Personal Health Information Protection Act, 2004, limits on use of de-identified information
S.O. 2004, c. 3, Sched. A, s. 11.2
In force since .
A sensitive categories rule binding public and private bodies.
- Obligation class
- Prohibition
- Audit expectation
- none
As of .
What it requires
- This duty binds any person, not only a health information custodian, who holds information that has been de-identified from personal health information.
- Do not use, or attempt to use, de-identified information to identify an individual, alone or combined with other information, unless the Act or another Act permits it. Custodians, prescribed entities, prescribed registry holders and other prescribed persons may re-identify information they de-identified themselves.
What this law does
No person may use or attempt to use information that has been de-identified to identify an individual, either alone or with other information, unless the Act or another Act permits the information to be used to identify the individual, subject to any prescribed exceptions.
The limit does not prevent a health information custodian, a prescribed entity mentioned in subsection 45 (1), a prescribed person who compiles or maintains a registry of personal health information, or any other prescribed person from using information that they de-identified to identify an individual.
To de-identify personal health information means to remove any information that identifies the individual or for which it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.
When LexLint raises it
When your app profile says your app handles health records, trains models or crawls the web.