I’m Kate Dewhirst.

I’m a lawyer who writes about legal issues affecting healthcare in Canada

Kate Dewhirst Health Law - bringing the law to life. Meet Kate (in 13 seconds)

Does your organization need a “back-up” Privacy Officer?

Posted by

Yup – you do!

I have heard from a lot of healthcare teams recently that they have been struggling with vacation, sick days, leaves of absence and unexpected departures from the Privacy Office.  When you rely on one person in your organization to deal with all the privacy issues, you can feel vulnerable when that person is too busy, off or leaves for good.

Here are my 3 tips to managing Privacy Officer back-up:

Tip #1: Have a few people (or at least two people – Privacy Officer and a spare) within the organization who understand the role and responsibilities of a Privacy Officer so you can bridge short and long term absences of your Privacy Officer.  Some health teams I know have a Privacy Committee that address serious privacy breaches. A member of that Committee could be tapped to step in for a Privacy Officer’s vacation or leave of absence.

Tip #2: Document the key components of your privacy compliance program and have a paper or electronic folder explaining how the program runs and where the files, to-do lists, projects, and templates can be found. There is nothing worse for an organization than having an entire “Program” only operating in one staff member’s mind, memory and actions.  While your Privacy Officer may be top notch, your organization is at risk if that person is the only person who knows anything about your organization’s privacy practices, compliance and up-coming obligations.  Every Privacy Program (even for small teams where “Program” seems like a laughable notion) needs to be documented for succession planning and back-up purposes in addition to complying with PHIPA and expectations of the Information and Privacy Commissioner.

Tip #3: Use external resources if needed.  You need to know who to ask for help when your Privacy Officer is away, such as a privacy lawyer or consultant.

Succession planning and back-up planning are essential components to your privacy compliance. Don’t forget to plan for positive absences such as vacations and promotions so that you can also respond to unexpected negative absences such as sickness, long-term disability or departures.

Health Sector Privacy Officer training for your SPARE!

My next Privacy Officer course will be on October 30th.  For more information and to register, click here.  This course is for actual Privacy Officers, but is also perfect for Privacy Officers-in-training or the “spare” Privacy Officer for your healthcare organization.  In this course I will train you how to document your privacy program so that you are set up for compliance and succession planning.

Here are some other resources you might be interested in:

  1. Attend one of my free Ask Me Anything about Health Privacy webinars – the first Wednesday of every month at 10am EDT/EST – if you missed any, they are also available for replay for purchase
  2. Join me for my next Advanced Privacy Officer training on December 10 – for practicing your skills.
  3. If you need advice on how to manage a privacy breach, complaint or query – call me! That’s what I do!
  4. Invite me to do your team privacy training or assist you with privacy policies
  5. Want to read about all the PHIPA privacy decisions of the IPC? Click here to get my free up-to-date summary of all the IPC’s PHIPA Decisions.

Hope to see you soon!


If you enjoyed this article please share it:


Previous and next posts from Kate:

Some of Kate’s recent and upcoming events

Team Privacy Training Events
October 16, October 24 and November 21

For Primary Care clinics, Children’s Aid and FHTs

Kate trains health professionals from many more primary care organizations how being privacy-respectful can improve therapeutic relationships. More details...

Speaking event October 23, 2019

Osgoode Professional Development – Mental health Certificate

Kate joins the faculty for this training event. More details...

Primary care webinars: Managing Incapacity & Consent to Treatment

Part of Kate’s monthly webinar series.

Our October webinar is about managing incapacity, and the November title is Consent to Treatment.
Full details of the 2020 webinar series and registration here.

Advanced Privacy Officer training
December 10, 2019

For experienced Privacy Officers within healthcare organisations.

This one day training course focuses on how to handle difficult privacy situations using real-life (but anonymized) case studies and role-play. Full details and registration here...

Privacy Officer training
January 20 & 27 and February 3,10 & 18, 2020

Kate is the program chair for the Osgoode Certificate in Privacy in Healthcare.

This program explores the range of privacy interests that must be protected in the day-to-day treatment of patients, the development of information systems and the creation of institutional policies. More details...

Free healthcare privacy webinar - ask me anything!
October 2, November 6 and December 4

Free webinars - advance registration needed

Whether you're an experienced privacy officer or new in the field, pick Kate’s brain for free for an hour, in this live webinar. No charge, but you’ll need to register in advance.

Kate Dewhirst Health Law

Kate says:

My mission is bringing the law to life. I make legal theory understandable, accessible and fun! I’m available and love to work for all organizations in the healthcare sector across Ontario and beyond.

Subscribe to my mailing list and keep up to date with news:

Latest Tweets

The main message: A doctor (or any other health information custodian) should never ignore a patient’s access reque… https://t.co/HW8mrFymnC

about 22 hours ago

What happens when someone asks for access to recordings? It depends. Here’s a story about what might happen.… https://t.co/kRnDh5IOo2

12:01 PM Oct 12th

When you have an early warning system you don't hold all those reports until the end of the year. You look for proa… https://t.co/mz22nGp89F

12:01 PM Oct 11th

contact details

901 King Street West Suite 400 East Tower
Toronto Ontario M5V 3H5

(416) 855 9557

.