Privacy Update Recent Updates in Privacy Law



Similar documents
PHIPA Potpourri. Judith Goldstein, Legal Counsel Information and Privacy Commissioner/Ontario. IPC Mediators April 21, 2015

Document Management in the FIPPA Era

Brian Beamish. Commissioner (Acting) Ontario Information and Privacy Commission. Cyber Risk National Conference February 9, 2015

Detecting and Deterring Unauthorized Access to Personal Health Information

The New Face of Privacy in the Courts: Damages, Tort Claims and Class Actions

Recent and Upcoming Privacy Law and Litigation Developments. Alex Cameron Partner, Fasken Martineau IAPP Canada Symposium May 8, 2014

What s New in Access, Privacy and Health Care. Brian Beamish Commissioner. Ontario Connections May 21, 2015

How To Ensure Health Information Is Protected

The potential legal consequences of a personal data breach

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance

Cloud Computing: Legal Risks and Best Practices

PINAL COUNTY POLICY AND PROCEDURE 2.50 ELECTRONIC MAIL AND SCHEDULING SYSTEM

Ann Cavoukian, Ph.D.

Health Information Privacy Refresher Training. March 2013

Insurance Journal. Defending Until the End When Does the Duty to. Volume 1, Issue 3 Editor Keoni Norgren. May 1, 2013

ORDER PO Appeal PA Ontario Securities Commission. June 16, 2015

Mohawk DI-r: Privacy Breach Management Procedure Version 2.0. April 2011

EHR Contributor Agreement

Cloud Computing: Privacy and Other Risks

PERSONAL HEALTH INFORMATION PROTECTION ACT, 2004: AN OVERVIEW FOR HEALTH INFORMATION CUSTODIANS

Privacy and Electronic Communications Regulations

Privacy Management Program Toolkit Health Custodians Personal Health Information Act

Cloudy With a Chance Of Risk Management

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

Helpful Tips. Privacy Breach Guidelines. September 2010

INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013

Corporate ICT & Data Management. Data Protection Policy

Privacy Breach Protocol

Personal Injury Laws

Mandatory Reporting A process

DOCUMENT RETENTION STRATEGIES FOR HEALTHCARE ORGANIZATIONS

Personal Health Information Privacy Policy

Ann Cavoukian, Ph.D.

Procedure for Managing a Privacy Breach

FIPPA and MFIPPA: Bill 8 The Recordkeeping Amendments

CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper

Personal Information Protection and Electronic Documents Act

Health Care Consent Act

South Australia LAW REFORM (CONTRIBUTORY NEGLIGENCE AND APPORTIONMENT OF LIABILITY) ACT 2001

VICTIMS OF CRIME ACT

So the security measures you put in place should seek to ensure that:

Health Care Provider Guide

RECORD AND INFORMATION MANAGEMENT FRAMEWORK FOR ONTARIO SCHOOL BOARDS/AUTHORITIES

THE PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT (PIPEDA) PERSONAL INFORMATION POLICY & PROCEDURE HANDBOOK

Merthyr Tydfil County Borough Council. Data Protection Policy

POLICE RECORD CHECKS IN EMPLOYMENT AND VOLUNTEERING

Report of the Information & Privacy Commissioner/Ontario. Review of the Canadian Institute for Health Information:

Electronic Health Record Privacy Policies

HIPAA/HITECH Compliance Using VMware vcloud Air

Privacy Incident and Breach Management Policy

Bill 34 The New Limitation Act: Significant Changes and Transition Issues Explained

Information and Privacy Commissioner of Ontario. Guidelines for Using Video Surveillance Cameras in Schools

SUBJECT: VOYAGEUR TRANSPORTATION CORPORATE POLICIES/PROCEDURES TITLE: PRIVACY OF PERSONAL HEALTH INFORMATION

Personal Information Protection Act Information Sheet 11

Philip L. Gordon, Esq. Littler Mendelson, P.C.

EMBEDDING PRIVACY INTO ELECTRONIC HEALTH RECORDS. Manuela Di Re Associate Director of Legal Services Information and Privacy Commissioner of Ontario

This procedure is associated with BCIT policy 6700, Freedom of Information and Protection of Privacy.

Practice Tool for Exercising Discretion: Emergency Disclosure of Personal Information by Universities, Colleges and other Educational Institutions

technical factsheet 176

EXAMINATION OF BRITISH COLUMBIA HEALTH AUTHORITY PRIVACY BREACH MANAGEMENT. Elizabeth Denham Information and Privacy Commissioner

The Health Information Protection Act

DATA SECURITY: A CRUCIAL TOPIC FOR CORPORATE COUNSEL AND MANAGEMENT

Civil Law (Wrongs) (Proportionate Liability and Professional Standards) Amendment Act 2004

INDEPENDENT CONTRACTOR AGREEMENT THE UNIVERSITY OF MANITOBA. (the University ) - and - (the Contractor )

Understanding Legal Documents for Guardianship, Powers of Attorney and Estates

Privacy Policy on the Collection, Use, Disclosure and Retention of Personal Health Information and De-Identified Data, 2010

NOTICE OF PRIVACY PRACTICES

OCR Reports on the Enforcement. Learning Objectives 4/1/2013. HIPAA Compliance/Enforcement (As of December 31, 2012) HCCA Compliance Institute

OCR Reports on the Enforcement. Learning Objectives

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

Transcription:

Privacy Update Recent Updates in Privacy Law Kathryn Frelick DISCLAIMER This Coffee Talk presentation is provided as an information service and is not meant to be taken as legal opinion or advice. Please do not act on the information provided in this presentation without seeking specific legal advice. Miller Thomson LLP, 2011 All Rights Reserved. All Intellectual Property Rights including copyright in this presentation are owned by Miller Thomson LLP. This presentation may be reproduced and distributed in its current state. Any other form of reproduction or distribution requires the prior written consent of Miller Thomson LLP which may be requested at healtheditor@millerthomson.com

Privacy Update Recent Developments in Privacy Law Overview 1. Can you be sued for a privacy breach? Privacy class action update and the implications of Ontario s new privacy tort 2. Recent developments under PHIPA and FIPPA 3. Recent cases Freedom of information

Can you be sued for breach of privacy? In Canada, traditionally no independent action for breach of privacy Typically tied to something else (i.e. constructive dismissal, breach of contract, trespass, negligence, breach of fiduciary duty)

Can you be sued for breach of privacy? May be statutory basis (i.e. PHIPA) Increasing concern regarding risk of identity theft (i.e. fraud/credit monitoring, need for protective measures) Significant increase in privacy class actions in Canada Loss/theft of PHI (i.e. Durham Health Region) Business practices / unauthorized access by employee(s) (i.e. recent certification of class action lawsuits against Regional Health Authorities in Newfoundland and Nova Scotia)

Privacy Breach Statutory Basis Limited recourse under PHIPA for breach of privacy Offences under the Provincial Offences Act Significant fines Action for damages for breach of PHIPA Statutory right to seek compensation from Superior Court for breach of privacy for actual harm suffered where order issued by IPC or conviction damages for mental anguish capped at $10,000 (payable where willful or reckless)

Durham Health Region Class Action December 2009 - Nurse loses unencrypted USB key with PHI of 83,500 individuals immunized for H1N1 January 2010 - IPC Order HO-007 strong encryption for mobile storage devices December 2011 - Class action certification motion $40 million damages (negligence, breach of statutory duty, breach of fiduciary duty) Primary concern - identity theft

Durham Health Region Class Action July 2012 class action settlement approved $500,000 in costs to counsel, plus % of claims paid Must demonstrate economic loss, otherwise, no damages Opportunity to mitigate loss Mr. Justice Lauwers: Risks from lost data negligible No evidence of identify theft / minimal information

Class Actions Unauthorized Access Recent class action law suits related to privacy breaches / unauthorized access to EHRs Hospitals notifying patients and managing breach Termination / discipline Early stages Vicarious liability is hospital responsible for intentional behaviour of employee? Systems responsibilities - adequate training, policies and procedures and systems in place to monitor policies?

New Privacy Tort Intrusion upon Seclusion Ontario Court of Appeal - Jones v. Tsige Bank employee accessing personal bank account of spouse s ex-wife (another bank employee) 174 times over 4 year period Brought motion for summary judgment on the basis that Ontario law does not recognize tort of breach of privacy CA determined that there ought to be a right of action for intrusion upon seclusion in certain situations where there has been a deliberate and significant invasion of personal privacy

Three elements - Intrusion upon seclusion Conduct must be intentional (or reckless) Individual must have invaded, without lawful justification, another s private affairs or concerns A reasonable person would regard the invasion as highly offensive causing distress, humiliation or anguish Objectively, only certain types of intrusions highly offensive i.e. involving financial or health information, employment, diary, personal correspondence

Damages for Intrusion Upon Seclusion No need to demonstrate harm to economic interests or actual loss Damages for intrusion upon seclusion will be relatively modest (i.e. capped at $20,000)

Implications for Health Industry Clients Extends beyond PHI to other types of personal information Actions may be contrary to organizational policy (employee discipline), but may still be exposed to potential law suits / class action law suits Significant public relations and legal risk, therefore, when and how individuals are notified is very important ensure strong communication strategy

Implications for Health Industry Clients Risk management Adequate policies and procedures Privacy breach management Training, monitoring and auditing compliance coming under increasing focus Consider risk transfer (i.e. privacy notification and look back programs, identity theft monitoring)

Review Orders/Decisions A review of Orders issued under PHIPA, as well as corresponding fact sheets and guidance documents reveal that many of these repeat the SAME THEMES Failure to use appropriate encryption or other safeguards when storing PHI on mobile devices Limit ability to remove PHI unless adequate safeguards are in place Improper disposal/destruction of PHI Document management and retention policies Contractual protections when relying upon third party

Recent Developments PHIPA and FIPPA PHIPA Order HO 011 October 2011 Cancer Care Ontario in its role as a prescribed person (Ontario Cancer Screening Registry) Delivery of screening reports to over 7000 physicians in paper format (sent by courier)

Recent Developments PHIPA and FIPPA Key findings: Need to evaluate privacy and security standards as they evolve over time Consider whether the use of fax, mail and courier services are adequate given technological advances Put practices in writing IPC Fact Sheet # 18 August 2012 Secure Transfer of Personal Health Information

Recent Developments PHIPA and FIPPA July 2012 - Elections Ontario losing unencrypted USB key involving personal information of up to 2.4 million individuals Failure to effectively implement and monitor privacy practices IPC White Paper - A Policy is Not Enough: It Must be Reflected in Concrete Practices September 2012

Recent Decisions Freedom of Information Carleton University (IPC, Feb. 2012) Presumption that an access request for emails does not require routine search of backup tapes for deleted emails Exception - unless there is a reason to assume that such a search is required If individual requests search from backup tapes, must search and retrieve

Recent Decisions - Advice and Recommendation Ontario Court of Appeal finding that IPC applying advice and recommendation exemption too narrowly Entire deliberative process is protected (not necessary to go to final decision maker) Presentation of range of options may be properly withheld leave to appeal to SCC filed (May 15, 2012) Ontario (Finance) v. Ontario (Information and Privacy Commissioner)

Recent Decisions Third Party Information Supreme Court of Canada decision - Merck Frosst v. Canada (Health) Outlines procedural and substantive protections for third parties Although deals with federal Access to Information Act, likely will apply more broadly No single interest is paramount (i.e. duty to provide access equally important as duty to protect third party information)

Recent Decisions Third Party Information Threshold to trigger notice obligation is low no need to provide notice where information clearly exempt or clearly subject to disclosure, but otherwise, must provide notice While third party assistance may be required, the decision to disclose ultimately lies with institution - head must apply the exemption / conduct thorough analysis Only where third party believes decision is wrong does the onus shift to third party Decision also considers substance of tests and threshold for harms-based exemptions

Questions? Thank you!