Law / Canada / Ontario

Personal Health Information Protection Act, 2004, electronic service providers and health information network providers

S.O. 2004, c. 3, Sched. A, s. 10 (4); O. Reg. 329/04, s. 6

In force since .

A sensitive categories rule binding public and private bodies.

Obligation class
Prohibition, Security, Governance, Disclosure, Contract terms, Breach notice
Audit expectation
continuous
Who audits it
Self
Where the report goes
Kept, Produced on request

As of .

What it requires

  • These duties bind a vendor or service provider that supplies goods or services enabling a health information custodian to use electronic means to collect, use, modify, disclose, retain or dispose of personal health information. A health information network provider carries further duties.
  • If you are not the custodian's agent, use personal health information you can access while providing the services only as necessary to provide them, and do not disclose it.
  • Do not let your employees, or anyone acting for you, have access to the information unless they agree to comply with the same restrictions.
  • If you are a health information network provider (you serve two or more custodians, primarily so that they can disclose personal health information to one another electronically), notify every applicable custodian at the first reasonable opportunity if you used, disclosed or disposed of the information outside those restrictions or an unauthorized person accessed it.
  • As a health information network provider, give each custodian a plain language description of your services that is suitable for sharing with patients, including the safeguards in place, and make that description and your applicable directives, guidelines and policies available to the public, other than a trade secret or confidential scientific, technical, commercial or labour relations information.
  • As a health information network provider, keep, to the extent reasonably practical, an electronic record of all accesses to and transfers of custodians' information in equipment you control, identifying who accessed or transferred it and when, and make it available to a custodian on request.
  • As a health information network provider, assess the threats, vulnerabilities and risks to the security and integrity of the information and how your services may affect the privacy of the individuals concerned, and give each custodian a written copy of the results.
  • As a health information network provider, make sure any third party you retain to help provide the services agrees to the restrictions and conditions you need in order to comply, and sign a written agreement with each custodian that describes the services and the administrative, technical and physical safeguards and requires you to comply with the Act and the regulations.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

A person who provides goods or services for the purpose of enabling a health information custodian to use electronic means to collect, use, modify, disclose, retain or dispose of personal health information must comply with the requirements the regulations prescribe. A supplier of services that is not an agent of the custodian must not use any personal health information to which it has access in the course of providing the services except as necessary in providing them.

That supplier must not disclose any personal health information to which it has access in the course of providing the services. That supplier must not permit its employees or any person acting on its behalf to have access to the information unless they agree to comply with the same restrictions.

A health information network provider is a person who provides services to two or more health information custodians, primarily to enable the custodians to use electronic means to disclose personal health information to one another.

A health information network provider must notify every applicable custodian at the first reasonable opportunity if it accessed, used, disclosed or disposed of personal health information other than as the supplier restrictions allow, or if an unauthorized person accessed the information.

A health information network provider must give each applicable custodian a plain language description of its services and safeguards, and must make that description, and its directives, guidelines and policies that apply to the services, available to the public to the extent they do not reveal a trade secret or confidential scientific, technical, commercial or labour relations information.

A health information network provider must, to the extent reasonably practical, keep an electronic record of all accesses to and transfers of the information held in equipment it controls and make it available to a custodian on request, and must perform and give each custodian a written copy of the results of an assessment of threats, vulnerabilities and risks to the security and integrity of the information and of how the services may affect the privacy of the individuals concerned.

A health information network provider must enter into a written agreement with each custodian that describes the services, describes the administrative, technical and physical safeguards, and requires the provider to comply with the Act and the regulations. A custodian that uses goods or services from such a supplier is not considered to disclose personal health information to the supplier if the supplier complies with those requirements.

When LexLint raises it

When your app profile says your app handles health records or distributes a software product.

Back to the example  ·  Lint your app