| Custodians, agents and authority |
⚙ |
An agent may only handle information as permitted by the custodian. Access authorisation
is an explicit, dated record naming who may do what — so "who was allowed to see this in
February" has an answer that does not depend on the current state of the system. Who you
appoint is yours. |
| The circle of care — implied consent for providing health care |
✓ |
PHIPA lets custodians assume implied consent to share for the purpose of providing health
care to that patient. This is the exact shape of the care-relationship model:
treating, supervising and administrative relationships are separate kinds, each with a start
date, an end date and a grace period, and read access is derived from them rather than
granted as a role. Membership of the circle is therefore a fact with dates on it, which is
what a commissioner asks to see. |
| The lockbox — express instruction, s. 20(2) and s. 37(1)(a) |
◐ |
Genuinely missing, and the largest gap on this page. A patient can instruct
a custodian not to share part of their record within the circle of care. Today that
instruction can be recorded as a note and honoured by people; it is not an object on the
record that the read path enforces. Section 05 sets out what building it means. |
| Telling the recipient that something was withheld |
◐ |
Where a lockbox stops a disclosure, the custodian must tell the receiving custodian that it
has been prevented from disclosing everything reasonably necessary — so the recipient knows
the picture is incomplete. That notice is part of the same missing piece, and it is the half
people forget. |
| s. 10(1) — information practices in place |
⚙ |
A custodian must have information practices that comply with the Act, and a written public
statement describing them. The versioned policy register holds them; the words are yours. |
| s. 12(1) — reasonable steps to protect |
✓ |
Encryption at rest with keys held outside the database, closed-by-default access derived
from care relationships, an append-only access log, break-glass as a recorded action rather
than a shared password, and a documented risk analysis. Section 03, principle 7. |
| s. 12(2) — notify the individual at the first reasonable opportunity |
✓ |
The breach record carries the affected individuals, what was involved, whether the data was
encrypted, whether keys were compromised, and the notification itself as a step with a date
— so the file answers "when did we tell them" rather than "we think we did". |
| s. 12(3) — report the breach to the Commissioner |
◐ |
Certain breaches must be reported to the IPC. The breach record exists and holds
everything the report needs; what is missing is the Ontario trigger list evaluated
on the record, and the report itself as a produced artefact. Today it is a person reading the
record and filling in the IPC's form. Section 07. |
| Annual breach statistics to the Commissioner |
◐ |
Custodians track breach statistics by calendar year and report the previous year's numbers
to the IPC each March — including breaches that never met the reporting threshold.
The underlying records exist and are categorised; the yearly count is not produced
for you. It is a small piece of work, and it is the kind that gets forgotten in
February — which is the argument for building it rather than remembering it. |
| s. 52–55 — access and correction |
✓ |
Access within 30 days, extendable; correction with a right to attach a statement of
disagreement where the custodian refuses. Both are first-class requests with computed
statutory dates, and a refusal has to record its reason rather than simply closing. |
| O. Reg. 329/04 s. 6(3) — logging, on an electronic record |
✓ |
Records held electronically must keep an electronic record of who accessed what and when.
This is the hash-chained access log, and it is the single most useful artefact in a PHIPA
investigation: it answers the snooping question — did a staff member look at a patient
they had no relationship with — as a query rather than an inference. |
| Health information network provider duties |
◐ |
If you deploy the platform so that two or more custodians share information through
it, section 6(3) adds duties: written agreements, a threat and risk assessment and
privacy impact assessment made available to the custodians, a plain-language description of
the service, an annual written report on accesses, and prompt notice of breaches. The
underlying evidence — the risk analysis, the logs, the breach records — exists.
The HINP statement of practices and the annual report do not, as documents.
A single-practice deployment does not raise this at all. |
| Retention, transfer and disposal |
⚙ |
Records must be retained, transferred and disposed of securely. The retention engine
computes disposal dates and disposal destroys the key rather than hoping every copy was
found; the periods themselves are yours to set, because in Canada they come
from your college. Section 06. |