nova scotia

Showing posts with label nova scotia. Show all posts
Showing posts with label nova scotia. Show all posts

Privacy Presentations Galore!

Phew! It has been a busy week. I flew back from Vancouver on Monday and hit the ground running. I gave four presentation this week, all of which are available for download for anyone who is interested.


I think I only have one presentation next week, but it's in Toronto. I'm getting too scared to look at my calendar, these days ...

Article: Who has your number?

The Halifax Chronicle Herald is carrying an article in today's business section, based on privacy and security concerns dicussed at the McInnes Cooper/National Privacy Services Inc. seminar on privacy and business.

Who has your number?:

"By CLARE MELLOR / Business Reporter

David Fraser pulls a store receipt from his wallet that shows all 16 digits of his debit card number in black and white.

A big no-no due to identity theft concerns, many retailers in Nova Scotia still haven't stopped the practice, said Mr. Fraser, a Halifax lawyer.

'I know some of the largest retailers in Nova Scotia are not protecting customer information,' said Mr. Fraser, an expert in privacy law.

Under the federal Personal Information Protection and Electronic Documents Act, all businesses must take adequate steps to protect against accidental disclosure of customers' personal information. "



Heather Black, the Assistant Privacy Commissioner of Canada, was the keynote speaker at the half-day event, and she shared some very interesting statistics about complaints recently brought to the Office of the Privacy Commissioner:

"Since January, there have been 567 complaints lodged with the federal Office of the Privacy Commissioner in Ottawa about the use and disclosure of personal information, Heather Black, Canada's assistant privacy commissioner, said at the seminar.

Sixty-one complaints were made against retailers, 71 involved insurance companies, 168 complaints involved financial institutions and 102 involved telecommunications companies. Twenty-eight complaints were made against doctors and other health professionals."

Canadian Passport Office caught in document mix-up

The Halifax Chronicle Herald is reporting on a mix-up from the Canadian Passport Office that has at least one person upset.

The ChronicleHerald.ca: Passport office passing the buck in document mix-up, woman says

When Alana Hines opened an envelope from Passport Canada recently, it contained more than her newest passport — she also found the complete credit card information, phone number, address and original marriage certificate for a stranger in Ontario.

Ms. Hines was not surprised, because the woman had called her at work earlier to say she received Ms. Hines’s marriage certificate and driver’s licence with her own new passport.

"I had her Visa number and her expiry date. I’m an honest person so I didn’t do anything with it but if it had gotten into the wrong hands, that could have been very serious," said Ms. Hines, of Dutch Settlement, Halifax County.

She called Passport Canada immediately but said the agency wasn’t any help.

"They tried to make excuses, they just said that they’d have to look into it and have somebody call me back. But they told me that I should try and contact (the Ontario woman) and see if she’d send my information back to me, and I didn’t believe that was acceptable, as they’re the ones that messed up."

Ms. Hines, who got married in August, had applied for a new passport Oct. 4 to reflect her married name. The passport arrived correctly but without the accompanying personal documents she had sent along with her application. And the ones she did receive had little in common to possibly explain the mix-up, she said.

...

Darce Fardy of the Nova Scotia Freedom of Information and Protection of Privacy Review Office said the mix-up is unacceptable.

"That is really awful, particularly for a government body."

Mr. Fardy said privacy concerns are becoming a big issue and easy access to personal information can quickly lead to fraud and identity theft.

"Those two people, they obviously knew that there was something wrong with this and that it was a privacy concern."

A Passport Canada spokesman said he was unaware Ms. Hines had not heard from the agency.

"We’re certainly going to recognize that incidents like this do happen but they are very rare,"" Dan Kingsbury said. "Obviously we take this kind of stuff very seriously."

...

Ms. Hines said she just wants to know how the mix-up happened and is disappointed with Passport Canada’s handling of the situation.

"It was like they didn’t care."

What to do if patient information is stolen

Doctors Nova Scotia (formerly the Medical Society of Nova Scotia) this week asked me to write a brief article for their website and magazine about what physicians should do if the security of patient information is compromised. The question arises most often in the form of "what if my computer [or PDA] is stolen?"

I was happy to help since DoctorsNS has been extremely proactive in helping its members to address PIPEDA. In fact, it was for DoctorsNS that I originally wrote the Physician's Privacy Manual (e-mail me - david.fraser at mcinnescooper.com - if you are interested in purchasing a copy).


Q. With the new privacy law now in force, what measures do physicians have to take to prevent the theft of computers and the like containing confidential patient information and what should physicians do if something like this were to happen?



A. Since January 1, 2004, the collection, use and disclosure of personal information by private practice physicians in Nova Scotia has been regulated by the Personal Information Protection and Electronic Documents Act, commonly know by its acronym “PIPEDA”. The law covers all aspects of physicians’ responsibilities with respect to patient information and specifically includes an obligation to safeguard personal information against a wide range of risks. Among those risks are loss, theft and inappropriate access. The law does not dictate what specific technological or security measures must employ but it does provide say that the safeguards must be proportional to the sensitivity of the information in question. Because medical records are among the most sensitive, a physician’s responsibilities in this area are proportionately high.

While PIPEDA is a new law, it does not replace the obligations that physicians have always had to exercise due care to protect their patients from harm caused by the physician’s actions or omissions. The inappropriate disclosure of personal information can undoubtedly cause harm, particularly in this age of identify theft. In addition, individuals entrust their physicians with very sensitive information that may have significant consequences if it is disclosed to others. For example, a patient’s record may contain information about a particular condition that, if disclosed to the individual’s employer, could result in the individual being fired. The inappropriate disclosure of information about a battered spouse may have severe safety repercussions for that patient.

These rules apply to all patient information, regardless of whether it is written on paper or stored in a computer. Use of electronic systems pose additional risks, simply because large amounts of information may be stored in an easily stolen form. Also, external hackers might access an under-protected system, leaving very little sign that the information has been compromised. Physicians should take all reasonable measures to protect this information against the sorts of threats that may exist, depending upon the circumstances. Locks on doors, virus scanners and computer firewalls immediately come to mind. The encryption of electronic data may also be the last line of defence, meaning that data stored on a stolen hard drive still cannot be accessed by a thief who does not have the password.

So what should a physician do if he or she believes that patient information may have been compromised? PIPEDA does not specifically say, unlike Ontario’s new Personal Health Information Protection Act which requires all health information custodians to inform an individual at the first reasonable opportunity if that individual’s personal information is stolen, lost, or accessed by unauthorized persons. While physicians likely should contact all affected patients to inform them of a breach or possible breach, whether they are under a legal obligation to do so is unclear. Because the unauthorized access to personal information may put individual patients at risk, the only way that this risk may be mitigated is to inform the patients so that steps can be taken to minimize the harm. The following checklist may be helpful to assist with a physician who believes that patient information may have been lost, stolen or inappropriately accessed:

  • If the incident relates to a theft or malicious intrusion attempt, the police should be notified as soon as possible.
  • The College of Physicians and Surgeons should be notified.
  • Your liability insurer and/or the Canadian Medical Protective Association should be notified.
  • Immediate steps should be taken to prevent the recurrence of the loss; for example, computer servers should be immediately disconnected from potential avenues for intrusion, such as external networks and modems; locks should be changed on the doors if the incident relates to a physical break-in.
  • Carefully consider whether patients should be contacted to allow them to mitigate the effects of the incident.

Physicians should not attempt to cover up or gloss over any of these incidents, as such actions tend to compound the problem and undermine patient confidence in physicians generally.

If you have any concerns about the way that personal information is safeguarded in your practice, Doctors Nova Scotia is able to help by referring you to information and specialists that can help minimize the risk to the security of your patient information.


I note that this article is not legal advice and only pertains to provinces where private practice physicians are governed solely by the Personal Information Protection and Electronic Documents Act (NS, NL, PE, NB and not BC, AB, SK, MB, QC, ON).

Privacy and Public Libraries

Last week, I gave a presentation to a group of directors of public libraries in Nova Scotia. Library staff are regularly called upon to consider privacy issues, particularly in connection with public use internet stations. Police regularly ask for information related to who was using a particular terminal at a particular time, often in connection with threats made or other allegedely illegal conduct. In addition, some libraries are contemplating offering reading suggestions based on reader preferences, a form of "data mining".

PIPEDA applies in Nova Scotia and public libraries are not, by and large, engaged in commercial activities. While they were interested in PIPEDA, most of the discussion related to privacy best practices they can adopt to meet the growing expectation of their users. The presentation is available here: Privacy and Public Libraries

Canadian Lawyer mentions Canadian blogging lawyers

The October 2004 edition of Canadian Lawyer magazine has a brief feature on Canadian blogging lawyers. It refers to Michael Fitzgibbon's fantastic blog, Thoughts from a management lawyer, Sharon E. Reashore's Elder Law in Nova Scotia and this blog, PIPEDA and Canadian Privacy Law. The article, which discusses the benefits of blogging for lawyers, is only available in the print edition.

Privacy and Insurance Claims

I was recently invited by the Canadian Bar Association - Nova Scotia's Insurance Law subsection to give a presentation on privacy laws and insurance claims, focusing on where we are now that PIPEDA has been in force for almost two years. The two principal themes were video surveillance and access to the claims file. You can download a pdf of the presentation here if you are interested: Privacy and Insurance Claims.

Card skimmer? We don't need no stinking card skimmer.

While card skimming is obviously a problem and a threat (The Canadian Privacy Law Blog: Bank card skimming arrest in Nova Scotia), what many people don't realize is that all that is encoded on your average debit card magnetic strip is the card number. Your card number and your PIN are all that are needed to recreate an exact copy of your card and raid your accounts. Companies that continue to put the full debit card number on receipts are making it easy for anyone who finds that receipt to completely recreate your card. Criminal clerks at stores don't even need to skim your card to rip you off. Their employer helps them do it.

OT: Another Nova Scotia lawyer joins the blogosphere

David Brannon, a personal injury lawyer at Patterson Palmer in Truro, Nova Scotia, has recently started a blog on personal injury matters. He has a background as an occupational therapist, so has an interesting perspective. Check out his blog at www.injurylawblog.com.

Bank card skimming arrest in Nova Scotia

A special Halifax Police/RCMP task force has recently made an arrest in Halifax in connection with a suspected card skimming operation. It is alleged that an employee at a gas station double-swiped customers' bank cards, first in the normal card terminal and then in a card reader, to capture card data. Then, the PIN entry was observed. This information was used to create new cards, which were then used by the fraudsters. Police say the scam may have had up to 400 victims: Latest charges bring total to 85 in bank card scam.

Privacy in the healthcare milieu

On Thursday night, I had the pleasure of giving a presentation alongside Nancy Milford (of the Nova Scotia Health
Organizations Protective Assoc.) to the Nova Scotia Medical-Legal Society on issues related to consent and the release of
patient information. The group is composed of lawyers and medical professionals who have an interest in health law. Almost
all of them had very interesting questions on how PIPEDA is being applied (and should be applied) in the healthcare context.
If you're interested in a copy of the materials, send me an e-mail at david.fraser@mcinnescooper.com.

Liability and Pharmacy Practice

I've been invited to speak on October 30 at the Fall Refresher for the Nova Scotia College of Pharmacists on privacy liability and pharmacy practice. The brochure for the full, two-day event is available here. If you are interested in the presentation materials, e-mail me at david.fraser@mcinnescooper.com.

Training, training, training! Privacy laws can be implemented without going off the deep end ...

It continually drives me bonkers when I read about how some organizations implement privacy laws (see below). Granted, these laws are not always easy to understand, but they usually can be implemented without completely shutting down normal business operations or even normal personal interactions.

A huge part of the problem is that the laws are not very easy to understand, particularly if you sit down a read them from beginning to end. Most laypeople have a hard enough time staying awake during the process and it is rare to actually make it through the law in one sitting. But even if you can manage to make it that far, there in little in the laws themselves to help you in translating theory to practice. (You're not alone: I've dealt with lawyers who have little understanding of the law itself, let alone how it should be implemented. A law degree does not automatically confer an ability to figure it out.)

So what's to be done? People need to be trained about what the law means and how it needs to be integrated into their operations. Front line employees don't need to memorize section 7(3)(c)(ii), but they do need to know how to do their job in this new regulatory environment. They need to know how to meet customer expectations. They need to know how to deal with circumstances where privacy laws may entail a bit more process for their customers. And they need some common sense.

On this front, I have to give full marks to the Nova Scotia Department of Justice, which recently held a series of workshops for department administrators of the Freedom of Information and Protection of Privacy Act throughout the province. And they had the good sense to include a unit on PIPEDA. Though this law doesn't generally apply to the same organizations subject to FOIPOP, it has been a major source of confusion.

CBC Manitoba - Ombudsman slams province over privacy laws:

"Tuckett says there are many cases where public officials do not use common sense in providing people with access to their own personal information.

'I had a call from somebody where they were talking to somebody in a medical doctor's office and asking about the condition of the person and the doctor came up and said, 'You know, you can't talk about your medical condition with other people in our office because it's contrary to PHIA,'' he says.

'I call it 'PHIAnoia' because, you know what it is, it's this, 'I can't share that, I can't do this.' Privacy laws were never intended to be applied so rigidly that all of a sudden you can't have normal human relations with people.'

Tuckett recommends the government should set up a training program to help its employees understand privacy and access laws.
This report will be Tuckett's last as ombudsman; he is retiring as of Feb. 11."

University students and privacy

I get to spend a fair amount of time at Halifax's many universities. One thing that I've noticed is that students appear to be getting younger (and I don't think it's just that I'm getting older!) and university is an extension of high school. It's not just students, though; it's also the parents. Many parents try to keep tabs on their kids and remain very active in their lives to the point of calling professors and administrators, looking for information on what their kids are up to. They don't take kindly to being told that they don't have any right to information without their kid's consent. In Nova Scotia, student information is protected by the Freedom of Information and Protection of Privacy Act. In the US, there's the Family Educational Rights and Privacy Act of 1974.

Today's Daily Mississippian has an article on FERPA, as it's known:

The Daily Mississippian - Privacy laws exist for all UM students:

"Some students when entering college are still pressured by parents who try to control their academic affairs by invading privacy which is a violation of Federal privacy laws.

The privacy of students is a top priority for the university's administration and is protected by federal law, administrators said. Student's academic records are private and can only be released with permission from the student.

"First and foremost, we try to be sensitive to the student's privacy," said Provost Carolyn Staton. "We follow federal laws."

Student privacy is protected under the Family Educational Rights and Privacy Act of 1974. Under this act, a student must give the school permission to release any information deemed private by the act. The only information freely available is directory information, such as dates of enrollment or honors and awards received...."

Nova Scotia government introduces legislation to monitor drug prescribing

The government of Nova Scotia has introduced a bill in the legislature that would allow the Prescription Drug Monitoring Board to have full access to medical records of Nova Scotians and to report suspected illegal prescribing to law enforcement.

Board may soon be able to report suspected abuse of prescription drugs

By AMY SMITH / Provincial Reporter Twelve years after its creation, Nova Scotia's prescription monitoring board could soon have the legal authority to report suspected drug abuse.

"Very often a physician is not aware another physician or two other physicians are writing prescriptions for the same product for that individual," board chairman Patrick King said Tuesday. "The program will now have the teeth to be able to deal with these individuals to the appropriate law enforcement...."



The Minister of Health's press release is available at http://www.gov.ns.ca/news/details.asp?id=20040928002

From Bill 107:

Prescription Monitoring Act:

"18 Upon the request of the Administrator, prescribers, pharmacists or any other body or person shall provide to the Administrator any information, including medical records, the Administrator requires to achieve the objects of the Program.

19 Information received by

(a) the Administrator;

(b) any person employed by the Administrator pursuant to this Act; or

(c) the Board,

shall only be used in accordance with this Act and the regulations and not for any other purpose.

20 Notwithstanding the Freedom of Information and Protection of Privacy Act, the Administrator may release

(a) information with respect to monitored drugs; and

(b) personal information with respect to a resident who has a prescription for monitored drugs,

to a prescriber, a pharmacist, a licensing authority or other body or person to achieve the objects of the Program.

21 Information communicated to the Administrator or the Board by persons employed in the administration of the Health Services and Insurance Act is deemed to be information communicated pursuant to clause 34(a) of the Health Services and Insurance Act.

22 (1) Any data provided to the Minister, the Governor in Council or the public with respect to the Program pursuant to this Act shall be non-nominal data.

(2) Notwithstanding subsection (1), a resident may have access to the resident's own personal information with respect to the Program.

23 (1) Where the Administrator has reasonable grounds to believe that an offence has been committed contrary to the Controlled Drugs and Substances Act (Canada) or the Criminal Code (Canada) or successor legislation, information in the possession of the Administrator in respect of such offence may be communicated to the appropriate law enforcement authority by the Administrator or such person as may be designated by the Administrator.

(2) The Administrator may, at any time, file a complaint with a licensing authority regarding the activities of a member of that licensing authority if the Administrator has reason to believe that the member may be practising in a manner that is inconsistent with the objects of the Program.

(3) Where the Administrator lays a complaint pursuant to subsection (2), the Administrator shall provide the licensing authority with all relevant information on which the complaint is based."



So far, there hasn't been much comment on the privacy aspects of the proposed law.

Legal conflicts for bloggers

Off topic, but ...

This past week, a colleague and I gave a presentation on blogs and blogging to the Halifax Association of Law Librarians. We covered the usual topics, including an overview of some of the good legal blogs out there, RSS, aggregators, etc.

But I also talked about an issue that has been a concern to me since I started this blog but I really haven't heard any discussion of it among the dozens of legal blogs that I follow: conflicts and blogging. Legal ethics say that a lawyer can't reveal the identity of a client or do anything that may be prejudicial to a client, except with the client's consent. See Rule 22 of the Nova Scotia Legal Ethics and Professional Conduct Handbook.

In this blog, I usually post about articles and incidents of interest that have a privacy angle. If I see an article or another blog post that deals with privacy, I'll post a link to it. I hope that this blog is "one stop shopping" for everything of interest related to Canadian privacy law. But it simply can't be. From time to time, a story hits the media that involves a client of my firm. Also, from time to time, I'll get a call from someone in the media asking to comment on a privacy story that involves a client. I always decline to link to the story or to make the comment. Unless I have the client's OK. (Which I've gotten from time to time, particularly if the result of the matter is public knowledge.)

It is a real challenge and something to be very mindful of. I work in a firm with almost 200 lawyers, with six offices in four jurisdictions. We also are Atlantic Canadian counsel to many of the largest companies operating in North America. Our securities group does agency work on behalf of loads of public companies that require registration in Atlantic Canada. If a lawyer in one of our New Brunswick offices does work for the Canadian subsidiary of a huge insurance company, that company is a client and I have to keep my mouth shut. Even if it may be borderline or in a grey area, I have to err on the side of caution.

I would be very interested to hear the thoughts of other legal bloggers out there on this topic. I think this is an important topic that could bear some informed discussion.




UPDATE:

I solicited Alan Gahtan's thoughts on this subject, which he has posted on Gahtan's Technology and Internet Law Blog:

"My view is that lawyers who publish, whether through a blog or through more traditional print media, operate under a disability. They must not disclose client confidences and must not advocate a position that is contrary to their client’s interests. The magnitude of the disability is proportionate to the size of the firm that a particular lawyer practices with since conflicts are “shared” among the lawyers of a firm. It is less of a problem when the lawyer’s publishing activities involve ad hoc articles as opposed to the operation of a website or blog that tries to cover all developments in a particular area. I’m not a legal ethics expert but my view is that simply reporting other information that is already public should not create a legal conflict (although I can see that it could create a business conflict with a particular client). However, it does mean that the blogging lawyer will be limited in their ability to comment on a particular news item if such comment would be detrimental to the interest of a client of the firm. It likely also means that any third party comments will also need to be filtered so that they do not contain any content that is detrimental to any such client. "


I like the use of the term that we lawyers are blogging "under a disability." Our hands our tied and our lips are always sealed, but this isn't unique to the blogging environment. Lawyers always have very juicy gossip but have to keep their mouths closed at cocktail parties. Blogging lawyers also have to be mindful not to aliente present and prospective clients with their blog content. I try to be as even-handed and balanced as possible, with the minimum of personal and political opinion (which is distinct from professional opinion).

There have been a number of times when I've had to remain silent when clients have appeared in the news, even though I have no immediate knowledge of the incident (for example, if its US branch is in the news). There have also been cases when the clients have had positive privacy-related publicity, but it is not my place to speak for or about them without permission. But when it does not inovolve a client, I think I am free to link to public information even though my firm has clients in the same industry with similar business issues.

Thanks Alan, Rob, David and DP Thinker for the comments, above and below.

Technorati tags: legal ethics :: blogging :: blogs :: lawyers :: legal profession

UK patients can opt-out from electronic health records

I'm aware of a number of government-sponsored electronic health records programs, from Nova Scotia to Alberta and further afield. The one being planned and implemented in the United Kingdom is the first that I know of that will allow individuals to choose to not be included:

Guardian Unlimited | The Guardian | Patients can stay off NHS database:

"NHS patients are to be asked whether they want intimate details of their personal medical history to be included in a new national electronic database that can be accessed by GPs, paramedics and hospital staff throughout England.

Those worried the information could be abused will be entitled to have it removed from the system or placed in an electronic 'sealed envelope', to be opened only in a dire emergency, John Hutton, the health minister, said yesterday.

However, patients restricting access to their records in this way ran the risk of clinical staff making mistakes in an emergency through lack of relevant information about previous medical conditions or allergic reactions. "

Conviction in Nova Scotia card skimming case

Crown prosecutors in Nova Scotia have secured the conviction of Eugeniu Micolai Moldovan on 77 counts of fraud, stemming from a scam in which Moldovan and an accomplice placed a card skimmer and PIN reader on automated ticketing machines at a local movie megaplex. The accomplice previously pleaded guilty.

Credit for catching the scammers goes to a vigilant bank employee who noted a pattern of fraud and tipped off the Halifax police that the scammer would likely be at a particular movie theatre on a particular date. I wish I knew which bank or who the employee is to give proper credit.

The scammer used a card reader and a pin-pad overlay to catch both the mag stripe info and the customer's PIN. The hardware used was pretty good and users couldn't tell it was there.


Moldovan will be sentenced on February 16 and the Crown Prosecutor said he'd be seeking a lengthy sentence.

See: The ChronicleHerald.ca

Technorati tags: Privacy ::
Card Skimming ::
Fraud ::
Credit Card ::
Credit Card Fraud ::
Debit Card ::
Debit Card Fraud ::
Nova Scotia

Nova Scotia Auditor General concerned about effect of USA Patriot Act on citizen privacy

The Nova Scotia Auditor General released his report for 2005 in December. The fourth chapter is entitled Electronic Information Security and Privacy Protection.

In his report, he reviews the privacy and information security practices of a number of departments, including Justice and Community Services. He also touches upon the USA Patriot Act and its possible impact on the personal information of Nova Scotians. Data processing and information storage services for the province are provided by wholly-owned subsidiaries of American companies, which are undoubtedly subject to American laws. The province has carried out a study of the situation, but refused to provide it to the Auditor General, citing solicitor-client and cabinet privilege. In an interview by the Canadian Press, the provincial Minister of Justice hinted that Nova Scotia will be introducing a law in the spring sitting of the Legislature to mirror that passed by British Columbia to better protect personal information from being disclosed to foreign law enforcement.

Read the CP article here: N.S. auditor concerned citizens information could be leaked to U.S. agencies - Yahoo! News.

Technorati tags: privacy ::
Patriot Act ::
Nova Scotia ::
privacy law.

Nova Scotia FOIPOP Review Officer to form Right to Know coalition upon retirement

As reported here on Saturday (The Canadian Privacy Law Blog: Nova Scotia's FOIPOP Review Officer to step down), Nova Scotia's Freedom of Information and Protection of Privacy Review Officer will be stepping down from his post on January 23, 2006 when his term concludes. Today's Halifax Chronicle Herald reports on the retirement and mentions that Darce will not be disappearing into the sunset. He is planning to start a "Right to Know" coalition to educate people about access to information laws and to lobby for greater openness. See: Freedom of information protector leaving his post:
Fardy plans to start citizens coalition called Right to Know

Technorati tags: :: ::
.