0% found this document useful (0 votes)
2 views6 pages

Definitions

The document provides definitions related to privacy and data management in healthcare, including terms like Access, Authentication, and Circle of Care. It outlines the responsibilities of healthcare providers regarding personal health information, consent, and confidentiality. Additionally, it discusses various legislative frameworks and tools designed to protect patient privacy and ensure compliance with privacy standards.

Uploaded by

okgulabjamun
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views6 pages

Definitions

The document provides definitions related to privacy and data management in healthcare, including terms like Access, Authentication, and Circle of Care. It outlines the responsibilities of healthcare providers regarding personal health information, consent, and confidentiality. Additionally, it discusses various legislative frameworks and tools designed to protect patient privacy and ensure compliance with privacy standards.

Uploaded by

okgulabjamun
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Definitions

Access
The process of viewing and/or obtaining data and/or personal information.

Application Service Provider (ASP)


A company that manages and stores the Electronic Medical Record (EMR) at its data centre,
rather than the physician managing and running servers in his or her own office. The EMR is
then accessed over the Internet or preferably over a private network.

Authentication
A method designed to allow a computer application to provide credentials—usually in the form
of a user name and password.

Canadian Medical Association (CMA) Privacy Wizard


An online tool developed by the CMA and all the provincial medical associations that helps
physicians ensure they have met key privacy requirements.

Circle of Care
A principle that recognizes and understands the practicality of the need for implied consent for
relevant information to flow from one health care provider to another in order to ensure the best
level of patient care, unless the health care provider who provides the information is aware that
the individual has expressly withheld or withdrawn consent. This is an evolving concept that
recognizes the unique challenges for obtaining informational consent in the health care
environment.

The definitions around the circle of care relate to the care and treatment of the patient and
health care services for the therapeutic benefit of the patient. This includes diagnostic
information and professional case consultation with other health care providers. The health care
providers within the circle of care should be obvious to the patient and reflect common
practices.

Collection
The gathering, acquisition, receipt, or obtaining of personal information.

Confidentiality
The ethical principle or legal right that a physician or other health professional will hold secret all
information relating to a patient, unless the patient gives consent permitting disclosure.

Consent
See Implied Consent and Expressed Consent.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 1
th
Last updated on June 15 , 2009
Data Stewardship
The management of personal health information including the collection, use, access, disclosure
and retention, and the legal, ethical, and fiduciary responsibilities of a physician in such
management.

Disclosure
Making information available to another organization or third party, or to the individual the
information is about.

Disclosure Directives
An individual's ability to control when and by whom his or her personal health information will be
accessed.

e-Health Act
Legislation that was introduced in 2008 to provide a privacy framework for governing personal
information in databanks designated by the Minister of Health as Health Information Banks
(HIBs). Also known as the Personal Health Information Access and Protection of Privacy Act, or
Bill 24.

Electronic
A format of data storage that includes digital, voice, video, etc.

Electronic Health Record (EHR)


In BC, an electronic record that is patient-centric and contains information from a broad range of
health providers. It generally contains a subset of sharable information including cumulative
patient profiles with current prescriptions, allergies, and immunization history. It may have
integrated information related to in-patient and out-patient encounters with the health care
system. Information in the EHR is not always accessed with each patient encounter, but is used
when additional information is required during a patient visit. Laboratory, diagnostic imaging
results, and other reports are also found in the EHR but are not necessarily delivered to a
specific provider for review (e.g., information is reviewed on the part of the provider at the time
the information is required).

Electronic Medical Record (EMR)


In BC, a medical record that is in a digital format and is provider-centric. It focuses on medical or
physician-specific information and is configured to reflect the needs of individual physicians or
groups of physicians responsible for the direct care of a patient.

Electronic Medical Record (EMR) vendor


A company that sells and supports Electronic Medical Record (EMR) software.

Encryption
The conversion of data into an electronic form that cannot be easily understood by unauthorized
users.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 2
th
Last updated on June 15 , 2009
Expressed Consent
Consent signified by the willing agreement of an individual for the collection, use, and disclosure
of personal information for a defined purpose (opt-in model). The consent can be given verbally
or in writing. (See also Implied Consent.)

Freedom of Information and Protection of Privacy Act (FIPPA)


BC legislation that governs personal information collected, used, and disclosed by public bodies
including Health Authorities and the Ministry of Health Services.

Handheld Device
Any mobile handheld device that provides computing and information storage and retrieval
capabilities for personal or business use (e.g., Blackberry). Such devices are frequently used to
maintain an electronic schedule or contact information.

Health Information Bank (HIB)


In general, an electronic database that allows consumers of health services to collect, store,
control, and share health information with members in their circle of care. In BC, since the e-
Health Act came into effect into 2008, organizations have to apply to be certified as an HIB and
are subject to a number of legislated expectations.

Implied Consent
Consent signified by the acceptance by a reasonable individual for the collection, use, and
disclosure of information for an obvious purpose where it is understood that the individual will
indicate if he or she does not accept (opt-out model). For implied consent to be meaningful, the
individual has to know that he or she has the right to expressly withhold or withdraw consent at
any time without fear of retribution. (See also Expressed Consent.)

Individual
The person/patient about whom information is collected. This includes persons who are
authorized to exercise rights on behalf of an individual/patient (e.g., parents on behalf of a child;
guardian or trustee; personal representative).

Information-Sharing Agreement (ISA)


A formal agreement between organizations and other persons or bodies acting on behalf of the
organization that define specific uses and disclosures for shared data. The agreement should
include who is permitted to access the data, disclosures for which the data will be used, and
conditions and limitations on the collection, use, disclosure of the information.

Masking
The application of rules that restrict access to data in an electronic record, unless additional
action is taken to override the restriction. This is differentiated from “blocking,” which is an
application of access restriction where the existence of the data is not presented. Masking can
be applied at different levels depending on the unique circumstance and system capabilities.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 3
th
Last updated on June 15 , 2009
Need to know principle
Access to personal information based on a legitimate relationship with the patient and a need to
access or use the personal information for the execution of one’s duties.

Personal Health Information


Information about an individual that identifies the individual and the individual’s health history
including physical or mental health; the provision of health services that individual; the
registration of the individual for the provision of health services; payments or eligibility for health
care; and any information collected in the course of the provision of health services to the
individual.

Personal Information
Information, including personal health information, about an identifiable individual which
includes factual or subjective information about that individual. This information includes, but is
not limited to, name, birth date, physical description, medical history, gender, address,
education, employment, and visual images such as photographs or videotapes.

Personal Information Protection Act (PIPA)


BC legislation that governs personal information collected, used, and disclosed by all private
sector organizations, including physicians’ private practices and other private health care
facilities.

Personal Information Protection and Electronic Documents Act (PIPEDA)


The federal legislation that governs the collection, use, and disclosure of personal information
by federally regulated private sector organizations.

Privacy
The right to be free from intrusion and interruption. It is linked with other fundamental rights such
as freedom and personal autonomy. In relation to information, privacy involves the right of
individuals to determine when, how, and to what extent they share information about
themselves with others.

Privacy Breach
Unauthorized access to, or the collection, use, disclosure, retention, or destruction of personal
health information.

Privacy Impact Assessment (PIA)


A foundation tool/process within FIPPA designed to ensure public organizations’ compliance
with privacy protection legislation. Can also refer to a structured process of assessing the
privacy and security aspects of a given process or project.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 4
th
Last updated on June 15 , 2009
Privacy Officer
The individual designated with the accountability to ensure organizational compliance with
privacy legislation, industry standards, and professional and regulatory obligations. The Privacy
Officer is responsible for policy development, compliance monitoring, privacy breach
management, staff training, and managing complaints, questions and access to personal
information requests. In a medical practice, it is recommended that the Privacy Officer be a
physician. This means that if the office is a solo practice, the solo physician is the de facto Privacy
Officer. In a group practice, one of the physicians must be identified as being responsible for this function.

Private Network
A secure, private, end-to-end network (patient data does not travel over the Internet) that allows
secure, high-speed access to an EMR or an EHR, secure Internet access, and secure email
messaging.

Private Physician Network (PPN)


A secure, private, end-to-end network (patient data does not travel over the Internet) provided
by the BC government to BC physicians to enable greater security and rapidity for the PITO
ASP based EMRs. The PPN allows secure, high-speed access to the PITO EMRs and secure
email messaging.

Reasonableness of Security Measures


As described in a 2006 report of the BC Information and Privacy Commissioner, “the measure
by which security measures are objectively diligent and prudent in the circumstance.” The report
also stated that “what is ‘reasonable’ may signify a very high level of rigour depending on the
situation.”

Remote Access
The ability to get access to a computer or network from a remote distance. Individuals who are
travelling or working from home may need access to information, and may access the network
and systems remotely.

Roles-Based Access
A policy and technical architecture involving the assignment of access privileges to roles rather
than to individual users. Users are granted privileges by virtue of being authorized to act in
specific roles.

Security
The preservation of the confidentiality, integrity, and availability of personal information. It is
achieved by implementing policies and procedures based on relevant legislation, industry
standards, design and implementation of appropriate technology solutions, and managing
ongoing operations relating to access to personal information.

Third Party
In the context of sharing personal information, any person, group of persons, or organization
other than the person or organization who directly collected the personal information.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 5
th
Last updated on June 15 , 2009
Staff
For the purposes of this document, locum physicians, associates, visiting specialists, medical
students, residents, physicians-in-training, contractors, and volunteers with whom you collect,
use, or disclose personal information.

Strong Password
A password that is sufficiently long, random, or otherwise producible only by the user who
creates it. It is case sensitive and includes a random combination of alphanumerics and
symbols. The College recommends that a strong password should be eight or more characters
in length and contain at least one number, one letter, and one symbol (e.g., Brown#123).

Two Factor Authentication


The combination of user name/password and some other physical identification tool (e.g.,
secure ID token in order to verify the identity of a person).

Use
The application of information for a specific purpose by the person or organization that collected
the information.

USB Memory Key


A compact data storage device that is typically removable and rewriteable. The most common
use of USB memory keys are to transport and store files such as documents, pictures, and
videos.

Virtual Private Network (VPN)


An authentication and encryption mechanism that allows connection from outside the
physician’s office to the EMR over the Internet with enhanced security.

Wireless
The transfer of information over a distance without the use of electrical conductors or wires.

Please see warning and disclaimer on page 2 of the whole BC Physician Privacy Toolkit 6
th
Last updated on June 15 , 2009

You might also like