I’m Kate Dewhirst.

I’m a lawyer who writes about legal issues affecting healthcare in Canada

Kate Dewhirst Health Law - bringing the law to life. Meet Kate (in 13 seconds)

Tracking Privacy Breaches in 2018 – Tools and Tips

Posted by

I’ve delivered five team privacy training sessions for health care groups this month all over the province. One thing that has everyone talking is the new requirement to track privacy breaches and report the statistics to the Information and Privacy Commissioner of Ontario in 2019.

Here are some tools and tips to help you better understand this new requirement.

A. What do we have to keep track of?

The IPC explains the requirement here

I wrote an introductory blog about it here

B. How do we keep track?

The Ontario Hospital Association created an AMAZING tool.  It is an Excel spreadsheet and has pre-populated for you all the requirements and has an amazing “instructions” tab. They made it public for free.  Download it here: Annual Breach Reporting Tracking Tool – for 2018  

ANY health information custodian can use it. It’s not unique to hospitals. So if you are a doctor’s office or midwifery clinic or NPLC or pharmacy or mental health clinic or a sole practitioner or any other kind of health information custodian  – the OHA’s tracking tool will work for you too.

Remember: The IPC will have an online form for you to complete. So the OHA Tool is just your tracking tool.  You will need to reenter the total numbers when prompted to do so in February/March 2019 on the IPC’s web portal. Stay tuned. I’ll let you know when it is live.

C. In group practices, who has to report?

This is the million dollar question.  If you are in a group practice, like a Family Health Team or a Family Health Organization or a Nurse Practitioner Led Clinic or a Birth Centre or a multidisciplinary team or partnership – you have to know whether there is a single health information custodian or whether each clinician is individually a custodian.   How do you know?  It should be written down.  If it is not written down – you should get legal advice to determine who is the custodian or custodians.

Every health information custodian is required to track and report privacy breaches.  In group practices where individual clinicians are individual health information custodians – you will have to decide whether to report individually or collectively to the IPC.  If you need help making this decision, let me know.

D. Is this my privacy breach to record? 

What happens if you receive a fax or email that was not meant for you.  Is that your privacy breach to track and report?  No.  It is the sender’s privacy breach.  You should notify the sender that you received the communication in error – but you do not have to add that to your statistical numbers.

Privacy Officer Training: The next round of Privacy Officer training starts in May 2018.  If you want to join me or want to read more about it – click here for information and registration details.


If you enjoyed this article please share it:


Previous and next posts from Kate:

Some of Kate’s recent and upcoming events

Team Privacy Training Events

November 14, 16, 29 & 30 and December 3, 11, 12, 13 & 19

For Primary Care clinics and FHTs

Kate trains health professionals from many more primary care organizations how being privacy-respectful can improve therapeutic relationships. more details...

Building healthy habits

November 26, 2018

Legal coaching at a Toronto law firm.

A private coaching session

Primary care webinar: Shared services agreements

December 6, 2018, 12 noon

Part of Kate’s monthly webinar series.

Pitfalls that primary care organizations need to look out for when agreeing to provide care in collaboration with other healthcare organizations.

Full details of the 2019 webinar series and registration here.

Privacy Officer training

April 30 through June 4, 2019

Kate’s specialist training course for Privacy Officers in health organizations.

Open to all health Privacy Officers, as well as those hoping to become Privacy Officers. Full details and registration for Privacy Officer training next spring here...

Advanced Privacy Officer training

June 18, 2019

For experienced Privacy Officers within healthcare organisations.

This one day training course focuses on how to handle difficult privacy situations using real-life (but anonymized) case studies and role-play. Full details and registration here...

Free healthcare privacy webinar - ask me anything!

December 5, 2018 4-5pm and January 9, 2019 12noon-1pm

Free webinar - advance registration needed

Whether you're an experience privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Kate Dewhirst Health Law

Kate says:

My mission is bringing the law to life. I make legal theory understandable, accessible and fun! I’m available and love to work for all organizations in the healthcare sector across Ontario and beyond.

Subscribe to my mailing list and keep up to date with news:

Latest Tweets

Physician fitness to practice cases challenging for #hospital leaders https://t.co/ZfHLYJDaxR #Credentialing #healthinformation #HealthLaw

about 2 hours ago


TedTalks your health care team can watch about privacy https://t.co/wNozQViSIA #TED #TEDtalks #healthcare #healthprivacy #HealthLaw #legal

about 8 hours ago

contact details

901 King Street West Suite 400 East Tower
Toronto Ontario M5V 3H5

(416) 855 9557