Personal Health Information Protection Act, 2004, electronic audit log
S.O. 2004, c. 3, Sched. A, s. 10.1
A sensitive categories rule binding public and private bodies.
- Obligation class
- Governance
- Audit expectation
- periodic
- Who audits it
- Self, Regulator
- Where the report goes
- Kept, Produced on request
As of .
What it requires
- This duty binds a health information custodian that uses electronic means to collect, use, disclose, modify, retain or dispose of personal health information, and so reaches the systems that supply those means.
- Maintain, or require the maintenance of, an electronic audit log that records, for every instance in which personal health information accessible by electronic means is viewed, handled, modified or otherwise dealt with, the type of information, the date and time, the identity of every person who dealt with it and the identity of the individual it relates to.
- Audit and monitor the log as often as the regulations require, comply with any prescribed requirements, and give the Commissioner a copy of the log on request, even where it contains personal health information.
What this law does
Subject to any prescribed exceptions, a health information custodian that uses electronic means to collect, use, disclose, modify, retain or dispose of personal health information must maintain, or require the maintenance of, an electronic audit log, audit and monitor the log as often as the regulations require, and comply with any prescribed requirements. The custodian must provide a copy of the electronic audit log to the Commissioner on request.
The log must include, for every instance in which a record or part of a record of personal health information that is accessible by electronic means is viewed, handled, modified or otherwise dealt with, the type of information, the date and time, the identity of all persons who dealt with it, and the identity of the individual to whom it relates.
When LexLint raises it
When your app profile says your app handles health records.