QuestionQ13

Foundational Principles

SCENARIO —

Reflecting on your first two years as Director of Personal Information Protection and Compliance for Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a series of accomplishments—from developing state-of-the-art simulation-based privacy-protection training for employees to establishing an interactive medical-records system accessible to patients as well as medical personnel. However, a question you have deferred now looms large: how should all the data be managed—not only recently created records, but also those retained from years ago? A data-flow diagram produced last year shows multiple servers, databases, and workstations, many holding files that have not yet been incorporated into the new records system. Although most of this data is encrypted, retaining it may create security and compliance concerns. The situation is further complicated by several long-term studies conducted by medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to ensure that the medical center complies with them.

You also remember a recent visit to the Records Storage Section—often called The Dungeon—in the basement of the old hospital beside the modern facility, where you observed a multitude of paper records. Some were in crates marked by year, medical condition, or patient name alphabetically, while others were in unclassified bundles on shelves and the floor. The section’s rear shelves held data tapes and old hard drives that were frequently unlabeled but appeared to be years old. As you left the dungeon, you saw ahead of you a small man in a lab coat whom you did not recognize. He was carrying a batch of folders under his arm, apparently records he had removed from storage.

Which regulation is most likely to apply to the data stored by Berry Country Regional Medical Center?

  • A Personal Information Protection and Electronic Documents Act
  • B Health Insurance Portability and Accountability Act
  • C The Health Records Act 2001
  • D The European Union Directive 95/46/EC
Explanation

Of the listed laws, the Personal Information Protection and Electronic Documents Act (PIPEDA) is the Canadian privacy statute. The other choices are tied to the United States, a different jurisdiction, or the European Union. Ontario’s more specific Personal Health Information Protection Act, 2004 governs personal health information handled by Ontario health information custodians, but it is not among the available choices.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!