Act'...."


Unfortunately, the website of the Right to Privacy Campaign seems to be down, which I expect would have much more info.

Read more from this post in Online law articles »

Presentation: PIPEDA for Physicians

I just attended Insight Information Co.'s Health Privacy conference in Halifax. The content was fantastic and the presenters were really top-notch. It was a bit disappointing that there were no healthpractitioners in attendance, but with a $1300 price tag it is hard to manage unless you have a hospital or other organization paying your way.

Without a doubt, I found that the best speaker was Karen Rose, who is the new Info and Privacy Commissioner for PEI. She spoke about the challenges and advantages of privacy compliance. I've asked her for her speaking notes, which I'll also ask her if I can post here. Suellen Murray, from the Nova Scotia Department of Health discussed the process that is underway to harmonize the health information laws from coast to coast (minus Quebec). She wasn't able to discuss the substance since there are some minor revisions underway, but the process is promising.

I was asked to present on PIPEDA in private practices. Since everyone in attendance came from public institutions (read: non-commercial, and therefore beyond PIPEDA's hooks), the interest was largely academic. I tried to emphasise that many of the doctors who are present in hospitals are going to be grappling with this development, so they'd better be sensitive to it. My presentation, PIPEDA for Physicians, is available here.

Read more from this post in Online law articles »

PIPEDA Awareness Raising Tools (PARTs) Initiative For The Health Sector

Those concerned with the application of PIPEDA to the healthcare sector likely know about Industry Canada and Health Canada's "PIPEDA Awareness Raising Tools". One of the more recent additions is, in my view, incorrect.

"47. Under PIPEDA, can regulatory bodies/colleges still continue to conduct their investigative practices? Does PIPEDA require any changes in the manner in which these investigative activities are conducted?

The relationship between a regulatory body/college and its members is most often of a noncommercial nature, and therefore not captured by PIPEDA. These bodies are also generally empowered by law to obtain personal information as necessary to fulfill their various functions. Professionals subject to the authority of a regulatory body/college would in all likelihood have agreed to the use of their personal information by the body, as part of a condition of membership. PIPEDA recognizes such authority.

Regulatory bodies/colleges may, in the course of their function, need to obtain personal information from other organizations that are subject to PIPEDA, such as financial institutions. Such organizations may only disclose personal information without consent to entities that have been designated as "investigative bodies" under PIPEDA, by regulation. As such, regulatory bodies/colleges may be required to obtain this designation if they wish to obtain personal information from these organizations without an individual's consent."



The "investigative body" designation is only useful for the circumstances set out in s. 7(d):

(d) made on the initiative of the organization to an investigative body, a government institution or a part of a government institution and the organization

(i) has reasonable grounds to believe that the information relates to a breach of an agreement or a contravention of the laws of Canada, a province or a foreign jurisdiction that has been, is being or is about to be committed, or

(ii) suspects that the information relates to national security, the defence of Canada or the conduct of international affairs;



For this exception to apply, it has to be on the initiative of the organization (e.g. the physician), not the investigative body. You simply can't rely on it if the investigative body is the one requesting the information. Also, it only applies in the circumstances set out in (i) and (ii). The circumstances in (ii) would clearly be inapplicable and it is questionable whether the circumstances of (i) would come to pass in the course of an investigation by a College of Physicians and Surgeons. The better response is the application of sections 7(3)(c) and (i):

(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is ...

(c) required to comply with a subpoena or warrant issued or an order made by a court, person or body with jurisdiction to compel the production of information, or to comply with rules of court relating to the production of records;

(i) required by law.



Many professional regulators have jurisdiction to subpoena or otherwise compel the production of information in the custody of a physician. These exceptions are clearly preferable to those in 7(d). Some professional regulators, like those for social workers in Nova Scotia, don't have the power to compel the production of documents and are therefore unable to get this information without consent.

Read more from this post in Online law articles »

Study: Patient privacy at risk in hospitals' hallways, lobbies, cafeterias

File this under "not very surprising" ...

A recent study, published in the journal Health Communication (and abstracted on the Purdue university website) discusses how patient privacy can be casually violated by conversations among health professionals in public spaces:

Patient privacy at risk in hospitals' hallways, lobbies, cafeterias:

"Patient privacy at risk in hospitals' hallways, lobbies, cafeterias

WEST LAFAYETTE, Ind. -- New health communication research shows that casual conversations in hospital hallways and waiting rooms poses a threat to the confidentiality of patients' medical information.

Research conducted at Purdue University by Maria Brann, assistant professor of communication studies at West Virginia University, and Marifran Mattson, associate professor of communication at Purdue, shows patient privacy is breached when hospital employees talk about patient cases in public areas, such as the cafeteria, or with people outside of work. The researchers' paper appears in the spring issue of the journal Health Communication."



Thanks to the Science Blog for this link.

Read more from this post in Online law articles »

Ontario's Personal Health Information Protection Act receives royal assent

Ontario's Personal Health Information Protection Act (also known as Bill 31) received royal assent on May 30, 2004. The main parts of the statute come into force on January 1, 2005:

PART IX

COMMENCEMENT AND SHORT TITLE

Commencement

95. (1) This section and sections 71, 72 and 96 come into force on the day the Health Information Protection Act, 2004 receives Royal Assent.

Same

(2) Sections 1 to 70 and 73 to 94 come into force on January 1, 2005.

Short title

96. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.





Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Read more from this post in Online law articles »

Article: ID Theft from Medical Records

A recent story from Baltimore, MD, highlights the vulnerability of personal information and the need for vigilance. People trust their doctors to maintain their confidentiality, but this trust can be betrayed by unscrupulous employees.


Making Medical Records Identity-Theft Proof

POSTED: 8:47 am EDT May 27, 2004

BALTIMORE -- You trust your doctor to maintain your health but what about your privacy?

Patients from one doctor's office thought their personal information was protected. They were wrong.

WBAL-TV 11 News I-Team reporter Barry Simms discovers how easily your security can be breeched.

Anne Knoeller thought her personal information was secure until an unusual phone call...

Knoeller: "He said check your credit report."

The caller -- a Baltimore County police detective. He told her, "your information's been taken out of a doctor's office."

She was shocked. The alleged thief -- a medical assistant trusted with private patient information. 21-year-old Chanell Cole of Baltimore worked at Hunt Manor Medical Associates in Phoenix. The practice is affiliated with the Greater Baltimore Medical Center....


Full text here ...

Read more from this post in Online law articles »

Article: Privacy issues develop over work done overseas

The issue of the privacy of personal information shipped overseas in connection with outsourcing is not a new issue, but an important one ...

Duluth News Tribune | 04/18/2004 | Privacy issues develop over work done overseas:

"The growing business of shipping sensitive personal data overseas threatens the privacy rights of U.S. citizens, according to Sens. Hillary Rodham Clinton, D-N.Y., Bill Nelson, D-Fla., and other foes of outsourcing.

Clinton is pushing legislation that would make U.S. businesses legally liable if a foreign subcontractor abuses American privacy laws.

The bill also would require U.S. businesses -- such as accounting firms, physicians, hospitals and banks -- to gain consent from consumers before shipping their private data to an overseas contractor if the Federal Trade Commission has determined that the country where the contractor is based doesn't have adequate privacy laws.

The privacy issue gained the attention of lawmakers after a Pakistani woman, Lubna Baloch, who transcribed confidential medical records of patients at UC San Francisco Medical Center, threatened to post them on the Internet last October unless the hospital helped her collect an overdue bill from a man who hired her as a medical transcription subcontractor.

Baloch withdrew her threat after she was paid.

Sue Blevins, president of the Institute for Health Freedom, a nonprofit concerned with medical privacy, said if personal information like mental illness, alcoholism treatment, marriage counseling, illegal drug use or a sexually transmitted disease gets out to the public, 'it could be devastating and cause emotional pain and affect people's career, families or even the ability to get a mortgage.'"


As I've said before, nearshore outsourcing to places like Nova Scotia does not have the same risk as outsourcing to Asia. Check out Nova Scotia Business Inc.

Read more from this post in Online law articles »

Article: Privacy issues develop over work done overseas

The issue of the privacy of personal information shipped overseas in connection with outsourcing is not a new issue, but an important one ...

Duluth News Tribune | 04/18/2004 | Privacy issues develop over work done overseas:

"The growing business of shipping sensitive personal data overseas threatens the privacy rights of U.S. citizens, according to Sens. Hillary Rodham Clinton, D-N.Y., Bill Nelson, D-Fla., and other foes of outsourcing.

Clinton is pushing legislation that would make U.S. businesses legally liable if a foreign subcontractor abuses American privacy laws.

The bill also would require U.S. businesses -- such as accounting firms, physicians, hospitals and banks -- to gain consent from consumers before shipping their private data to an overseas contractor if the Federal Trade Commission has determined that the country where the contractor is based doesn't have adequate privacy laws.

The privacy issue gained the attention of lawmakers after a Pakistani woman, Lubna Baloch, who transcribed confidential medical records of patients at UC San Francisco Medical Center, threatened to post them on the Internet last October unless the hospital helped her collect an overdue bill from a man who hired her as a medical transcription subcontractor.

Baloch withdrew her threat after she was paid.

Sue Blevins, president of the Institute for Health Freedom, a nonprofit concerned with medical privacy, said if personal information like mental illness, alcoholism treatment, marriage counseling, illegal drug use or a sexually transmitted disease gets out to the public, 'it could be devastating and cause emotional pain and affect people's career, families or even the ability to get a mortgage.'"


As I've said before, nearshore outsourcing to places like Nova Scotia does not have the same risk as outsourcing to Asia. Check out Nova Scotia Business Inc.

Read more from this post in Online law articles »

Letter to BC and Alberta Information and Privacy Commissioners - Privacy Commissioner of Canada

Residents of British Columbia and Alberta are caught in a state of jurisdictional overlap with respect to privacy laws. PIPEDA applies to commercial activities, except in those provinces that have enacted legislation that has been declared to be substantially similar. Both BC and Alberta have private sector privacy laws that came into effect on January 1, 2004, but none have been declared by the federal parliament to be "substantially similar". It appears that complainants can go to both the federal and provincial commissioners to complian about a provincially-regulated business.

The federal Privacy Commissioner has just released a letter to the commissioners for BC and Alberta on how to handle this overlap until the federal cabinet makes such a declaration:

The Privacy Commissioner of Canada, Jennifer Stoddart, sent the following letter to Mr. Frank Work, Information and Privacy Commissioner for Alberta, and Mr. David Loukidelis, Information and Privacy Commissioner for British Columbia, regarding the handling of complaints under PIPEDA as of January 1, 2004.



March 11, 2004



Mr. Frank Work

Information and Privacy Commissioner

Office of the Information and Privacy Commissioner

4th floor 9925,109 Street

Edmonton AB T5K 2J8



Mr. David Loukidelis

Information & Privacy Commissioner for British Columbia

Office of the Information and Privacy Commissioner

PO Box 9038, STN Prov Govt

Victoria, BC V8W 9A4



Dear Mr. Work and Mr. Loukidelis:



Handling of complaints under PIPEDA as of January 1, 2004



This letter will serve to confirm the discussions we had in Ottawa on January 21, 2004 concerning our current and future handling of complaints by our Office where the complaint is against an organization in, as the case may be, British Columbia or Alberta.



Our understanding is as follows:




  • Until the BC and Alberta Personal Information Protection Acts (PIPAs) are, respectively, declared to be substantially similar by the Governor in Council;



  1. The Office of the Privacy Commissioner of Canada (OPC) has a legal obligation to apply the Personal Information Protection and Electronic Documents Act (PIPEDA) where appropriate.


  2. OPC will take complaints against private sector organizations in BC and Alberta that are collecting, using or disclosing personal information about their customers in the course of commercial activity. This includes organizations that deal in personal health information such as physicians and dentists’ offices, private laboratories, etc.


  3. OPC will verbally inform complainants of the possibility of complaining directly to the appropriate provincial commissioner and that complaints which fall clearly in provincial rather than federal jurisdiction, after a substantially similar order, will be transferred in any event.


  4. If the complainant wishes nevertheless to proceed federally, OPC will open a complaint file but will inform all parties to the complaint that there will be a transfer of the complaint and all information on the file to the appropriate provincial commissioner if and when a substantially similar order is made.



  • OPC will continue, after any substantially similar order is made, to take complaints concerning federal works, undertakings and businesses (FWUBs), including complaints about employee personal information and information about job applicants to FWUBs.


  • Complaints involving inter-provincial issues will be handled by OPC in accordance with the following principles.




  1. Before the making of a substantially similar order, the complaints will be handled as per (2) above in all cases unless the complaint is substantially about the crossing of inter-provincial boundaries or the issue otherwise falls under OPC’s jurisdiction.


  2. After the making of a substantially similar order, complaints will be handled as per arrangements which we will continue to develop between OPC and your respective offices.



  • Our offices are also currently discussing the following issues:





  1. arrangements to share the contents of complaints files where circumstances warrant and consistent with our respective legal authorities and obligations;


  2. harmonization of statistical reporting and language for such reporting where possible;


  3. development of joint statements, questions and answers, and jurisdictional tools where possible.


The arrangements set out above reflect current practices in our respective offices, but may change over time. In light of that, we have each agreed to name individuals in our respective offices to engage in day-to-day discussions on issues as they arise. We also agree to keep the channels of communication open at the most senior levels and will attempt to meet as frequently as required and possible.



We are pleased that we have been able to reach these understandings and look forward to continuing to work with you to effectively protect the privacy rights of individuals.



Yours sincerely,


Jennifer Stoddart

Privacy Commissioner of Canada



c.c. Provincial Commissioners





Read more from this post in Online law articles »
Info recommended by: Webpages of law and Law articles

© Online law articles: health information