Protection des renseignements sur votre santé
Renseignez-vous sur la Loi sur les renseignements médicaux personnels et ses dispositions sur ce que les fournisseurs de services de santé peuvent et ne peuvent pas faire de vos renseignements médicaux.
Elle contient des dispositions strictes sur la confidentialité et la sécurité pour garantir une protection adéquate des renseignements personnels sur la santé des patients.
- Les fournisseurs de soins de santé peuvent uniquement recueillir les renseignements sur les patients nécessaires aux fins de collecte.
- Les fournisseurs de soins de santé doivent collecter, utiliser et transmettre uniquement des renseignements ne permettant pas d’identifier une personne, à moins que ces renseignements personnels ne soient requis.
- En vertu de la Loi sur les renseignements sur la santé, les personnes utilisant des renseignements personnels sur la santé doivent prendre des mesures raisonnables pour assurer la sécurité et la confidentialité des documents.
- Les fournisseurs de soins de santé doivent adopter des normes, des politiques et des procédures qui leur permettront de mettre en œuvre la Loi et de s’y conformer.
- Des dispositifs de protection administratifs, techniques et physiques doivent être instaurés et revus chaque année pour protéger les renseignements des patients.
- Ces fournisseurs de soins de santé doivent également mettre en place des mesures de contrôle d’accès, notamment pour l’accès aux systèmes électroniques d’information sur la santé, en fonction des rôles conférés, pour s’assurer que seuls ceux ayant une raison légitime de consulter les renseignements sur la santé d’une personne peuvent le faire.
- Si des renseignements personnels sur la santé ne sont pas utilisés adéquatement ou sont perdus, ou s’il y a atteinte quelconque à la vie privée, les personnes responsables doivent en informer la personne touchée dans les plus brefs délais.
- Le ministère de la Santé et des Services sociaux ainsi que les administrations des services de santé et des services sociaux sont tenus de procéder à des évaluations des facteurs relatifs à la vie privée s’ils proposent des changements ou en apportent aux systèmes de gestion de l’information et aux technologies de communication. Ces évaluations des facteurs relatifs à la vie privée doivent être communiquées au commissaire à l’information et à la vie privée (CIVP), qui peut les commenter.
- Lorsqu’ils recueillent ou utilisent des renseignements sur une personne, les fournisseurs de soins de santé doivent s’assurer du caractère exact et complet de l’information.
- La Loi sur les renseignements sur la santé exige la conformité à ses dispositions ainsi qu’au règlement, aux politiques et aux normes connexes; des mesures strictes sont prévues pour en garantir l’exécution, notamment sous forme de peines.
Connaissez vos droits en vertu de la Loi.
- Vous avez le droit de savoir exactement comment les renseignements sur votre santé seront recueillis, utilisés et communiqués.
- Vos fournisseurs de soins de santé doivent vous informer des raisons pour lesquelles vos renseignements seront recueillis, utilisés et communiqués, de même que des moyens choisis à cet égard.
- Vous pouvez fixer des limites et des conditions sur la saisie, l’utilisation et la communication de vos renseignements personnels.
- Vous avez le droit de consulter les renseignements sur votre santé et d’en obtenir une copie.
- Vous avez le droit de vous assurer que les renseignements recueillis sont exacts et vous pouvez demander qu’ils soient corrigés au besoin.
- Vous avez le droit de demander un examen au commissaire à l’information et à la protection de la vie privée si vous pensez que la protection des renseignements sur votre santé a été enfreinte ou si vous avez des inquiétudes concernant l’accès à vos renseignements ou une demande de correction déposée.
-
Toute personne a le droit de savoir qui a pu consulter l’information médicale la concernant.
Pour en savoir plus, veuillez discuter avec votre fournisseur de soins de santé ou écrivez à HIA@gov.nt.ca.
Loi sur l’accès à l’information et la protection de la vie privée
La Loi sur l’accès à l’information et la protection de la vie privée vous confère le droit d’accéder aux renseignements détenus par les organismes publics des Territoires du Nord-Ouest. Le ministère de la Justice offre les renseignements suivants sur l’accès à l’information et la protection de la vie privée :
The Health Information Act
The Health Information Act includes tough privacy and security safeguard requirements to ensure patients’ personal health information is properly protected.
- Health care providers may only collect enough patient information necessary for the purpose of the collection.
- Health care providers must collect, use and share unidentifiable information unless identifiable information is necessary.
- Those responsible for maintaining personal health information under the HIA must take reasonable measures to protect the security and confidentiality of records.
- Health care providers must put in place standards, policies and procedures to implement and comply with the HIA.
- Administrative, technical and physical safeguards must be put in place and must be reviewed annually to protect patient information.
- Health care providers must put in place access controls, such as role-based access to electronic health information systems, to ensure only those health care providers who have a legitimate reason to view someone’s personal health information are able to see the information.
- When an individual’s personal health information is not used properly or goes missing, or there is any kind of privacy breach, those responsible must tell the individual as soon as possible.
- The Department of Health and Social Services and Health and Social Services Authorities must do privacy impact assessments when moving forward with new or significant changes to information systems and communication technologies. These privacy impact assessments must be shared with the Information and Privacy Commissioner (IPC), who may comment and provide feedback.
- When collecting a person’s information or using it, health care providers must ensure that this information is accurate and complete.
- The HIA requires compliance with the Act, regulations and any policies and standards adopted, and includes strong enforcement and penalty provisions.
Know your rights under the Act
- Individuals have the right to be fully knowledgeable about how their health information will be collected, used and shared.
- Health care providers are expected to provide notice to individuals on why and how their information may be collected, used, and shared.
- Individuals can set limits and conditions on how their information may be collected, used or shared.
- Individuals have the right to see and get a copy of their health information.
- Individuals have the right to ensure their health information is correct and can ask for a correction if necessary.
- Individuals have the right to request a review by the Information and Privacy Commissioner if they believe their health information has been breached or if they have concerns over an access or correction request made.
- Individuals have the right to find out who has seen their health information.
For more information, please ask your health care provider or email HIA@gov.nt.ca.
Access to Information and Protection of Privacy Act
The Access to Information and Protection of Privacy Act (ATIPP Act) gives you a legal right to request access to information held by Northwest Territories public bodies. The Department of Justice provides the following information on Access to Information and Protection of Privacy:
Notice of Information Collection, Use and Disclosure (Health Information Act)
The Health Information Act (HIA) sets out rules on how personal health information maybe collected, used and shared. As a health service provider identified by the HIA, we are required to notify you, the client, on how your information may be collected, used and shared.
Basic Principles of Collecting, Using and Sharing Personal Health Information
- A client’s personal health information cannot be collected, used, or shared if non-identifiable data will do.
- Health service providers cannot collect, use, or share more client information than is absolutely necessary.
These principles must be applied to all the ways in which we may collect, use, or share your personal health information.
Collection of Personal Health Information
We can collect personal health information if:
- you or your substitute decision-maker consents; or
- we are allowed to collect or have your information shared with us under the HIA or any other law.
Under the HIA, we can collect your information from another person if:
- you consent to another person providing the information;
- the information is collected from a health services provider to provide health services to you;
- we need to collect it this way to get accurate, timely information in a safe way;
- the information is necessary for verifying your eligibility for a health service;
- the information is for a genetic family history related to your health concerns or health services you receive;
- a law requires this; or
- a research ethics committee has allowed the collection from another person.
The only people who can collect or use your health care number are:
- you;
- a health service provider; or
- a person who is permitted by law to collect or use the number (e.g. a correctional facility worker can collect an inmate’s health care card number to provide health services to the inmate while in custody).
Before health service providers collect your personal health information using a recording device, they must tell you that they will be using the device.
Use of Personal Health Information:
We can only use your personal health information if you consent or if we are otherwise allowed or required by law to use it for a particular purpose.
Authorized (secondary) uses of personal health information include:
- the purpose for which it was collected and any related functions necessary to achieve the purpose;
- providing a health service to you;
- verifying eligibility for you to receive a health service;
- internal management purposes including resource allocation, audits, evaluations, quality improvement activities, processing payments, legal, risk and error management services, and professional mentorship training;
- inspecting and investigating a health facility;
- for research, if we get research ethics committee approval;
- to seek your express consent, e.g. passing your information on to an outside or academic researcher;
- to produce non-identifiable statistical data;
- to comply with a law or court order; and
- to perform “data matching”, where we compare one health record in one electronic system with another record in another electronic system to match up the correct Mr. John Smith client with the correct Mr. John Smith medical chart.
The Department of Health and Social Services and the Health and Social Services Authorities can also use your health information for the development of health programs and services, planning and resource allocation, public health surveillance and promotion, and for administration of the HIA.
Disclosure of Personal Health Information:
We can only share your health information if you consent or if we are otherwise allowed or required by law.
Before disclosing information, we must be sure the person receiving the information is who they say they are and is allowed to get the information.
A third party can only use the information for the reason for which we shared the information or for a legal requirement. A third party cannot use more information than is necessary.
We can share your information as follows:
- with you;
- with the Information and Privacy Commissioner when it is necessary so that they can do their job;
- with other health service providers for authorized uses set out in the HIA (see above);
- with the Department of Health and Social Services and Health and Social Services Authorities for authorized uses (e.g. health system planning and management);
- with health service providers providing services to you;
- with a person other than a health care provider, if they need the information to care for you;
- with someone to find you a substitute decision maker, if you are injured or incapacitated;
- limited general diagnosis information to someone in a close personal relationship with you if this is done according to professional best practice and it does not go against a condition set by you;
- personal health information about deceased persons:
- in order to identify the person;
- to inform a relative or a person who was in a close personal relationship with the deceased about the patient’s death and any recent health services received;
- to inform another person, where reasonable, about the circumstances of the death;
- to the personal representative, executor, or spouse to deal with the patient’s estate;
- to a relative to allow that relative to make an informed health decision about them or their child; and
- to a person with custody of a child who is a relative of the deceased to make informed health decisions about the child. This allows for adoptive parents to get information about a child’s biological parent if deceased.
- for verifying your eligibility to receive an insured or non-insured health service or benefit provided by the GNWT or the Federal Government;
- for payment purposes;
- for reimbursing claims;
- for reciprocal billing with other jurisdictions, where necessary;
- with an investigator, adjudicator, complaints officer, or board of inquiry investigating a complaint against a health care provider;
- if we are a party in a legal proceeding;
- to comply with a subpoena or warrant;
- to comply with the rules of court;
- to an appointed litigation guardian or legal representative;
- to an official investigator or inspector;
- to a quality assurance committee set out in accordance with the Evidence Act for a quality assurance activity;
- to the head of a correctional facility to help the facility make decisions about arranging health services for an inmate, housing the inmate in the facility, or discharging the inmate;
- to the head of a mental health facility in which the patient is involuntarily held to help the facility make decisions about arranging health services for the patient or other matters (from accommodation needs to transfer considerations) as necessary;
- to auditors and those providing legal, error management, and risk management services to the health service provider;
- in order for a person considering taking over a health service provider’s practice or business (i.e. private pharmacy) to evaluate the health service provider’s business, subject to a confidentiality agreement;
- with a health provider taking over their business;
- with another health service provider to prevent fraud, limit abuse of health services delivered, or prevent a crime;
- for law enforcement purposes;
- to prevent or reduce an imminent threat or risk of serious harm to someone’s health or safety, or an imminent or serious threat to the public’s safety;
- with medical or mental health experts to consult them about the likelihood of an imminent threat from the above disclosure to a third party or from granting the patient access to their own information;
- with persons to determine if access and correction requests should be granted;
- with the Federal Government, a provincial/territorial government, an Aboriginal government, or a department or agency of these governments, to manage, monitor and evaluate the health system and health programs and services;
- with the NWT Bureau of Statistics and the Canadian Institute of Health Information so they can compile and analyze statistical information that would assist in health system planning carried out by the GNWT and those governments set out above;
- with the Department of Health and Social Services (i.e. system navigator) if a patient makes a complaint;
- with designated electronic health information systems, such as the electronic medical record system;
- with a prescription monitoring program;
- with public health authorities if necessary for a public health purpose; and
- with researchers subject to strict requirements set out in the HIA, particularly approval from a recognized and objective Research Ethics Committee.
Setting Limits on the Use and Disclosure of Personal Health Information
Anytime a health service provider is not required to share your information, you can set limits on how you want your information used and shared, for example, who you want to see or don’t want to see what information can be shared. You can also withdraw your consent at anytime.
We cannot share information with other health service providers if this goes against a condition set by you.
Any conditions have to be set in writing and signed by you.