I’m Kate Dewhirst.

My team and I write about legal issues affecting healthcare in Canada.

Kate Dewhirst Health Law - bringing the law to life. Meet Kate (in 13 seconds)

Health Privacy Update #2 – August 2017 – Precedent setting new case Decision 49

Posted by

The Information and Privacy Commissioner of Ontario just released two more decisions all health care providers in Ontario should read.

Decision 48: A hospital received a request for access to records. The hospital provided the complainant with a full copy of his health records but the complainant believed there should be additional records (specifically letters from a social worker). The complainant had copies of the letters the social worker had written and wanted confirmation that the hospital had those letters in its records. The social worker had since retired from the hospital. The hospital searched for those records, but could not find them. The IPC required the hospital to provide affidavits explaining the searches performed and steps taken to locate responsive records.  IPC concluded that the hospital had completed a “reasonable search” and was convinced the hospital did not have copies of the social worker letters. The IPC dismissed the complaint.

Bottom Line:  Decision 48 supports previous decisions of the IPC and explains the responsibility to conduct “reasonable searches”.

Decision 49: This one is monumental. For the first time, the IPC has ordered a patient to destroy records using the “recipient” rules under the health privacy legislation.

After a clinical appointment, a patient took a photograph of a physician’s computer screen. The image captured the health information of 71 other patients. The patient was upset that the physician had left the computer unlocked with his and other people’s information on the screen. He wanted to pursue a legal claim against the physician and was threatening to make the image public or share the image with his lawyer in order to file a lawsuit against the physician or both.  Once notified of the photograph, the physician asked the patient to securely destroy it because he was not authorized to have the other patients’ information. The patient refused. The physician notified the 71 patients of the privacy breach. The IPC will review the physician’s practices separately.

IPC concluded that the photograph was a record of personal health information and that the physician had disclosed personal health information to the patient by not protecting the information on the computer screen. The disclosure was not authorized by PHIPA.

IPC found that the patient was a “recipient” of personal health information under PHIPA.  As such, the IPC had the authority to and ordered the patient to destroy the image and all copies because the patient had or intended to contravene PHIPA.  Because the patient had not yet initiated legal action against the physician many months later, the IPC refrained from deciding whether the patient would have been entitled to use the image for the purposes of litigation. The hospital undertook to maintain a copy of the image in case of future litigation.

Bottom Line:  Decision 49 is a bit of a game changer.

First, it is essential that health care providers take care not to allow patients or visitors to collect information from computer screens or other sources. Even if done inadvertently, allowing patients to view other patients’ information constitutes a privacy breach.

Second, this is the first time we see a recipient ordered to destroy health information.  When there has been a breach, one of the first obligations is to contain the breach. One way to contain the breach is to make sure that anyone who received or copied personal health information inappropriately confirms they have destroyed the copy or returned the record.  It is rare to have a recipient refuse to comply with this request. This decision now demonstrates the IPC’s power to compel the destruction of copies of health records in the hands of those who should not have the information.

Here is an updated summary of all 49 IPC PHIPA Decisions


If you enjoyed this article please share it:


Previous and next posts from Kate:

Some of Kate’s recent and upcoming events

Free healthcare privacy webinar - ask me anything!
the first Wednesday of every month

Free webinars - advance registration needed

Whether you're an experienced privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Primary care webinars: Employment Law Update & Legal Issues for EDs and Board members

Part of Kate’s monthly webinar series.

Our 2025 program is now live.
Full details of the 2024 webinar series and registration here.

Mental Health webinars: Legal issues for mental health and addictions agencies and teams
Annual membership 2025

For managers and other leaders from mental health and addictions agencies, hospitals, CMHAs, CHCs, school boards, FHTs and Indigenous health services

This is an annual membership program with monthly webinars.
Full details and registration here.

Health Privacy Officer Foundations training
starts Spring 2025

For Privacy Officers within healthcare organizations.

This course focuses on how to become a more confident privacy officer and gives you the tools to document your privacy program. Full details and registration here...

Join the Shush: a collective of health privacy officers
Annual membership 2024

For Privacy Officers within healthcare organizations

This is an annual membership program that takes theory into practice and tackles real life scenarios to build Privacy Officer skills.
Full details and registration here.

Team Privacy Training Events

For Primary Care clinics, Hospitals, Community Agencies, Mental Health Teams, Public Health Units, School Boards, Police departments

Scheduled to your team's needs for comprehensive or refresher training More details...

Free summary of all PHIPA IPC decisions

Want to read privacy breach stories to learn how to improve your work? We have summarized all the Information and Privacy Commissioner's health privacy decisions for you Download here...

Kate Dewhirst Health Law

Kate says:

My mission is bringing the law to life. I make legal theory understandable, accessible and fun! I’m available and love to work for all organizations in the healthcare sector across Ontario and beyond.

Subscribe to my mailing list and keep up to date with news:

Latest Tweets

  • Our twitter feed is unavailable right now. Follow us on Twitter
  • contact details

    P.O. Box 13024, RPO Bradford Centre
    Bradford, ON, L3Z 2Y5

    (416) 855 9557

    .