I’m Kate Dewhirst.

My team and I write about legal issues affecting healthcare in Canada.

Kate Dewhirst Health Law - bringing the law to life. Meet Kate (in 13 seconds)

Don’t make these 3 mistakes when processing requests for access to health records – New IPC decision 93

Posted by

A patient wants a copy of their health record.

You give them your organization’s form to fill out before you give them a copy.

What are you allowed to ask on that form? If your questions are not all answered, are you allowed to  send back the access request as “incomplete”?

That’s the subject of a new decision of the Information and Privacy Commissioner of Ontario (IPC) – Decision 93.

In Decision 93, a patient of a hospital asked for a copy of their record.  The patient complained to the IPC about the fees charged for processing the request. The fee dispute was settled between the hospital and the patient.

What’s fascinating about this decision, is that the IPC goes on to comment on the hospital’s process of rejecting “incomplete” record requests.

The hospital considered patient requests for copies of their health records to be “incomplete” if the request form was not:

  1. Witnessed
  2. Dated within the last 3 months
  3. Directed to the hospital
  4. Inclusive of what information the individual required (including relevant dates of records)
  5. Inclusive of the purpose for the request
  6. Inclusive of the patient’s name, address, signature, date of birth, health care number and other identifying information
  7. Inclusive of the substitute decision-maker’s name and proof of legal authority (if the request was made by the patient’s substitute decision-maker)

The IPC stated that it was inappropriate for the hospital to reject access requests as incomplete on 3 of those elements:

  1. Witnessed: access requests are not required by law to be witnessed by another person
  2. Dated within the last 3 months: the hospital had not explained why it took the position that every access request signed beyond 3 months prior was automatically suspicious and therefore rejected
  3. Inclusive of the purpose for the request: individuals are not required to explain why they want access to their own records – while healthcare organizations are allowed to ask for the purpose (in order to help understand the request for access), they are not allowed to refuse to process the request if a reason for access is not shared

What questions do your access forms ask?

How do you process access requests?

Do you ever send the forms back as “incomplete”?  If yes, read Decision 93 to better understand your obligations to ensure patients have proper access to their own information.

Want to read about PHIPA privacy decisions of the IPC? Click here to get my free up-to-date Summary of all the IPC’s PHIPA Decisions.


If you enjoyed this article please share it:


Previous and next posts from Kate:

Some of Kate’s recent and upcoming events

Free healthcare privacy webinar - ask me anything!
the first Wednesday of every month

Free webinars - advance registration needed

Whether you're an experienced privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Primary care webinars: Employment Law Update & Legal Issues for EDs and Board members

Part of Kate’s monthly webinar series.

Our 2025 program is now live.
Full details of the 2024 webinar series and registration here.

Mental Health webinars: Legal issues for mental health and addictions agencies and teams
Annual membership 2025

For managers and other leaders from mental health and addictions agencies, hospitals, CMHAs, CHCs, school boards, FHTs and Indigenous health services

This is an annual membership program with monthly webinars.
Full details and registration here.

Health Privacy Officer Foundations training
starts Spring 2025

For Privacy Officers within healthcare organizations.

This course focuses on how to become a more confident privacy officer and gives you the tools to document your privacy program. Full details and registration here...

Join the Shush: a collective of health privacy officers
Annual membership 2024

For Privacy Officers within healthcare organizations

This is an annual membership program that takes theory into practice and tackles real life scenarios to build Privacy Officer skills.
Full details and registration here.

Team Privacy Training Events

For Primary Care clinics, Hospitals, Community Agencies, Mental Health Teams, Public Health Units, School Boards, Police departments

Scheduled to your team's needs for comprehensive or refresher training More details...

Free summary of all PHIPA IPC decisions

Want to read privacy breach stories to learn how to improve your work? We have summarized all the Information and Privacy Commissioner's health privacy decisions for you Download here...

Kate Dewhirst Health Law

Kate says:

My mission is bringing the law to life. I make legal theory understandable, accessible and fun! I’m available and love to work for all organizations in the healthcare sector across Ontario and beyond.

Subscribe to my mailing list and keep up to date with news:

Latest Tweets

  • Our twitter feed is unavailable right now. Follow us on Twitter
  • contact details

    P.O. Box 13024, RPO Bradford Centre
    Bradford, ON, L3Z 2Y5

    (416) 855 9557

    .