In this decision, the adjudicator determines that Quinte Health Care (the hospital) breached the Personal Health Information Protection Act, 2004 in permitting staff fulfilling a designated role to access personal health information not reasonably necessary to the role. The inadequacies of the hospital’s processes and policies in defining the access to patient information appropriate to this role resulted in unauthorized accesses to the complainant’s personal health information. This decision also finds that an investigation of allegations of breaches of the complainant’s privacy was conducted in a manner contrary to the hospital’s privacy policies, resulting in other unauthorized accesses. The adjudicator concludes, taking into account a second investigation, that the hospital’s response to the privacy breach was adequate. The hospital has taken steps to remedy the deficiencies in its processes and policies and no orders are necessary.
PHIPA DECISION 155
Collection
Health Information and Privacy
Date
File Numbers
HC17-64
Adjudicators
Sherry Liang
Decision Type
Decision - PHIPA
Applicable Legislation
PHIPA - 12(1)
PHIPA - 17(1)
PHIPA - 17(3)
PHIPA - 30(2)