This summer, the Ontario government introduced the Electronic Personal Health Information Protection Act (“EPHIPA”), which will amend the Personal Health Information Protection Act (“PHIPA”) to deal with the introduction of electronic health records (“EHRs”). The aim of the Bill is to regulate the privacy of individuals and their rights to their personal information in light of the specific concerns that surround EHRs. The bill went through its second reading and debate on October 10th, 2013.
The amendments govern the use, collection and disclosure of EHRs, and propose:
- the creation of “prescribed organizations” to create and maintain EHRs
- allowing patients to create consent directives
- giving patients the right to access their records
- allowing patients the right to request a correction of their records
- giving patients the right to know who accessed their records
- allowing patients to lodge complaints
- limiting the sharing of EHRs
- the creation of harsher sanctions for persons or organizations who breach the Act,
- the creation of an independent advisory to advise the Ministry of Health and Long-Term Care (“the Ministry”) on policies regarding electronic health records.
EPHIPA would give individuals more control over the use, collection and disclosure of their personal health information. The bill would allow patients to create “consent directives” over who can, and who cannot, access or use their personal health information. These directives could be modified at any time, and can be overridden, if the patient gives consent, or in certain situations where a prescribed organization reasonably believes that collection would reduce or eliminate a risk of serious injury. Thus, in most circumstances, EPHIPA would have the effect of giving the patient more agency in controlling how their personal information is collected, used and disclosed by different health organizations.
The response to the proposed legislation has generally been positive. Ontario’s Information and Privacy Commissioner, Dr. Ann Cavoukian, commended the bill’s amendments to PHIPA. Commissioner Cavoukian stated:
These amendments are necessary to foster public trust and confidence, as the health sector transitions from paper-based records to electronic health records… I will continue to work closely with the Government and the health care sector to ensure a smooth and seamless transition into the digital era, while strongly protecting the privacy of Ontarians and the confidentiality of their personal health information.