|
A10-2 - Privacy and Security of Personal Health Information
THAT the Government of Ontario takes the following steps, as soon as possible, to improve the privacy and security of personal health information (PHI) that is collected, used, disclosed, stored and disposed by Ontario’s public health system, including local public health agencies and the Ontario Ministry of Health and Long-Term Care:
Ensures that Health Information Custodians continually use secure and encrypted mobile devices and media for the collection and storage of PHI and that Custodians’ corresponding information practices and privacy and security policies and procedures are properly aligned with this requirement,
Ensures that Custodians limit the collection of PHI, including health card numbers, to that which is necessary to fulfill the identified purposes under the Act, in consultation with the IPC and other key stakeholders,
Ensures there is greater clarity respecting the role of Custodians who use provincial information systems that collect and store PHI that can be accessed by local public health agencies and provincial ministries, in consultation with the IPC and/or other key stakeholders,
Ensures that provincial Custodians conduct privacy impact assessments, on current and new provincial public health information systems, in consultation with the IPC and other key stakeholders, and that such assessments are shared with local Custodians, so that they can determine whether PHIPA requirements regarding their information systems, have been met,
Ensures that the Health Protection and Promotion Act and PHIPA are strengthened such that Custodians are empowered to give clear directions to their agents with respect to the privacy and security of PHI, including the completion of privacy and security training and an attestation to that effect, and agents are required to comply with such directions,
Ensures that Custodians and their agents receive ongoing education and training with respect to their powers and duties under PHIPA, in consultation with the IPC, Ontario Agency for Health Protection and Promotion and other key stakeholders,
Ensures that Custodians share PHI related privacy and security best practices, including information practice notices, policies, procedures and templates, across the public health system,
Ensures Custodians receive ongoing adequate resources to ensure that they and their agents are able to fulfill their duties under PHIPA
|