Privacy Policy
Personal Health Information Protection Act (PHIPA)
The Ministry of Health and Long-Term Care and the Office of the Privacy Commissioner stipulate that all Family Health Teams must be in compliance with Provincial Privacy Legislation, specifically Bill 31: The Personal Health Information Protection Act (PHIPA), which came into effect on November 1, 2004. For this reason, the Halton Hills Family Health Team (“HHFHT”) has developed the following Privacy Policy.
Guiding Philosophies:
- The HHFHT acknowledges that the legislation applies to all health information about our patients;
- The term "Privacy" includes both the confidentiality and security of Patient Information;
- The HHFHT, as a Health Information Custodian, is accountable and responsible for the protection of all personal patient information within its care;
- Accountability for HHFHT compliance with privacy rests with the Privacy Officer who is designated to act on behalf of the Executive Director and the Board of Directors in matters related to privacy;
- The Privacy Officer is designated to oversee privacy legislation compliance;
- Each individual has a right to expect their personal information will be reasonably protected;
- Each health care professional and HHFHT employee has a duty to protect the personal information of those seeking our services;
- Access permission will be granted on a need-to-know basis. Access will facilitate employees to effectively perform their assigned duties;
- The HHFHT acknowledges the appropriate use of notice, implied and expressed consent in compliance with the legislation;
- Privacy investigations will be conducted in a fair and consistent manner. The process will ensure that numbers of contacts are kept to a minimum to maintain confidentiality;
- Contractual agreements between third party partners/suppliers/vendors will be in place to ensure privacy compliance to HHFHT policies and procedures.
Due to the sensitive nature of health information, the HHFHT will apply the following principles across all aspects of its operation:
Privacy Principles:
- Accountability for Personal Information: The HHFHT is responsible for the personal information of patients under its control and will delegate an individual(s) who is/are accountable for its compliance with the privacy principles and relevant legislation.
- Identify Purposes for the Collection of Personal Information: The HHFHT and its personnel will identify the purposes for which personal information is collected at or before the time the information is collected.
- Consent for Collection, Use and Disclosure of Personal Information: The knowledge and informed-consent of the individual are required for the collection, use or disclosure of personal information, except where inappropriate or recognized exceptions apply (notice will be posted to outline the following: provision of direct patient care within the organization and across the health system, administrative and management of the health care system, research, teaching, statistics, quality improvement initiatives, compliance with legal and regulatory requirements).
- Limit Collection of Personal Information: Information will be collected through fair and lawful means to that which is necessary for the purposes identified.
- Limit Use, Disclosure and Retention of Personal Information: Personal information will not be used or disclosed for purposes other than those for which it was collected, except with the consent of knowledge of the individual as required by law. Personal information will be retained only as long as is legally required or is necessary to fulfill its stated purpose.
- Accuracy of Personal Information: Personal information will be as accurate, complete, and up-to-date as is necessary for the purpose for which it is used.
- Safeguards for Personal Information: personal information will be protected by security methods appropriate to the format and sensitivity of the information.
- Openness about Privacy Policies: The HHFHT will make readily available to individuals specific information about its policies and procedures relating to the management of personal information.
- Individual Access to Personal Information: Upon request, an individual will be informed of the existence, use and disclosure of his/her personal information and will be given access to that information. An individual will be able to challenge the accuracy and completeness of the information and have it noted or amended as appropriate.
- Challenge Compliance with the Privacy Policy: An individual will be able to challenge the compliance with the HHFHT policy to the Privacy Officer and/or Executive Director.