health information

Showing posts with label health information. Show all posts
Showing posts with label health information. Show all posts

Your daily digital data droppings

Canwest Global is doing a series of feature-length articles on privacy between Christmas and New Year. For the first one, I was "shadowed" by a reporter to look at the sorts of data that we leave in our wake as we go throughout our daily lives.

Our every move is tracked and recorded:

"Short of becoming a hermit, there's little Canadians can do to avoid the pervasive climate of surveillance that surrounds them, says Richard Foot. However, there is protection in knowing what information is sought, how it is collected, and why.

The Ottawa Citizen

Monday, December 27, 2004

David Fraser walks out his front door on a midwinter morning bound for work. His movements and activities are under surveillance, tracked by networks of people and distant computers in his own city and around the planet.

Mr. Fraser isn't a wanted man, nor is he a foreign spy. He's an ordinary Canadian inhabiting a world so wired by ubiquitous technology that almost everything he does is monitored and measured in breathtaking detail.

Mr. Fraser, a Halifax privacy lawyer, isn't concerned about the surveillance itself. What worries him is that most Canadians simply don't know their lives are so closely watched by the silent eyes of business and government. Like federal privacy commissioner Jennifer Stoddart, he calls public ignorance about the vast, daily exchange of personal information the greatest threat to privacy in Canada today.

'The critical thing is that people must be aware of it,' Mr. Fraser says. 'Yet most people simply don't understand much private information they leave behind them each day, during their ordinary routines.'...

The Series

Tomorrow: Biometric wizardry poised to remove last shreds of anonymity.


Wednesday: School security: When safety concerns override privacy rights.


Thursday: Your health records in cyberspace.


Friday: Lives and habits of Canadian consumers up for grabs."

I'll post links to the stories as the appear online.

HIPAA and electronic medical records in one hospital

The Marshfield News Herald (Marshfield, WI) has an article on privacy and hospital records that also briefly discusses some patient attitudes to new processes and procedures:

Marshfield News Herald - Hospitals work on protecting digital records:

"...While the federal government has cracked down on medical privacy, some patients say they were not actually concerned their privacy was being invaded, be it from hackers or from employees within the health care system.

'I have no privacy issues at all, because I could care less if other people saw my medical records,' said Lisa Schilling, 32, of Marshfield. 'What do I have in there that is so good to see?'

Schilling said the HIPAA regulations are actually an inconvenience and would like to help her husband with his medical information 'without them making me sign a piece of paper. It's almost getting too carried away.'

Under HIPAA privacy rules, an individual can schedule an appointment for a spouse but cannot have access to information such as laboratory tests without express written consent from his or her spouse...."

Canadian Privacy Firsts: Misdirected faxes leads to joint investigation and report by Alberta and Federal Commissioners

Canada suffers under a tangle of privacy laws, some of which overlap and others that leave gaping holes. In some cases, a number of privacy laws may apply. Misdirected faxes with sensitive information in Alberta over the summer engaged both the Alberta Health Information Act and the Personal Information Protection and Electronic Documents Act, resulting in the first joint investigation and report from the federal and Alberta privacy commissioners. The report is also notable as the Federal Commissioner's report "names names".

The Federal Commissioner's finding is here:

Report: Misdirected faxes containing health information end up in apartment managers' hands - December 21, 2004

Incident

In July 2004, it was reported in the Edmonton Journal that a couple who managed an apartment building had received facsimile transmissions in error from various sources. These transmissions contained personal medical information.

The Office of the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner of Alberta collaborated in investigating this incident. It was determined that the couple received 10 facsimile transmissions from seven different companies. Some of these transmissions came under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA). Two companies were responsible for these transmissions:

  • Dynacare
  • Viewpoint

The following is a summary of the investigation into the incidents.

Summary of Investigation — Dynacare

One facsimile was sent erroneously by Dynacare, which operates medical laboratories, on January 19, 2004. It contained such personal information as the name, age, height, smoking habits, and patient number of an individual who had undergone testing by the company. Also included was a diagnosis and specific medical test results for the individual.

Once the company had been alerted to the privacy breach, it investigated the incident but was unable to determine who was directly responsible for the transmission. It was able to narrow responsibility, however, down to one of five individuals. Our Office confirmed that the facsimile was sent via manual transmission, in other words, the person who sent the facsimile manually keyed in the number.

All five individuals had signed an oath of confidentiality at the time of hiring, and were aware of the confidential nature of the medical records and the need to ensure that they are not inappropriately disclosed. These oaths had not been reviewed since they were signed. The company has developed a new form and will ensure that employees review and sign it annually.

Dynacare also implemented an electronic auto fax function on its computers. Facsimile numbers are entered into the system and checked for accuracy. If an employee wishes to send a facsimile, he or she will use the automated system. Such a measure should minimize the risk of regularly used numbers being misdialed. For numbers that are used infrequently or on a one-time basis (they are not programmed into the system), Dynacare provided employees with a set of instructions that are intended to ensure that they confirm the accuracy of the fax numbers before transmission.

Dynacare is in the process of revising its policies and procedures to ensure full compliance with all applicable legislation, including Alberta's Health Information Act and the PIPEDA.

Although Dynacare had not notified the individual whose personal information was on the facsimile, it indicated that it would consider doing so.

Conclusion

The Assistant Privacy Commissioner concluded that Dynacare disclosed personal information without consent, contrary to the provisions of PIPEDA.

Summary of Investigation — Viewpoint

Viewpoint is a medical organization that provides diagnosis consultation services. The facsimile in question, sent on April 14, 2004, was a medical evaluation. It contained the patient's name, age, occupation, detailed medical history, and also included information about the patient's children. The evaluation was sent by a medical consultant to a Viewpoint physician, who reviewed and made comments on the report. It was then supposed to be sent back to the consultant via facsimile. Two of the numbers, however, were transposed, and the facsimile was sent to the incorrect place. Although the Viewpoint physician made notes to the report, he was not responsible for its transmission and Viewpoint has not been able to determine who in fact sent the facsimile to the wrong number.

When the recipients of the facsimile contacted Viewpoint regarding the transmission they were told to destroy the documentation. Viewpoint indicated to our Office that in future, should any facsimile transmissions containing personal information be sent to the wrong number, Viewpoint will dispatch a courier to retrieve any such records. The company has also taken steps to have all facsimile numbers verified before transmission and has implemented measures to have any incidents reported to management.

As for the patient in question, Viewpoint indicated that it would be more appropriate for the medical consultant to contact the patient regarding the disclosure as they have a doctor-patient relationship.

Conclusion

The Assistant Commissioner concluded that Viewpoint contravened PIPEDA when it disclosed personal information without consent.

Recommendations made to Dynacare and Viewpoint

The Assistant Commissioner made the following recommendations to both companies:

  • That the organizations implement and follow the OPC's recommendations with respect to the transmission of facsimiles as set out in the fact sheet Faxing Personal Information.
  • That the organizations implement measures to notify individuals whose personal information has been inadvertently disclosed via misdirected facsimiles.
  • That the organizations review and update employee confidentiality/privacy agreements on a yearly basis.


The press release from the Alberta Information and Privacy Commissioner is available in PDF at http://www.oipc.ab.ca/ims/client/upload/NR_H2004_IR_001_2.pdf and his report is here: http://www.oipc.ab.ca/ims/client/upload/H2004-IR-001.pdf

From the Edmonton Journal:

Clinics, doctors criticized for fax foul-ups: Privacy commissioner puts onus on offices to ensure information sent to correct number:

"EDMONTON - A new report from Alberta's privacy commissioner is a sharp reminder to health workers that careless faxes can put patient privacy in jeopardy.

Each day, hundreds of fax machines in medical clinics send patient information from one place to another. It's the standard way information is shared among doctors, therapists, laboratories and consultants.

On Tuesday, the commissioner's office released a 16-page report that found two local doctors and three clinics violated the Health Information Act by not handling faxes correctly.

The investigation was launched after The Journal reported in July that a local woman received more than 20 faxes with confidential medical information that were supposed to go to LifeMark Health Institute, a private medical consulting company. Nese Premakumran's fax number was one digit different from LifeMark's...."

Privacy, hospitals and law enforcement

A FOX station in the pacific northwest is carrying the following story:

FOX 12 OREGON Conflict with law enforcement:

"WENATCHEE, Wash. Last spring a Douglas County man shot himself in the hand while cleaning his gun.

He was treated at a hospital that did not report the incident to law enforcement because of privacy law.

Douglas County Sheriff Dan LaRoche heard about it weeks later and said it should have been investigated, although he believes it was an accident.

The incident is an example of how the privacy law (Health Insurance Portability and Accountability Act -- known as HIPAA) can hamper law enforcement.

A spokeswoman for the Washington State Hospital Association, Cassie Sauer, says the year-old law has strained the working relationship between health care workers and police in some areas of the state.
(Wenatchee World)"


In Alberta, the Health Information Act allows healthcare providers to tell the cops, but only if the person has not told the hopspital not to: "Doc, don't tell the cops about my seven gunshot wounds."

OPC and Ontario pharmacists release new guidelines on dispensing Plan B emergency contraception

This just came over the wires ...

New Privacy-Protective Guidelines for the Provision of 'Plan B' Emergency Contraception by Pharmacists in Ontario:

TORONTO, Dec. 15 /CNW/ - New guidelines for pharmacists have been issued
in record time through a highly successful collaboration between the Ontario
College of Pharmacists, the Ontario Pharmacists' Association and the
Information and Privacy Commissioner of Ontario.

Dr. Ann Cavoukian, Ontario's Information and Privacy Commissioner,
stated, "Within a short week of voicing my concerns, I am delighted to say
that our joint working group has successfully collaborated and reached an
agreement on made-in-Ontario guidelines for pharmacists providing Plan B."

These guidelines follow the issuance of the College's December 8, 2005
notice advising pharmacists not to use the "Screening Form for Emergency
Contraceptive Pills (ECPs)," developed by the Canadian Pharmacists
Association, which recommended the collection of detailed personal
information.

Ontario's new guidelines (available at www.ocpinfo.com) emphasize that
pharmacists should continue to seek information from the patient only as
necessary to clarify the appropriateness of providing Plan B, keeping in mind
the need to respect the individual's right to remain anonymous and to decline
responding to personally sensitive questions.

"I was assured by the College that pharmacists do not routinely collect
personally identifiable information with regard to the provision of Schedule
II products," said the Commissioner. Personally identifiable information
should not be recorded except when requested by the patient for reimbursement
purposes or in those rare instances where it is deemed important for
continuity of care of the patient.

Under the Personal Health Information Protection Act (PHIPA), which was
enacted last year to protect the health information of Ontarians, health
information custodians must minimize their collections of personal health
information and must not collect identifiable information if other information
will serve the same purpose.

The Information and Privacy Commissioner is appointed by and reports to
the Ontario Legislative Assembly, and is an independent officer of the
Legislature. The Commissioner's mandate includes overseeing the access and
privacy provisions of the Freedom of Information and Protection of Privacy
Act, the Municipal Freedom of Information and Protection of Privacy Act, and
the Personal Health Information Protection Act, and commenting on other access
and privacy issues.



December 15, 2005

Notice to Pharmacists

Re: Ontario Guidelines for Provision of Plan B (Schedule II)

Following the issuance of an Ontario College of Pharmacists Notice to
Pharmacists last week concerning a specific form being used in some cases when
the Schedule II product, Plan B, was requested, a working group was formed,
consisting of staff from the College, the Ontario Pharmacists Association, and
the Office of the Information and Privacy Commissioner of Ontario.

The goal of the group was to develop and agree on guidelines which could
be used by pharmacists in Ontario to ensure that their ongoing practice with
respect to the sale of this product meets all applicable legislation,
including Standards of Practice. The attached document will serve to clarify
the expectations of the College that pharmacists will continue to serve their
patients well by providing appropriate information and counselling and to add
value to the sale of Plan B as they would for any Schedule II product.

It is suggested that existing tools and practice be examined at this time
to ensure compliance with these guidelines.

Yours truly,

(signed)

Anne Resnick, R.Ph., B.Sc.Phm

Associate Director, Professional Practice Programs

Attachment


Ontario College of Pharmacists - December 15, 2005


Ontario Guidelines for Provision of Plan B (Schedule II)

Pharmacists are health care professionals whose practice is guided by the
Code of Ethics and Standards of Practice established by their regulatory body,
the Ontario College of Pharmacists (OCP). Pharmacists practice in accordance
with all applicable legislation and regulations including Ontario's privacy
legislation, the Personal Health Information Protection Act, 2004 (PHIPA).
These guidelines are the result of the joint efforts of the OCP, the Office of
the Information and Privacy Commissioner of Ontario (IPC), and the Ontario
Pharmacists' Association (OPA). These guidelines follow the issuance of OCP's
December 8, 2005 notice which advised pharmacists not to use the "Screening
Form for Emergency Contraceptive Pills (ECPs)," developed by the Canadian
Pharmacists Association (CPhA).

As there are already educational resources available to pharmacists for
Plan B, these guidelines will not duplicate those efforts, but will outline
the appropriate application of OCP's Standards of Practice and Code of Ethics
and PHIPA in the context of providing Plan B.

The IPC recognizes the important health care services pharmacists
provide. The IPC's mandate is to ensure that personal health information is
collected, used and disclosed in the most privacy protective manner possible.
Specifically, under PHIPA, health information custodians shall not collect,
use or disclose personal health information if other information will serve
the purpose. Moreover, PHIPA restricts the collection, use and disclosure of
personal health information to that which is reasonably necessary to meet the
purpose of providing health care. OCP's Code of Ethics and Standards of
Practice provide the framework for pharmacists' practice. Many components of
the Code of Ethics and Standards of Practice protect patient privacy and
reinforce the Ontario health privacy legislation, PHIPA.

For the provision of Plan B, as with any other Schedule II product, the
pharmacist must always be involved in the decision to provide the medication.
As with other medications, prior to its sale, the pharmacist has a
professional responsibility to be assured of the appropriateness of the drug
for the individual.

Pharmacists should continue to seek information from the patient only as
necessary to clarify the appropriateness of providing Plan B, keeping in mind
the need to respect the individual's right to remain anonymous and to decline
responding to personally sensitive questions. As with all Schedule II
products, if a pharmacist makes a decision not to sell Plan B, reasons should
be communicated to the patient.

Pharmacists do not routinely collect personally identifiable information
as it relates to the provision of Schedule II products. In the case of Plan B,
personally identifiable information should not be recorded except when
requested by the patient for reimbursement purposes or in those rare instances
where it is deemed important for continuity of care of the patient.




For some background, see


PHIPA declared substantially similar

Thanks to a regular correspondent for pointing this out ...

The Personal Health Information Protection Act of Ontario has been declared to be substantially similar to PIPEDA:

Canada Gazette:

Health Information Custodians in the Province of Ontario Exemption Order

P.C. 2005-2224 November 28, 2005

Whereas the Governor in Council is satisfied that the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, of the Province of Ontario, which is substantially similar to Part 1 of the Personal Information Protection and Electronic Documents Act (see footnote a), applies to the health information custodians referred to in the annexed Order;

Therefore, Her Excellency the Governor General in Council, on the recommendation of the Minister of Industry, pursuant to paragraph 26(2)(b) of the Personal Information Protection and Electronic Documents Act (see footnote b), hereby makes the annexed Health Information Custodians in the Province of Ontario Exemption Order.

HEALTH INFORMATION CUSTODIANS IN THE PROVINCE OF ONTARIO EXEMPTION ORDER

EXEMPTION

1. Any health information custodian to which the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, applies is exempt from the application of Part 1 of the Personal Information Protection and Electronic Documents Act in respect of the collection, use and disclosure of personal information that occurs within the Province of Ontario.

COMING INTO FORCE

2. This Order comes into force on the day on which it is registered.

Churches and the federal privacy law

Focus on the Family is running the following article in their "Today's Family News":

Churches fear breaching privacy laws

December 14, 2005

Recent privacy legislation is causing some churches to fear they could be breaking the law simply by circulating the addresses of members, praying aloud for people by name, and – at least in Ontario – making hospital visits, the Ottawa Citizen reported.

At the heart of their concern, which some think is exaggerated, is the Personal Information Protection and Electronic Documents Act, which Parliament passed in January 2004. It primarily affects businesses and would only apply to churches that sold their parish or membership lists or charged for their services.

Even so, it has prompted some pastors to question whether even making public the names and addresses of the people in their congregations might be deemed illegal under the Act.

One church in Halifax, for example, removed a “prayer board” in its foyer listing the names of people in hospital. Others have adopted privacy policies and some have even appointed privacy officers to oversee the correct handling of information.

For clergy in Ontario, the province’s year-old Personal Health Information Protection Act has made it more difficult from them to visit hospital patients, even if they belong to the same denomination.

Patients when being admitted have the option of indicating their faith background, which James Christie, dean of the faculty of theology at the University of Winnipeg, says clergy have assumed indicated they would welcome “some sort of pastoral presence.” But now, as he told the Citizen, “that graciousness is gone.”

But London, Ontario, lawyer Janet Allinson, a specialist in privacy law, believes many churches “are misunderstanding the legislation altogether. I get quite a few calls from people very concerned, they are so afraid of the Privacy Act.”

"I think it's important that they don't lose the spirit and treat it like a business" added Allinson.



The impact of the federal private sector privacy law has been very misunderstood by churches and other non-profits.

The Personal Information Protection and Electronic Documents Act, or PIPEDA as it is commonly known, applies to the collection, use and disclosure of personal information in the course of commercial activities, except in those provinces that have enacted substantially similar legislation. Ontario has not enacted legislation that is substantially similar to PIPEDA (other than the Personal Health Information Protection Act which may hinder the abilities of health information custodians to share information with visiting clergy, but does not regulate churches directly). In short, PIPEDA applies to personal information that is handled in connection with commercial activities, other than in Alberta, BC and Quebec.

The reason for the commercial activity connection is that the Federal Government is relying upon its constitutional jurisdiction over general trade and commerce in Canada to implement PIPEDA. It can use this power to regulate commerce generally, but is not able to regulate the non-profit sector using this power except to the extent that the non-profit organization actually is engaged in commercial activity. There are some activities that a non-profit can engage in that are deemed commercial activities and some activities can be sufficiently commercial to invoke PIPEDA. The deemed activities are generally limited to certain kinds of dealing with membership and donor lists. If a church exchanges, sells, trades or leases its membership list, that is a deemed commercial activity and PIPEDA applies (including requiring consent for the transfer). The key is an exchange of value. If a list is freely given with no expectation of any value in return, there is no commercial activity and PIPEDA is not triggered. Also, if a church veers away from its core not-for-profit objectives, it can be seen to be engaged in commercial activity. Charging admission to a benefit concert for the church is not commercial activity. Operating a business within the church may be commercial. Church fund-raising is not a commercial activity, nor is praying out loud or listing members in a directory.

This does not mean that a church or a non-profit shoudn't follow fair information practices. This is not because it is required by PIPEDA or any other law, but rather because it is just the right thing to do. Churches are entrusted with sensitive personal information. Having a privacy policy that is reasonable and consistently followed sends a positive message to the members of the congregation who are more privacy aware.

Discussion of Canadian Plan B and privacy issues in the BMJ

The British Medical Journal has an article on the current controversy in Canada over the collection of personal information in connection with dispensing the morning after pill, aka Plan B: Advice to pharmacists on dispensing contraception an "invasion of privacy" -- Spurgeon 331 (7529): 1360 -- BMJ.

There is also a letter to the editor in the December 9 edition that raises one of the most significant issues for pharmacists. Namely, the role of pharmacists in the dispensing of such drugs:

bmj.com Rapid Responses for Spurgeon, 331 (7529) 1360:

Spurgeon's news(1) seems to fall into a recurrent BMJ bias: forgetting the clinical role of the pharmacist. The text seems to state that pharmacists gathering relevant clinical information are invading patient privacy. This leads to a dichotomy: Is a physician invading patient privacy when gathering patient clinical information? Or, do pharmacists invade patient privacy because they should not act clinically?

Obviously, there is no doubt to the first question. Assessing clinical situations requires some information about patient health status, but also about patient life style. So, a healthcare professional needs information to make a decision, and sometimes this information can be considered as private. Thus, confidentiality is expected.

But, what about the second question? Is this the never-ending story? When are we going to shoot(2) the pharmacist? How big should be the evidence of the benefits of the clinical role of pharmacist working together with the other healthcare professionals?

And the most important question, why do not give the right to choice to the patient? If patients want to give that private information to their pharmacists, why should another healthcare professional disagree?

Jurisdictional limitations on Canadian privacy law

Canada's privacy law is already hobbled by the constitutional division of power. For example, as a federal law, it cannot apply to the provincially regulated workplace. But, theoretically, it can apply outside of Canada's border. This has been the theoretical position of officials from the Office of the Privacy Commissioner. However, when dealing with an actual complaint, the Commissioner did not extend the federal privacy law to an organization entirely outside of Canada.

Michael Geist, in his weekly Toronto Star Column, reports on an as-of-yet unpublished finding of the Commisioner that concludes that the law cannot regulate the use of Canadian personal information that is in the hands of an organization that has no presence in this country:

TheStar.com - CIBC breach spotlights hole in privacy law:

"...According to a recent unpublished letter from the privacy commissioner, the answer is unfortunately no. The Commissioner has adopted the position that Canada's privacy legislation stops at the border and that her office does not have the power to investigate companies that do not have a physical presence in Canada.

The letter was issued in response to a complaint launched by the Canadian Internet Policy and Public Interest Clinic (CIPPIC) against Abika.com, a U.S. company that harvests databases and public reports. The company uses the information to produce reports that allegedly include, in some cases, psychosexual profiles. CIPPIC filed its complaint in June, claiming that Abika collects, uses, and discloses the personal information of Canadians without their consent in violation of Canada's national privacy law.

The privacy commissioner's office responded privately to Canadian Internet Policy and Public Interest Clinic two weeks ago. It noted that the company does not have a physical presence in Canada and therefore concluded that 'while the organization may well be collecting information on Canadians, our legislation does not extend to investigating organizations located only in the United States. We are, therefore, unable to investigate this matter under PIPEDA' (the Personal Information Protection and Electronic Documents Act, Canada's national privacy law that governs how businesses collect and use personal information)...."



I tend to agree with Michael ... the Privacy Commissioner could have asserted jurisdiction and then dealt with the challenges of enforcement. This would at least have left the complainant with the ability to take the finding to the Federal Court of Canada to see if a real remedy could be fashioned.

Under traditional principles of international law, there are six bases on which a country such as Canada can assume jurisdiction to proscribe the actions of individuals and companies. (In most cases, these principles have arisen in the criminal law context but there is no reason to believe the Canadian courts would not apply them.) Four of the bases for jurisdiction are relevant to this discussion:

  • Territorial Principle – A state has the jurisdiction to regulate individuals and subjects within its territory, including internal waters and airspace. This is the primary and most universal base for jurisdiction.
  • Nationality Principle – Civil law countries have traditionally asserted jurisdiction over their nationals, regardless of where they may be located.
  • Passive Personality Principle – States have assumed jurisdiction over crimes committed abroad against its nationals.
  • By Agreement – A country may, by agreement, grant another country jurisdiction over certain persons or subjects within its borders.


Traditionally, the territorial principle has been the most persuasive and widely applied. This is based on the fundamental principle of international sovereignty that a state has absolute jurisdiction over "all persons, citizens and aliens alike, and things within its territory."

The Supreme Court of Canada’s decision in Libman v. The Queen is the leading Canadian authority on the issue of how and when a Canadian court may assert jurisdiction. Libman dealt with a "telemarketing scam" where the calls originated from Canada but were made to residents of the United States. Justice LaForest, who delivered the judgment of the unanimous court, recited the relevant facts:

3 During the period covered by the informations, Mr. Libman operated a telephone sales solicitation room (or "boiler room") at 43 Menin Road in Toronto, where a number of individuals were employed as telephone sales personnel. Pursuant to Mr. Libman's directions the sales personnel telephoned United States residents and attempted to induce them to purchase shares in two companies, Hebilla Mining Corporation and Claravella Corporation, which purported to be engaged in gold mining in Costa Rica. In addition to the telephone representations, the United States residents also received promotional material which was mailed from Panama City, Panama and San José, Costa Rica by associates of Mr. Libman.

4 The telephone sales personnel, on the direction of Mr. Libman, made material misrepresentations with respect to their identity, where they were telephoning from, and the quality and value of the shares they were selling. As a result of these misrepresentations, a large number of United States residents were induced to purchase shares in the two mining companies. There was some evidence tendered at the preliminary inquiry from which it could be inferred that these shares were virtually worthless.

5 The United States residents who agreed to purchase shares were told by the telephone sales personnel to send their money to offices operated by Mr. Libman's associates in either San José, Costa Rica or Panama City, Panama. There was evidence tendered that Mr. Libman went to a location outside Canada, usually Costa Rica or Panama, to meet with his associates and receive his share of the proceeds of the sale of the shares. Mr. Libman then brought this money back to Toronto and distributed a portion of it to his sales personnel. There was also evidence tendered at the preliminary inquiry with respect to the wire transfer of monies from Panama City to Mr. Libman in Toronto.



The appellant, Mr. Libman, was charged in Canada with fraud under the Criminal Code. In his defence, the appellant argued that Canada did not have the jurisdiction to prosecute him for the offence as the deprivation of the victim is the essential element of the offence and, if it did occur at all, it did not occur in Canada.

Justice LaForest began with the essential principle of territorial jurisdiction:

11 The primary basis of criminal jurisdiction is territorial. The reasons for this are obvious. States ordinarily have little interest in prohibiting activities that occur abroad and they are, as well, hesitant to incur the displeasure of other states by indiscriminate attempts to control activities that take place wholly within the boundaries of those other countries; see R. v. Martin, [1956] 2 All E.R. 86, at p. 92. … As well, along with other types of protective measures, states increasingly exercise jurisdiction over criminal behaviour in other states that has harmful consequences within their own territory or jurisdiction; see The Lotus (1927), P.C.I.J., Ser. A., No. 10. It follows from this that the same criminal act may occasionally be subject to prosecution in more than one country, a matter to which I shall refer from time to time.



The analysis is relatively straightforward where all the elements and effects of an alleged offence are within the bounds of the prosecuting state: Territorial and subject matter jurisdiction unambiguously provide that state with sufficient grounds to assert jurisdiction. In fact, it would be difficult for another state to attempt to exert jurisdiction. Matters become much more complicated when transnational activities are in question:

16 The cases reveal several possibilities, of which I mention a few. One is to assume that jurisdiction lies in the country where the act is planned or initiated. Other possibilities include the place where the impact of an offence is felt, where it is initiated, where it is completed, or again where the gravamen, or essential element of the offence took place. It is also possible to maintain that any country where a substantial or any part of the chain of events constituting an offence takes place may take jurisdiction.

17 Though counsel for Mr. Libman argued that exclusive jurisdiction belongs to the country where the gravamen of the offence took place or where it was completed, a review of the English authorities does not really support that position. What it shows is that the courts have taken different stances at different times and the general result, as several writers have stated, is one of doctrinal confusion, a confusion compounded by the fact that the discussion often focuses on the specific offence charged, a discussion made more complicated by the further fact that some offences are aimed at the act committed and others at the result of that act.



After surveying the threads of English and Canadian jurisprudence, LaForest J. concluded that a Canadian court may assert jurisdiction in circumstances where there is a "real and substantial link" between the offence and Canada:

74 I might summarize my approach to the limits of territoriality in this way. As I see it, all that is necessary to make an offence subject to the jurisdiction of our courts is that a significant portion of the activities constituting that offence took place in Canada. As it is put by modern academics, it is sufficient that there be a “real and substantial link” between an offence and this country, a test well-known in public and private international law; see Williams and Castel, supra; Hall, supra. As Professor Hall notes (p. 277), this does not require legislation. It was the courts after all that defined the manner in which the doctrine of territoriality applied, and the test proposed simply amounts to a revival of the earlier way of formulating the principle. It is in fact the test that best reconciles all the cases. The only ones that do not fall within it are those like Harden and Rush which, in my view, should no longer be followed.

75 That this approach is attuned to modern times is evident from the fact that some variant of it has been recommended by numerous law reform bodies or adopted in legislation…

76 Just what may constitute a real and substantial link in a particular case, I need not explore. There were ample links here. The outer limits of the test may, however, well be coterminous with the requirements of international comity.

77 As I have already noted, in some of the early cases the English courts tended to express a narrow view of the territorial application of English law so as to ensure that they did not unduly infringe on the jurisdiction of other states. However, even as early as the late 19th century, following the invention and development of modern means of communication, they began to exercise criminal jurisdiction over transnational transactions as long as a significant part of the chain of action occurred in England. Since then means of communications have proliferated at an accelerating pace and the common interests of states have grown proportionately. Under these circumstances, the notion of comity, which means no more nor less than “kindly and considerate behaviour towards others”, has also evolved. How considerate is it of the interests of the United States in this case to permit criminals based in this country to prey on its citizens? How does it conform to its interests or to ours for us to permit such activities when law enforcement agencies in both countries have developed cooperative schemes to prevent and prosecute those engaged in such activities? To ask these questions is to answer them. No issue of comity is involved here. In this regard, I make mine the words of Lord Diplock in Treacy v. Director of Public Prosecutions cited earlier. I also agree with the sentiments expressed by Lord Salmon in Director of Public Prosecutions v. Doot, supra, that we should not be indifferent to the protection of the public in other countries. In a shrinking world, we are all our brother's keepers. In the criminal arena this is underlined by the international cooperative schemes that have been developed among national law enforcement bodies.

78 For these reasons, I have no difficulty in holding on the facts agreed upon for the purpose of this appeal, that the counts of fraud with which the appellant is charged may properly be prosecuted in Canada, and I see nothing in the requirements of international comity that would dictate that this country refrain from exercising its jurisdiction. Since these fraudulent activities took place in Canada, it follows for the reasons set forth in the Chapman case that the conspiracy count may also be proceeded with in Canada.



It goes without saying that the evolving adoption of privacy and data protection laws are not identical to criminal law, either domestically or internationally. However, analogies are easily made and there is an evolving international cooperative scheme, beginning with the OECD Guidelines.

As the basis for Canada to claim jurisdiction requires a "real and substantial link" between the activity and Canada, one must consider whether the collection of personal information about Canadians by foreign companies would be considered to provide a "real and substantial link" to Canada or the collection of information about non-Canadians by a Canadian company. The facts in Libman are sufficiently analogous to provide authority for the proposition that a court on review would likely find a “real and substantial link” between such activities and Canadian jurisdiction, notwithstanding any argument that the connection is de minimis.

The Personal Information Protection and Electronic Documents Act sets out, at Section 4, the basis of its application:

Application

4. (1) This Part applies to every organization in respect of personal information that

(a) the organization collects, uses or discloses in the course of commercial activities; or

(b) is about an employee of the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.



Limit

(2) This Part does not apply to

(a) any government institution to which the Privacy Act applies;

(b) any individual in respect of personal information that the individual collects, uses or discloses for personal or domestic purposes and does not collect, use or disclose for any other purpose; or

(c) any organization in respect of personal information that the organization collects, uses or discloses for journalistic, artistic or literary purposes and does not collect, use or disclose for any other purpose.



Other Acts

*(3) Every provision of this Part applies despite any provision, enacted after this subsection comes into force, of any other Act of Parliament, unless the other Act expressly declares that that provision operates despite the provision of this Part.



The application section is entirely silent with respect to its intended territorial application. The only reference to specific jurisdictions are contained in the transitional provisions and the definition of "federal work, undertaking or business". The transition provisions begin with Section 30:

DIVISION 5

TRANSITIONAL PROVISIONS

Application

30. (1) This Part does not apply to any organization in respect of personal information that it collects, uses or discloses within a province whose legislature has the power to regulate the collection, use or disclosure of the information, unless the organization does it in connection with the operation of a federal work, undertaking or business or the organization discloses the information outside the province for consideration.

Application

(1.1) This Part does not apply to any organization in respect of personal health information that it collects, uses or discloses.

Expiry date

*(2) Subsection (1) ceases to have effect three years after the day on which this section comes into force.

*[Note: Section 30 in force January 1, 2001, see SI/2000-29.]

Expiry date

*(2.1) Subsection (1.1) ceases to have effect one year after the day on which this section comes into force.

*[Note: Section 30 in force January 1, 2001, see SI/2000-29.]



These provisions are temporary (and expired on January 1, 2004), as they assist with the gradual implementation of the legislation, providing individual provinces with the ability to put in place substantially similar legislation during the period in which the law only applies to the federally regulated private sector and cross-border sales of information. It may be notable that the cross-border reference says "outside the province" and not "to another province".

In the absence of clear guidance from the statute, one can interpret it to apply in all circumstances where there exists a "real and substantial link" to Canada, following the Supreme Court's guidance in Libman. In any event, there is nothing in the statute that would prevent Canada from assuming jurisdiction in the circumstances set out above.

In the past, Officials with the Office of the Privacy Commissioner have advised that the Commissioner likely would assume jurisdiction where the collection of personal information is about Canadians or Canadian residents or where the collection originates in Canada. This appears to no longer be the case. Not only would the collection take place "in Canada", the Commissioner’s office used to be of the view that PIPEDA is part of an international scheme of privacy protection that could reach over borders.

The Privacy Commissioner has an arguable basis to make this second assertion and assume jurisdiction. As mentioned above, Canada implemented PIPEDA following the OECD Guidelines and in light of threatened restrictions on cross-border data flows caused by the EU Directive. Recital 20 of the EU Directive reads:

(20) Whereas the fact that the processing of data is carried out by a person established in a third country must not stand in the way of the protection of individuals provided for in this Directive; whereas in these cases, the processing should be governed by the law of the Member State in which the means used are located, and there should be guarantees to ensure that the rights and obligations provided for in this Directive are respected in practice;


The EU Directive is implemented, for example, in the United Kingdom's Data Protection Act 1998, which provides that the statute would apply, for example, if a call centre contacting Canadians were located in the United Kingdom:

Application of Act.

5. - (1) Except as otherwise provided by or under section 54, this Act applies to a data controller in respect of any data only if-

(a) the data controller is established in the United Kingdom and the data are processed in the context of that establishment, or

(b) the data controller is established neither in the United Kingdom nor in any other EEA State but uses equipment in the United Kingdom for processing the data otherwise than for the purposes of transit through the United Kingdom.



(2) A data controller falling within subsection (1)(b) must nominate for the purposes of this Act a representative established in the United Kingdom.

(3) For the purposes of subsections (1) and (2), each of the following is to be treated as established in the United Kingdom-

(a) an individual who is ordinarily resident in the United Kingdom,

(b) a body incorporated under the law of, or of any part of, the United Kingdom,

(c) a partnership or other unincorporated association formed under the law of any part of the United Kingdom, and

(d) any person who does not fall within paragraph (a), (b) or (c) but maintains in the United Kingdom-

(i) an office, branch or agency through which he carries on any activity, or

(ii) a regular practice;



and the reference to establishment in any other EEA State has a corresponding meaning.



While Canada is obviously not bound by the EU Directive, it appears to be the spirit of PIPEDA that the Canadian law fit within this general scheme of international data protection.

This may be academic, as this no longer appears to be the position of the Office of the Privacy Commissioner.

Canadian draft guidelines to shield personal information from the USA Patriot Act

The Canadian Press just released a story about new draft guidelines for Canadian federal government departments designed to (at least try to) shield information about Canadians from the reach of the USA Patriot Act. The guidelines remain in draft form as the election has intervened to prevent them from being tabled in Parliament this fall and more internal consultations are taking place.

Canada drafts proposals to shield personal data from U.S. anti-terror law - Yahoo! News

... The draft guidance document suggests, in the interest of upholding Canadian privacy laws, that federal databases of sensitive personal information created by contractors be located in Canada and be accessible only within the country.

However, it recognizes international trade obligations may make this impossible. In such cases, the government suggests contractors must agree to respect Canadian privacy laws as a condition of contract.

The guidelines say that if the privacy risk is considered high, a federal department might go so far as to cut off the flow of personal information to a foreign firm should it be "presented with an order" - such as an FBI notice - compelling release of data about Canadians.

In general, the guidelines encourage departments to assess each potential contract case-by-case to gauge the possibility of privacy invasion, the expectations of Canadians, and likelihood of injury to a person's "career, reputation, financial position, safety, health or well-being."

Treasury Board spokesman Robert Makichuk said the draft guidelines were undergoing revision following internal federal consultations....

Ontario Information and Privacy Commissioner responds to "Plan B" concerns

A letter to the editor in today's Toronto Star:

TheStar.com - No problem with giving Plan B info:

Letter, Dec. 9.

In his letter, Tim Lu stated that I recommended pharmacists not ask any questions when dispensing Plan B. Allow me to offer the following correction. I refer him to the Ontario College of Pharmacists notice of Dec. 8, 2005, which states the following: 'the Privacy Commissioner stressed that pharmacists should continue to provide information to patients who request this drug, to gather information and to educate and counsel patients. Pharmacists should ask questions of patients if necessary in the course of providing this service but should not record personal health information in a manner which identifies individual patients.'

My office did not recommend that pharmacists not communicate relevant information to women to ensure the safe and effective use of Plan B. Indeed, I noted that pharmacists provide very important services and guidance. However, in order to protect the privacy of Ontarians, as I am mandated to do under the Personal Health Information Protection Act, I must ensure that identifiable personal health information is only collected when it is necessary and that no more personal health information is collected than is necessary. With this in mind, my office together with the Ontario College of Pharmacists and the Ontario Association of Pharmacists is working expeditiously to develop new guidelines to assist pharmacists when dispensing Plan B.

Again, let me be clear. I have no problem with a pharmacist imparting information on Plan B to patients. My concerns lie with the unnecessary collection and recording of personally identifiable, sensitive health information.


Ann Cavoukian, Ontario Information and Privacy Commissioner, Toronto

Beyond the Patchwork of Privacy Regulations

Kristina Lovejoy at Newsfactor is calling for omnibus privacy legislation for the US. What's interesting is that what she proposes looks a lot like the CSA Model Code that's built into PIPEDA:

NewsFactor Network - Enterprise - Beyond the Patchwork of Privacy Regulations:

...Because terms like privacy, confidentiality, and security often create confusion, the label 'information protection' was coined to encompass the range of mechanisms that guide collection, use, and disclosure of information. An information-protection regulation is one that enforces the right of privacy by dictating, among other things, requirements for maintaining the confidentiality, integrity, and availability of protected data.

In general, a strong information-protection plan would require the following:

1. Establishing ownership and accountability within the organization for confidentiality, integrity, and availability.

2. Identifying the reasons for obtaining private information from an end user and making those reasons available.

3. Establishing mechanisms for gaining consent of the end user before collecting private information.

4. Limiting collection of private information only to that information you need for business purposes.

5. Limiting use and disclosure only for the purposes for which you have gained consent, and limiting retention of information to a period specified by law or by user consent.

6. Ensuring that information collected is accurate.

7. Implementing administrative, technical, and physical controls around information to ensure its confidentiality, integrity, and availability.

8. Creating a culture of openness so that if the confidentiality, integrity, or availability of the information is breached in a significant way, the user is notified.

9. Providing the end user with documented escalation policy and process.

In the U.S., information-protection mandates have generally had impact only in certain market segments, such as the Health Insurance Portability and Accountability Act (HIPAA) in healthcare industry and the Gramm-Leach-Bliley Act (GLBA) in the banking sector.

Will there be increased pressure to regulate other industries? Yes. Will there be impetus for creating an Omnibus Information Protection regulation? Definitely.

Sexual history no longer taken for morning after pill in Ontario

Futher to my blog posting The Canadian Privacy Law Blog: Morning-after pill privacy concerns raised, the Information and Privacy Comimssioner of Ontario has stepped in to advise the Ontario College of Pharmacists that the interrogation of customers seeking the "morning after pill" was too broad to comply with the Personal Health Information Protectoin Act. From TheStar.com:

Cavoukian said in an interview she was unaware of the form until she read about it in the Star and "I was taken aback. It struck me that a lot of information that was being collected was very personal. It looked excessive and I was alarmed."

The Ontario Personal Health Information Act specifies that no personal identifiable data be collected and "if you must collect it, you collect the absolute minimum," she said. "It's a fundamental principle in privacy.

"You can ask questions but you don't record it," she said. "You don't need those things."

Toronto - MD launches privacy complaint over new special diet application

An Ontario physician has registered a complaint with the Ontario Information and Privacy Commissioner about a new welfare program that requires social workers to collect detailed health information from social services recipients. Here's the scoop:

Toronto - MD launches privacy complaint over new special diet application

A family physician with St. Michael’s Hospital in Toronto, Dr. Gary Bloch, has filed a complaint with privacy commissioner Ann Cavoukian regarding the new application form for the Special Diet Supplement available to recipients of social assistance.

The new form requires health providers to disclose specific health conditions to social services workers for extra funds to be approved for recipients’ special dietary needs. The supplement has been available for almost a decade, and has always required a health care provider’s assessment in order for the Ministry of Community and Social Services to approve the extra funds. The health provider simply had to state which special diet a client qualified for, and the supplement was approved.

As of November 18, the Ministry amended Ontario Disability Support Program and Ontario Works regulations with a new form which requires health providers to reveal specific health conditions, including such socially charged conditions as HIV, and send this information to social services.

“The new system forces individuals living in poverty to reveal their health conditions to social services workers who have no right to know such information,” said Dr. Bloch. “This constitutes a gross breach of these individuals’ right to privacy. The previous system kept confidential health information where it belonged—between a patient and her health care provider.”

Dr. Philip Berger, chief of the Department of Family and Community Medicine of St. Michael’s Hospital, recalls a similar complaint he filed with Dr. Cavoukian five years ago regarding an application form for recipients of Ontario Disability Support to receive funds for transportation to medical appointments. A negotiated settlement in that case resulted in a change in the form to eliminate the need to reveal confidential health information.

“I can’t believe the Ministry hasn’t learned from its previous mistakes,” Dr. Philip Berger stated. “This looks like another misguided attempt to intrude into the lives of people living in poverty. As a health provider, I am left with an impossible choice: to breach patient confidentiality or to deny my patients their ability to buy food.”

For more information:

Dr. Gary Bloch, (416) 995-7018

Dr. Philip Berger, (416) 867-3712

Janet Maher, (416) 770-1311

[copy of complaint letter attached]

November 22, 2005.

Dr. Ann Cavoukian

Information and Privacy Commissioner of Ontario

2 Bloor St. East, Suite 1400

Toronto, ON M4W 1A8

Dear Dr. Cavoukian:

I am writing to express my concern regarding the privacy implications of the new “Application for Special Diet Allowance and Pregnancy Nutritional Allowance” form implemented by the Ontario Ministry of Community and Social Services this month. I have enclosed a copy of the new form.

My primary concern is that this form requires the disclosure of confidential, private medical information to the Ministry of Community and Social Services. This new requirement will result in social services workers with no direct involvement in an individual’s health care obtaining information about clients’ health conditions. The potential ramifications of this are high, most obviously with a socially charged condition such as HIV, but any unnecessary revealing of a client’s health status constitutes a breach of her or his right to privacy.

The special diet application process has functioned for many years without the need to reveal this information. The process (both old and new) requires an assessment of a client’s eligibility for a special diet by her or his health care provider. There is no additional benefit to client care from a third party’s involvement in this assessment process. In addition, this results in inequitable treatment of individuals already vulnerable due to their poverty.

I feel this new form represents an unnecessary impingement on individuals’ right to privacy. I have attached a letter Dr. Philip Berger, Chief of the Department of Family and Community Medicine at St. Michael’s Hospital, written to you in May, 2000, regarding similar concerns he had about a transportation allowance form for recipients of ODSP. I have also included your commission’s response which outlines the negotiated settlement to address the privacy concerns in that case.

I greatly appreciate your attention to this matter.

Sincerely,

[Original signed by Gary Bloch MD CCFP]

Identity theft and fraud in the healthcare context

Jeff, at HIPAA Blog points to an article on ID theft and fraud in the healthcare context put out by the American Health Information Managment Association. He introduces it thusly:

HIPAA Blog

More on identity theft: Here's an article from AHIMA that supports my constant cry that the big risk of improper use/disclosure of PHI isn't about the 'H' but about the 'P'. Unless you're a professional athlete, nobody cares about your knee surgery. But they do care about your name, address and social security number. There's money in that information.


From the into to the article:

Identity Theft and Fraud-The Impact on HIM Operations (Journal of AHIMA):

Identity theft and fraud are the fastest growing crimes today. Healthcare organizations are particularly vulnerable to identity theft due to the wealth of patient personal, demographic, and financial information that is collected, transmitted, and maintained in the course of operations. Healthcare employees with legitimate access to protected health information (PHI) may gather information for later misuse. Credit cards and identification may be stolen while patients are being treated in healthcare facilities. Individuals posing as investigators may contact patients or providers asking for information that allows them to impersonate the patient or provider.

Morning-after pill privacy concerns raised

The Toronto Star is reporting on a controversy brewing after the Canadian Pharmacists Society has issued guidelines to its members on prescribing Plan B, also known as the "morning after pill". The guidelines call on pharmacists to collect and hold onto personal information from the patient, including information on sexual history. No other over the counter medication requires this and pharmacists are proposing to add a "consultation fee" of $20 on top of the price of the drug.

I have done a lot of looking at privacy practices in Canadian pharmacies and compliance with privacy laws is spotty, at best. If you accept that this information in necessary for the proper dispensing of Plan B, pharmacists will still need to make sure that this consultation takes place in private. Many pharmacies, particularly in the large chains, have built consultation rooms but I have yet to see one actually used while sensitive health information is routinely discussed over the counter within earshot of other customers.

Read the Star article here: TheStar.com - Morning-after pill privacy concerns raised.

Departed US doctor complains his patient list was used for marketing by former employer

The Columbia Tribune is reporting a doctor's allegations that, after he left his hospital practice, his former employer passed his patient list to an external company to market services to them:

Doctor hears from patients who say university broke law
:

"...That's why he decided to leave to start a private practice. King thought he was leaving on good terms with no hard feelings. Then he started hearing from his patients.

King was shocked when he found out what had happened. His former boss, Kevin Dellsperger, chairman of internal medicine, had given a list of about 800 of King's former patients, along with their phone numbers, to a home-health-care provider from Cape Girardeau. A woman from the company had been calling the patients, King says, trying to sell home health-care services, including a $3,000-a-month drug that he says many of the patients didn't need.

'She was making cold calls, asking people about their hepatitis C,' he says. 'Most of the people on the list have hepatitis C. Not all of them do. I got a call from one lady frantic over the phone call. "I don't have hepatitis C," she told me. "What's this all about?" Whoever was making the calls had no way of knowing if these people were sick, if they have cirrhosis, if they're still using. She's just making phone calls to get people on treatment. That is scary.'

It's also, King believes, a clear violation of the recently enacted federal privacy law, the Health Insurance Portability and Accountability Act, or HIPA [sic HIPAA]. The law severely restricts hospitals' and doctors' ability to share private information about patients, including names and phone numbers, without consent from the patient. There are specific rules that guide the use of information for marketing, unless the other medical party already has some relationship to the patient.

What complicates the privacy concern in this case is the nature of hepatitis C patients. Most, King says, are middle-age folks who contracted the disease from youthful indiscretions in the 1960s and '70s. Some got it from blood exposure or bad needles, possibly from drug use, others got it from bad blood transfusions before 1990 when procedures were improved....

Follow-up: Las Vegas hospital responds to article on hospitalized orphan

This is a followup to an earlier posting, in which I linked to a story in the Las Vegas Review Journal. (PIPEDA and Canadian Privacy Law: Read the privacy law before implementing an inhuman policy.) The story in the paper certainly left the impression that the hospital in question did not allow relatives and friends to know that the child was in the hospital. Now, the CEO of the hospital weighs in to give the hospital's position. I'm in no position to judge whose account is correct (I'm leaning toward the hospital, but what do I know?), but readers should take a close read of the CEO's letter:

reviewjournal.com -- Opinion: LETTERS: UMC policies protected, comforted boy:

"To the editor:

I'd like to correct the record concerning your news reports and editorial about the young boy who witnessed the brutal slaying of his mother and became a victim of violence himself while trying to protect her.

As the only Level 1 trauma center in Southern Nevada, University Medical Center had the responsibility of responding to this boy's medical needs as well as his emotional well-being.

The articles and editorial (" `Privacy' law fails brave boy," Nov. 13) suggested that this boy was left alone to deal with his injuries and the emotional turmoil of his loss. I want to assure everyone that this was simply not the case.

It also was suggested that UMC ought to have allowed total strangers to come into the facility to sit with this patient. While grateful for these offers of assistance, I'd like to explain why this was not practical.

First, UMC employs three certified child life specialists who are assigned to respond to the emotional needs of any pediatric patient who requires their services. In this particular situation, a child life specialist was immediately assigned to the patient upon admission to the hospital.

It should also be pointed out that this patient was recovering in a specialized pediatric intensive care unit, where the nursing care is one-on-one for each patient. Therefore, at no time was this child ever left alone or unattended. In fact, I can assure you that we were there to provide comfort and assistance and to hold his hand during a time of immeasurable grief and loss.

Much has been written about the Health Insurance Portability and Accountability Act being the rationale for not publicly disclosing the patient's name and condition. The reality is, even if there were no HIPAA regulations, there have always been patient privacy protocols any hospital would follow. I think we all can agree that hospitals must do all that they can to guard the privacy of their patients and to ensure that their medical information be kept confidential. Additionally, this boy was a witness to a murder, so an extra layer of caution needed to be maintained to protect him.

We take very seriously our slogan, "UMC: The Symbol of Excellence." We believe that in this case, we lived up to that slogan's significance. We saved a life. We cared for a poor child's emotional well-being with personal attention and care. We found a relative who could come sit by his bedside. In this case, as in all cases, our first priority was with the patient. I thought your readers would like to know.

LACY L. THOMAS

LAS VEGAS


The writer is chief executive officer of University Medical Center in Las Vegas. "

Article: Who has your number?

The Halifax Chronicle Herald is carrying an article in today's business section, based on privacy and security concerns dicussed at the McInnes Cooper/National Privacy Services Inc. seminar on privacy and business.

Who has your number?:

"By CLARE MELLOR / Business Reporter

David Fraser pulls a store receipt from his wallet that shows all 16 digits of his debit card number in black and white.

A big no-no due to identity theft concerns, many retailers in Nova Scotia still haven't stopped the practice, said Mr. Fraser, a Halifax lawyer.

'I know some of the largest retailers in Nova Scotia are not protecting customer information,' said Mr. Fraser, an expert in privacy law.

Under the federal Personal Information Protection and Electronic Documents Act, all businesses must take adequate steps to protect against accidental disclosure of customers' personal information. "



Heather Black, the Assistant Privacy Commissioner of Canada, was the keynote speaker at the half-day event, and she shared some very interesting statistics about complaints recently brought to the Office of the Privacy Commissioner:

"Since January, there have been 567 complaints lodged with the federal Office of the Privacy Commissioner in Ottawa about the use and disclosure of personal information, Heather Black, Canada's assistant privacy commissioner, said at the seminar.

Sixty-one complaints were made against retailers, 71 involved insurance companies, 168 complaints involved financial institutions and 102 involved telecommunications companies. Twenty-eight complaints were made against doctors and other health professionals."

Article: Ontario prescribes privacy law for health-care sector (ITBusiness.ca)

Ontario's new privacy law is finally getting some press. ITBusiness.ca, one of the few Canadian publications that has very thorough privacy coverage, is carrying an article on the Personal Health Information Protection Act:

Ontario prescribes privacy law for health-care sector:
11/22/2004 2:20:34 PM - The province introduces rules around patient data and fines for those who don't comply.

"Ontario's law regulating the privacy of health information took effect Nov. 1, and may force organizations that fail to comply to pay up to tens of thousands of dollars in maximum penalties.

In what's being hailed as the province's first privacy law governing a specific industry, the Personal

Health Information Protection Act (PHIPA) will be overseen by the office of the Information and Privacy Commissioner, Ann Cavoukian, and apply to all individuals and organizations involved in the delivery of health-care...."