loader from loading.io

PIPEDA’s Mandatory Privacy Breach Notification | Episode #084

Practice Management Nuggets

Release Date: 01/07/2020

5 Strategies for Writing Engaging Social Media Posts for your Practice with Guest Expert Kayla Das show art 5 Strategies for Writing Engaging Social Media Posts for your Practice with Guest Expert Kayla Das

Practice Management Nuggets

Are you a new clinic owner and wondering if social media marketing is for you? Maybe you have been dabbling into social media marketing but now you are feeling overwhelmed? Or, maybe you have an established social media presence but you want to learn new ways to get social media engagement. In this Episode #109 of the Practice Management Nuggets Podcast For Your Healthcare Practice, guest expert Kayla Das of Evaspare Inc. provides 5 strategies for writing engaging social media posts for your practice! Welcome to Practice Management Nuggets podcast, practical practice management, and...

info_outline
Interview Right to Hire Right show art Interview Right to Hire Right

Practice Management Nuggets

Do you feel that you are “unlucky” when making hiring decisions? Have you ever hired someone and then within a few days realized that this isn’t the right fit? Would you like to avoid common hiring mistakes? Would you like some tips on how to improve your hiring process? Hiring the right person for the job is one of the biggest tasks for a manager. It takes time and preparation to conduct effective interviews. Invest the time now to develop the key interview questions. Today we're going to talk with Nelson Scott, who is an expert in hiring employees and a coach for managers who need to...

info_outline
Cybersecurity In Your Privacy Impact Assessment show art Cybersecurity In Your Privacy Impact Assessment

Practice Management Nuggets

How To Include Cybersecurity In Your Privacy Impact Assessment Keeping information safe and secure is a challenging development for businesses of all sizes over the last few years. Remote working and using cloud hosted services forced healthcare practices to change, or at least re-examine, their cybersecurity practices and protocols. According to CyberEdge’s Cyberthreat Defense Report, 85% of organizations suffered from a successful cyberattack in 2021. A privacy impact assessment (PIA) is an important tool to help understand the risks to patient health information and your healthcare...

info_outline
How Virtual Office Medical Administration Services Can Help Your Healthcare Practice show art How Virtual Office Medical Administration Services Can Help Your Healthcare Practice

Practice Management Nuggets

Have you ever said, If only our referral backlog was caught up, our incoming faxes were sorted, our billing team was more confident someone could help with the incoming phone calls during our busiest hours or lunch hour then you want to listen to our episode today how virtual medical office assistants and receptionists can help your healthcare practice. Today my guest expert is Kyle Sherritt of Sherritt Services, and he will show us how a virtual medical office administration service can improve the bottom line of your healthcare practice and improve the patient experience. See all the show...

info_outline
Managing Employees When They Make Mistakes - Addressing Employee Performance show art Managing Employees When They Make Mistakes - Addressing Employee Performance

Practice Management Nuggets

Have you ever had an employee who has made a mistake and now you’re scrambling about what to do next? Your business needs a set of reasonable rules and guidelines for employees to follow. This helps to create a safe and respectful workplace and protect the privacy rights of your patients and employees. Your healthcare practice should have a written policy and procedure to guide you in your response to a privacy and security incident. Sometimes, our employees have been directly involved in the incident. For example: Petty theft (personal gain) Snooping in patient or employee records...

info_outline
Build Your Authority, Appeal, and Profit as an Author show art Build Your Authority, Appeal, and Profit as an Author

Practice Management Nuggets

In this episode #104 of the Practice Management Nuggets Podcast, Lind Stirling will walk you through some of the essentials for creating a profitable book that represents you well. Would you like to help family members of your patients to be better prepared to support your patient after treatments? Would you like to coach your patients in between in-person visits? Do you ever feel that you could help more people avoid / prevent illness if they just did this one thing that you specialize in? Do you want your patients to be more compliant with the follow-up actions that help your patients...

info_outline
Lessons From The Babylon Telus Health OIPC Investigation Report show art Lessons From The Babylon Telus Health OIPC Investigation Report

Practice Management Nuggets

You've probably heard about the Office of the Information and Privacy Commissioner (OIPC) investigation report into Babylon Health. The investigation report provides privacy guidance for vendors of virtual health solutions and the healthcare providers who use the digital health solutions. This is a great demonstration on why it is so important to ensure that you have current information management agreements with your vendors. Jean Eaton shares tips to help you keep your vendor agreements current and explains why it is important to the protection of patient information and the reputation of...

info_outline
5 Critical Things Healthcare Practitioners Need To Have A Profitable Business show art 5 Critical Things Healthcare Practitioners Need To Have A Profitable Business

Practice Management Nuggets

In the latest episode of Practice Management Nuggets Podcast, Tammy Hyska shares her expert tips on 5 Critical Things Healthcare Practitioners Need To Have A Profitable Business.

info_outline
How To Build a Legal Foundation For Your Healthcare Practice | Episode #101 show art How To Build a Legal Foundation For Your Healthcare Practice | Episode #101

Practice Management Nuggets

In the latest episode of Practice Management Nuggets Podcast, Corrinne Boudreau shares her expert tips on How To Build a Legal Foundation For Your Healthcare Practice.

info_outline
What’s New In Cybersecurity In Healthcare | Episode #100 show art What’s New In Cybersecurity In Healthcare | Episode #100

Practice Management Nuggets

What has been happening lately in cybersecurity in healthcare? Today, Anne Genge, CEO of Alexio Corporation is my guest on this episode of Practice Management Nuggets For Your Healthcare Practice! Anne and Jean discuss recent privacy breach scenarios and cybersecurity trends and steps that you can take now to prevent these events to happen to you! Virtual care, telehealth, and working from home presents opportunities – and cybersecurity risks. Digital health and digital transformation has grown rapidly in the last year. Take time now to review your practice and defend yourself from dramatic...

info_outline
 
More Episodes

 

Organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private sector privacy law, are required to report to the Office of the Privacy Commissioner (OPC) any breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals. They also need to notify affected individuals about those breaches, and keep records of all data breaches within the organization.

On today's podcast, PIPEDA’s Mandatory Privacy Breach Notification, we will look at how PIPEDA applies to healthcare organizations and the vendors that support them.

The Privacy Commissioner shares lessons learned after one year of mandatory breach reporting requirements under PIPEDA.

Does PIPEDA Apply To You?

PIPEDA applies to private sector businesses across Canada with the exception of Quebec, Alberta, and BC. In these provinces, provincial legislation wish is substantially similar to PIPEDA applies. In all cases, businesses which handle personal information which crosses provincial or national borders fall under PIPEDA regardless of which province that they are based in.

In Alberta, we have privacy legislation called the Health Information Act (HIA) that takes precedence over PIPEDA and Alberta's Personal Information Protection Act, (PIPA). If a business, like a physician's office, has a privacy breach which includes health information, then the custodian of the physician office must report the privacy breach following the HIA regulations. If it's employee information or other non-health information is included in the breach then that triggers privacy breach notification under PIPA. Sometimes, a breach can include both types of information and the physician office must notify under both legislation.

In BC the Personal Information Protection Act (PIPA) is BC's private sector privacy laws has also been deemed substantially similar to the federal private sector privacy law. BC does not have health information specific privacy legislation, so PIPA applies to private organizations in BC, including physician practices, and governs how the personal information about patients, employees and volunteers may be collected, used and disclosed.

If you are a business in Canada, for example, an electronic medical records (EMR) business and you have a data center in Canada where all of your clients provide their information and store it in your data center, the EMR vendor likely falls under the PIPEDA regulations.

The vendor may be responsive to other legislation as well. If you are an EMR vendor, you do not directly comply with the HIA in Alberta because that applies only to custodians. However, as an information manager of a custodian under the HIA, you have some obligations under the HIA in the event of a privacy breach. But that does not mean that you don't also have obligations under PIPEDA.

Listen to the podcast to learn more!

Show Notes

You can advance the audio to the time entries

03:00  PIPEDA

03:18  Does PIPEDA apply to you?

04:11  Alberta

04:53  British Columbia

05:26  EMR vendor and businesses that support healthcare practices

06:52  What is personal information

07:44  Why is privacy important?

In 2017, 65% of large organizations with more than 100 employees indicated that they were privacy aware, but only 43% of small businesses indicated that they were privacy aware.

09:11  What Is A Privacy Breach

12:44  PIPEDA Mandatory Privacy Breach Reporting Process

12:55  Keep Records

13:27  ROSH

14:04  Report to the OPC

14:10  Notification

Information Manager Agreement – should indicate if a vendor should directly notify a patient about the privacy breach or if the custodian will do the notification. The Information Manager Agreement should also identify which party (parties) is responsible for the cost of notification.

See the Practice Management Success Tip – Top 3 Agreements https://InformationManagers.ca/Top-3

15:46  What is ROSH?

17:47  What information, circumstances of the breach.

19:33   CASL Canada’s Anti-Spam Legislation

20:34  Good Privacy Is Good For Business

When we know better, we can do better…

I’ve helped hundreds of healthcare practices prevent privacy breach pain like this. If you would like to discuss how I can help your practice, just send me an email. I am here to help you protect your practice.

How to Manage a Privacy Breach with Confidence

The 4 Step Response Plan will help you with prevent privacy breach pain and give you the tips, templates, training, and tools that you can use right away to prepare your privacy breach response plan:

In the world of privacy breaches ‘If’ has become ‘When’. Will you be ready?

Link to 4 Step Response Plan

Click here for more information on the on-line 4 Step Response Plan course available now!

https://informationmanagers.ca/4-step


New! Podcast Key Word Search Tool

Did you hear something on today’s podcast that you would like to go back and listen to again?

Searchie Lady

Or, maybe you heard something on one of our previous podcasts that you want to listen to again, but you can’t remember which one and you would like to find it quickly and easily.

Well, that’s easy to do now!

If you heard something on this podcast that you want to re-visit, go to PracticeManagementNuggets.Live/search and enter the keyword in the magic box.

You will automatically be brought to the podcast at the exact spot where we talked about it.


Rate and Review the Podcast

I am honoured that you choose to spend your time with me today. Thank you for the opportunity to share my obsession about privacy, confidentiality and security with you!

Reviews for the podcast on whatever platform that you use is greatly appreciated!

When you provide your honest feedback it helps other people just like you find content that may help them, too.  If you received value from this episode, please take a moment and leave your honest rating and review.

Jean L. Eaton, Your Practical Privacy Coach

and Your Practice Management Mentor

with Information Managers Ltd.