I’m Kate Dewhirst.

I’m a lawyer who writes about legal issues affecting healthcare in Canada

Kate Dewhirst Health Law - bringing the law to life. Meet Kate (in 13 seconds)

Health Privacy Update #2 – August 2017 – Precedent setting new case Decision 49

Posted by

The Information and Privacy Commissioner of Ontario just released two more decisions all health care providers in Ontario should read.

Decision 48: A hospital received a request for access to records. The hospital provided the complainant with a full copy of his health records but the complainant believed there should be additional records (specifically letters from a social worker). The complainant had copies of the letters the social worker had written and wanted confirmation that the hospital had those letters in its records. The social worker had since retired from the hospital. The hospital searched for those records, but could not find them. The IPC required the hospital to provide affidavits explaining the searches performed and steps taken to locate responsive records.  IPC concluded that the hospital had completed a “reasonable search” and was convinced the hospital did not have copies of the social worker letters. The IPC dismissed the complaint.

Bottom Line:  Decision 48 supports previous decisions of the IPC and explains the responsibility to conduct “reasonable searches”.

Decision 49: This one is monumental. For the first time, the IPC has ordered a patient to destroy records using the “recipient” rules under the health privacy legislation.

After a clinical appointment, a patient took a photograph of a physician’s computer screen. The image captured the health information of 71 other patients. The patient was upset that the physician had left the computer unlocked with his and other people’s information on the screen. He wanted to pursue a legal claim against the physician and was threatening to make the image public or share the image with his lawyer in order to file a lawsuit against the physician or both.  Once notified of the photograph, the physician asked the patient to securely destroy it because he was not authorized to have the other patients’ information. The patient refused. The physician notified the 71 patients of the privacy breach. The IPC will review the physician’s practices separately.

IPC concluded that the photograph was a record of personal health information and that the physician had disclosed personal health information to the patient by not protecting the information on the computer screen. The disclosure was not authorized by PHIPA.

IPC found that the patient was a “recipient” of personal health information under PHIPA.  As such, the IPC had the authority to and ordered the patient to destroy the image and all copies because the patient had or intended to contravene PHIPA.  Because the patient had not yet initiated legal action against the physician many months later, the IPC refrained from deciding whether the patient would have been entitled to use the image for the purposes of litigation. The hospital undertook to maintain a copy of the image in case of future litigation.

Bottom Line:  Decision 49 is a bit of a game changer.

First, it is essential that health care providers take care not to allow patients or visitors to collect information from computer screens or other sources. Even if done inadvertently, allowing patients to view other patients’ information constitutes a privacy breach.

Second, this is the first time we see a recipient ordered to destroy health information.  When there has been a breach, one of the first obligations is to contain the breach. One way to contain the breach is to make sure that anyone who received or copied personal health information inappropriately confirms they have destroyed the copy or returned the record.  It is rare to have a recipient refuse to comply with this request. This decision now demonstrates the IPC’s power to compel the destruction of copies of health records in the hands of those who should not have the information.

Here is an updated summary of all 49 IPC PHIPA Decisions


If you enjoyed this article please share it:


Previous and next posts from Kate:

Some of Kate’s recent and upcoming events

Health Privacy Officer training
September 22, 2020

For Privacy Officers within healthcare organizations - now totally online.

This course focuses on how to become a more confident privacy officer and gives you the tools to document your privacy program. Full details and registration here...

Primary care webinars: Employment Law Update & Legal Issues for EDs and Board members

Part of Kate’s monthly webinar series.

Our September program is on privacy litigation and the October program will address harassment issues and scenarios.
Full details of the 2020 webinar series and registration here.

Free healthcare privacy webinar - ask me anything!
the first Wednesday of every month (Off for the Summer - next up: September 2 and October 7)

Free webinars - advance registration needed

Whether you're an experienced privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Free Part X CYFSA privacy webinar - ask me anything!
the second Wednesday of every month (next up: July 8 and August 12)

Free webinars - advance registration needed

Whether you're an experienced privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Team Privacy Training Events
July 8, 23, 28 August 4, October 7, 8

For Primary Care clinics, Hospitals, Community Agencies and Children’s Aid

Kate trains health professionals from many more health care organizations how being privacy-respectful can improve therapeutic relationships. More details...

Kate Dewhirst Health Law

Kate says:

My mission is bringing the law to life. I make legal theory understandable, accessible and fun! I’m available and love to work for all organizations in the healthcare sector across Ontario and beyond.

Subscribe to my mailing list and keep up to date with news:

Latest Tweets

[SEPT 3] Learn about the latest cases in privacy so you can better understand your privacy risks Register now - web… https://t.co/EGRJXI9BYs

09:05 AM Jul 8th


contact details

P.O. Box 97010 Roncesvalles
Toronto Ontario M6R 3B3

(416) 855 9557

.