ASSIGNEMNT DUE BY 24 HRS
CMTO Record Keeping Workshop
Module Six
After completing this module, participants will be able to:
o Identify the legislative requirements for privacy and confidentiality;
o Recall the legislative responsibilities for regulated health care professionals as established by the Personal Health Information Protection Act, 2004.
2
Learning Objectives
Privacy and Confidentiality
3
4
There is an important difference between the concepts of privacy and confidentiality.
As regulated health care professionals, Massage Therapists must understand the differences in order to fulfill their responsibilities.
PRIVACY: refers to the right of every individual to control the collection, use and disclosure of their own personal information*.
CONFIDENTIALITY: refers to the commitment to protect and safeguard the personal information that is disclosed to you*.
*Used with permission from the College of Medical Laboratory Technologists of Ontario
5
Pinch (2000) identifies three major characteristics of confidentiality:
- 1. Confidentiality is a duty connected to privileged information obtained in the context of the professional relationship with the client;
- 2. Protecting that information is carried out as part of a professional commitment; and,
- 3. The obligation to maintain confidentiality is rooted in the client’s right to privacy.
- Pinch, W.J.E. (2000). Confidentiality: Concept Analysis and clinical application. Nursing Forum 35(2), 5 - 16
The Personal Health Information Protection Act of Ontario, 2004
6
7
The Personal Health Information Protection Act, 2004 or ‘PHIPA’ is provincial legislation that is designed to address the complex issues concerning the collection, use and disclosure of personal health information by ‘Health Information Custodians’.
According to PHIPA, a Health Information Custodian (HIC) is an individual or organization who has custody or control of personal health information (PHI). For example, a regulated health care practitioner, hospitals, psychiatric care facilities or boards of health etc.
PHIPA also establishes that only certain individuals or entities are eligible to fulfill the duties of a Health Information Custodian (HIC). Whereas an ‘Agent’ to a Health Information Custodian is defined as any person who is authorized by a HIC to perform services or activities on the HIC’s behalf.
Please take a moment to review the following reference document for an overview of the roles of the HIC and the Agent to the HIC.
8
Personal Health Information (PHI) is defined as any identifying information about a client / patient that is collected orally, and any information that is recorded throughout the process of providing health care services.
PHI includes the information that is recorded in appointment, financial or client health records such as: the client’s name and address, date, time and duration of treatment(s), any fee rates that were charged, health history information, the particulars of assessments or treatments, clinical, medical or legal reports, diagnostic examination or test results, recommendations or advice provided as a part of a treatment, copies of signed consent, copies of and treatment plans and details of any treatments that were provided.
9
When a Massage Therapist (MT) fulfills the duties of the HIC, the MT must take reasonable steps to protect the personal health information (PHI) that belongs to each client by:
- 1. Protecting against loss, theft or unauthorized access, use or disclosure of PHI;
- 2. Protect against unauthorized copying, modification or disposal of PHI;
- 3. Notify a client if their PHI is stolen, lost or accessed by unauthorized individuals at the first available opportunity;
- 4. Ensure that PHI contained in the client records for which they have custody are retained, transferred and disposed of in a secure manner according to PHIPA requirements;
- 5. Create and implement privacy protocols for their practice and publish a privacy statement for clients to access and review.
CMTO provides the following guidelines to help MTs create privacy protocols for practice, and privacy statements for clients.
10
In general, an HIC cannot disclose a client’s PHI unless:
- The client has provided express, written consent;
- The disclosure is permitted or required by PHIPA; or,
- The disclosure is permitted or required by another law (e.g., the RHPA).
There are some circumstances where a HIC can disclose PHI without client consent, including:
- When the information pertains to grave hazards and it is in the best interests of the Public to disclose the information to appropriate authorities;
- The health and safety of the client is at risk;
- Disclosures to public health authorities as required by law; or,
- When the provision of health care requires disclosure within a ‘Circle of Care’.
11
The concept of the ‘Circle of Care’ helps HICs to identify circumstances where it might be acceptable to assume that a client has consented to disclose or share their personal information.
The ‘Circle of Care’ also helps HICs to identify circumstances where they should not assume that the client has provided consent to share or disclose their information. In cases where disclosure falls ‘outside’ the Circle of Care, HICs should not disclose or share a client’s personal health information without obtaining written consent from the client beforehand.
Take a moment to review the following guidelines for the ‘Circle of Care’.
How should a HIC respond to requests for access to information contained in a client
health record?
12
13
When the request for access or copy comes directly from the client, MTs must refer to the guidelines for managing these requests in the Personal Health Information Protection Act, 2004:
According to PHIPA:
- Clients may notify a HIC of their request for information verbally or in writing;
- The HIC must then respond to the request within 30 days by establishing access to the record, or by providing a copy; and,
- The HIC is permitted to charge a reasonable fee for this service.
When requests for access to a client’s personal health information comes from someone other than the client (also known as a third party); Massage Therapists must obtain written consent from the client before providing access or copies to the client’s personal health information. These guidelines are established in the CMTO Policy for Release of Records.
Are HICs responsible for creating and implementing privacy protocols and privacy
policies / statements?
14
15
HICs are responsible for creating and implementing privacy protocols for a practice. HICs are also responsible for creating privacy policies or statements to provide to clients in order to help them understand how their information is retained, and who to contact when they wish to request access or copies of their personal health information.
16
Privacy policies or statements must include the following information: name and contact information for the HIC, how to place a request to obtain access or request copies of information, a description of the type of information that will be collected, an explanation for how the information will be used and stored and how information will be disclosed or shared (e.g., with client consent only).
RMTs can find a step-by-step process for developing and implementing privacy protocols and creating privacy policies or statements for a healthcare practice in the following resource.
This resource includes helpful template ‘forms’ for privacy policies and statements on pages 27 to 35.
What are the HIC’s responsibilities when departing from a practice?
17
18
When a HIC departs a practice location, or departs from the profession altogether, they can choose to retain custody and control over client health records or transfer the custody and control of the records to another eligible HIC.
When any changes to custody are made, clients should be notified of those changes so that they remain aware of how to access their records.
If a HIC is transferring the custody and control of records, they are not automatically entitled to retain copies of the records without first obtaining written consent from each client.
In cases where a HIC did not obtain written consent from clients to retain copies of the records prior to transferring the records to a new HIC, they could choose to organize a written agreement with the new HIC to allow for access to the records for medical or legal reasons for the remainder of the mandatory storage period. The CMTO Policy for the Maintenance of Client Health Records outlines the mandatory storage period for client health records.
What are the responsibilities associated with reporting theft, loss or unauthorized access to
PHI?
19
20
If a MT is a HIC, and they discover that a client’s PHI has been lost, stolen or accessed by unauthorized parties, they have a duty to report the breach to the client and the Information and Privacy Commissioner of Ontario. In some cases, there may be a requirement to notify CMTO.
Here are some additional resources from the Information and Privacy Commissioner of Ontario (IPC): how to develop a privacy breach protocol, how to respond to a privacy breach and how to report a privacy breach.
20
Health Information Custodians also have a duty to report annual statistics for privacy breaches to the Information and Privacy Commissioner’s Office of Ontario.
RMTs can find more information about these responsibilities in the following resource.
Whenever RMTs fulfill the duties of the HIC within their practice, they have a responsibility to report annual statistics directly to the IPC every year.