Personal Health Information Protection Act, 2004, breach notification by custodians and agents
S.O. 2004, c. 3, Sched. A, ss. 12 (2)-(3), 17 (4), 17.1; O. Reg. 329/04, ss. 6.3-6.4
In force since .
A breach notification rule binding public and private bodies.
- Obligation class
- Breach notice, Reporting
- Audit expectation
- none
As of .
What it requires
- These duties bind a health information custodian and, for the duty to tell the custodian, its agent.
- If personal health information in your custody or control is stolen or lost, or is used or disclosed without authority, notify the individual at the first reasonable opportunity and state in the notice that the individual is entitled to make a complaint to the Commissioner.
- Notify the Commissioner at the first reasonable opportunity when the theft, loss or unauthorized use or disclosure meets a prescribed circumstance: reasonable grounds to believe the information was used or disclosed without authority by a person who knew or ought to have known that, reasonable grounds to believe it was stolen, further unauthorized use or disclosure after an initial incident, a pattern of similar incidents, a notice you must give a College, or your own determination that the incident is significant after weighing sensitivity, volume, the number of individuals and the number of custodians or agents responsible.
- On or before March 1 each year, report to the Commissioner how many times in the previous calendar year personal health information in your custody or control was stolen, lost, used without authority or disclosed without authority.
- If you are an agent of a custodian, notify the custodian at the first reasonable opportunity if personal health information you handled for it is stolen or lost, or is used or disclosed without authority.
- If you employ a health care practitioner who is a member of a College and the practitioner is terminated, suspended or disciplined because of unauthorized collection, use, disclosure, retention or disposal of personal health information, give the College written notice within 30 days.
What this law does
If personal health information in a custodian's custody or control is stolen or lost, or is used or disclosed without authority, the custodian must notify the individual at the first reasonable opportunity and include in the notice a statement that the individual is entitled to make a complaint to the Commissioner. If the circumstances meet the prescribed requirements, the custodian must also notify the Commissioner.
The regulation prescribes those circumstances, which include reasonable grounds to believe that the information was stolen, and reasonable grounds to believe that it was used or disclosed without authority by a person who knew or ought to have known that. The prescribed circumstances also include a loss or unauthorized use or disclosure that is part of a pattern of similar losses or unauthorized uses or disclosures of personal health information in the custody or control of the custodian.
A further prescribed circumstance is the custodian's determination that the loss or unauthorized use or disclosure is significant after considering all relevant circumstances, including the sensitivity of the information, the volume of information and the number of individuals affected. The custodian must notify the Commissioner of such a circumstance at the first reasonable opportunity.
On or before March 1 in each year a custodian must give the Commissioner a report of the number of times in the previous calendar year that personal health information in its custody or control was stolen, lost, used without authority or disclosed without authority. An agent of a custodian must notify the custodian at the first reasonable opportunity if personal health information that the agent handled on the custodian's behalf is stolen or lost or is used or disclosed without authority.
A custodian that employs a health care practitioner who is a member of a College must give the College written notice within 30 days if the employee is terminated, suspended or subject to disciplinary action as a result of unauthorized collection, use, disclosure, retention or disposal of personal health information.
When LexLint raises it
When your app profile says your app handles health records.