Law / Canada / Ontario

Personal Health Information Protection Act, 2004, electronic audit log

S.O. 2004, c. 3, Sched. A, s. 10.1

A sensitive categories rule binding public and private bodies.

Obligation class
Governance
Audit expectation
periodic
Who audits it
Self, Regulator
Where the report goes
Kept, Produced on request

As of .

What it requires

  • This duty binds a health information custodian that uses electronic means to collect, use, disclose, modify, retain or dispose of personal health information, and so reaches the systems that supply those means.
  • Maintain, or require the maintenance of, an electronic audit log that records, for every instance in which personal health information accessible by electronic means is viewed, handled, modified or otherwise dealt with, the type of information, the date and time, the identity of every person who dealt with it and the identity of the individual it relates to.
  • Audit and monitor the log as often as the regulations require, comply with any prescribed requirements, and give the Commissioner a copy of the log on request, even where it contains personal health information.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Subject to any prescribed exceptions, a health information custodian that uses electronic means to collect, use, disclose, modify, retain or dispose of personal health information must maintain, or require the maintenance of, an electronic audit log, audit and monitor the log as often as the regulations require, and comply with any prescribed requirements. The custodian must provide a copy of the electronic audit log to the Commissioner on request.

The log must include, for every instance in which a record or part of a record of personal health information that is accessible by electronic means is viewed, handled, modified or otherwise dealt with, the type of information, the date and time, the identity of all persons who dealt with it, and the identity of the individual to whom it relates.

When LexLint raises it

When your app profile says your app handles health records.

Back to the example  ·  Lint your app