eHealth Ontario

  • Contact
  • News
  • Français
  • Sign In
    • For health care professionals

    • ConnectingOntario ClinicalViewer
    • cSWO ClinicalConnect
    • ONE Mail Direct
    • ONE ID
    • eHealth Portal
    • DPV
    • ENITS
  • Français
  • Menu
  • Health Care Professionals
    • Digital Health Services

    • Clinical Viewers

      • ConnectingOntario ClinicalViewer
      • cSWO ClinicalConnect
    • Clinical Data

      • Clinical Documents
      • Lab Results
      • Diagnostic Images & Reports
      • Medication Records
    • Access & Identity

      • ONE ID Account
      • ONE ID Federation
      • ONE ID Application Federation
    • Secure Email

      • ONE Mail Direct
      • ONE Mail Partnered
    • Regional Programs

      • Greater Toronto Area
      • South West Ontario
      • Northern & Eastern Region
  • IT Professionals
    • Architecture & Standards

    • Strategy

      • Connectivity Strategy
      • eHealth Blueprint
    • EHR Standards

      • Current
      • Pending Review
      • Trial-for-use
    • Services

      • Innovation Lab
      • Community of Practice
    • Resources

      • Digital Health Asset Inventory
      • FAQs
  • Patients and Families
    • Your Digital Health Record Explained

    • Your EHR

      • Accessing Your EHR
      • Success Stories
    • Your Privacy

      • Managing Access to Your EHR
      • Requesting EHR Access Reports
      • Privacy Questions and Complaints
    • FAQs

      • General Questions
      • Privacy Questions
  • Client Support
    • Client Support

    • Clinical Viewers

      • ConnectingOntario ClinicalViewer
      • cSWO ClinicalConnect
      • eHealth Portal
      • Certified EMRs
      • Drug Profile Viewer
      • Health Report Manager
    • Clinical Data

      • Acute & Community Care Clinical Data Repository
      • Ontario Laboratories Information System
      • Diagnostic Imaging Repositories
      • Digital Health Drug Repository
    • Access & Identity

      • ONE ID
      • Client Registry
      • Provider Registry
      • Identity & Delivery Channel Services
    • Secure Email, Network and Technology Integration (HIAL)

      • ONE Network
      • ONE Mail
      • Health Information Access Layer (HIAL)
  • About Us
    • What We Do

    • About Us

      • What We Do
      • Leadership Team
      • Progress Report
      • Realizing Benefits
    • Privacy

      • Privacy Program
      • Statement of Information Practices
      • Privacy Impact Assessments
      • Freedom of Information Requests
      • FAQs
    • Security

      • Security Program
      • Safeguards
      • Information Security Guides
      • FAQs
    • Disclosure

      • Governance Documents
      • Expenses
      • Salaries
      • Open Data
    • Work With Us

      • Careers
      • Vendor Relations
  • Contact
  • News
  • Sign In
    • For health care professionals

    • ConnectingOntario ClinicalViewer
    • cSWO ClinicalConnect
    • ONE Mail Direct
    • ONE ID
    • eHealth Portal
    • DPV
    • ENITS
  • Health Care Professionals
    • Digital Health Services

      Our suite of digital health services supports the delivery of modern, integrated, patient-centred care.
      Learn More

    • Clinical Viewers

      • ConnectingOntario ClinicalViewer
      • cSWO ClinicalConnect
    • Clinical Data

      • Clinical Documents
      • Lab Results
      • Diagnostic Images & Reports
      • Medication Records
    • Access & Identity

      • ONE ID Account
      • ONE ID Federation
      • ONE ID Application Federation
    • Secure Email

      • ONE Mail Direct
      • ONE Mail Partnered
    • Regional Programs

      • Greater Toronto Area
      • South West Ontario
      • Northern & Eastern Region
  • IT Professionals
    • Architecture & Standards

      What you need to know to plan, design and integrate secure digital health care services, including advice on using consistent standards.
      Learn More

    • Strategy

      • Connectivity Strategy
      • eHealth Blueprint
    • EHR Standards

      • Current
      • Pending Review
      • Trial-for-use
    • Services

      • Innovation Lab
      • Community of Practice
    • Resources

      • Digital Health Asset Inventory
      • FAQs
  • Patients and Families
    • Your Digital Health Record Explained

      Digital records enable a secure lifetime record of your health history, sometimes called an Electronic Health Record (EHR).
      Learn More

    • Your EHR

      • Accessing Your EHR
      • Success Stories
    • Your Privacy

      • Managing Access to Your EHR
      • Requesting EHR Access Reports
      • Privacy Questions and Complaints
    • FAQs

      • General Questions
      • Privacy Questions
  • Client Support
    • Client Support

      Whether you are a new user, an existing client, or an organization looking to connect to our digital health services, the resources you need are available here.
      Learn More

    • Clinical Viewers

      • ConnectingOntario ClinicalViewer
      • cSWO ClinicalConnect
      • eHealth Portal
      • Certified EMRs
      • Drug Profile Viewer
      • Health Report Manager
    • Clinical Data

      • Acute & Community Care Clinical Data Repository
      • Ontario Laboratories Information System
      • Diagnostic Imaging Repositories
      • Digital Health Drug Repository
    • Access & Identity

      • ONE ID
      • Client Registry
      • Provider Registry
      • Identity & Delivery Channel Services
    • Secure Email, Network and Technology Integration (HIAL)

      • ONE Network
      • ONE Mail
      • Health Information Access Layer (HIAL)
  • About Us
    • What We Do

      We’ve built the foundation of an integrated digital health system so that providers can securely share and access patient information.
      View Our Progress

    • About Us

      • What We Do
      • Leadership Team
      • Progress Report
      • Realizing Benefits
    • Privacy

      • Privacy Program
      • Statement of Information Practices
      • Privacy Impact Assessments
      • Freedom of Information Requests
      • FAQs
    • Security

      • Security Program
      • Safeguards
      • Information Security Guides
      • FAQs
    • Disclosure

      • Governance Documents
      • Expenses
      • Salaries
      • Open Data
    • Work With Us

      • Careers
      • Vendor Relations
  • Contact
  • News

eHealth Ontario

Our Privacy Commitment

Personal health information (PHI) is a private matter and an important concern for all Ontarians. eHealth Ontario is leading the way in ensuring seamless integration of privacy processes, practices and policies for all applications of EHRs.


Privacy

  • Privacy Program
  • Statement of Information Practices
  • Privacy Impact Assessments
  • Freedom of Information Requests
  • FAQs
  • Change Category
        • Privacy Program
        • Statement of Information Practices
        • Privacy Impact Assessments
        • Freedom of Information Requests
        • FAQs

Statement of Information Practices

Health Ontario was created in September 2008 as a crown agency with the mandate to

  • provide eHealth Services to support health care in Ontario;
  • develop an eHealth Services strategy; and
  • protect the privacy of individuals whose personal health information may be handled by the agency.

Our Role

Under the Development Corporations Act, Ontario Regulation 43/02, eHealth Ontario was established to provide eHealth Services to promote the delivery of health care services in Ontario that use electronic systems and processes, information technology and communication technology to facilitate electronic availability and exchange of information related to health matters, including personal information and personal health information, by and among patients, health care providers and other permitted users.

Under Ontario Regulation (O. Reg.) 329/04 to the Personal Health Information Protection Act, 2004 (PHIPA), eHealth Ontario provides electronic means to enable health care practitioners to share personal health information with one another for the purpose of providing or assisting in providing health care to individuals. Specifically, eHealth Ontario supports hospitals, clinics and health care practitioners by providing controlled access channels to personal health information and secure infrastructure, hosting, networks, email and related services for secure transmission, processing and storage of personal health information.

Electronic Health Records

Our mandate includes supporting the creation or maintenance of EHRs in Ontario. We are involved in a number of electronic system programs and services including ConnectingOntario, diagnostic imaging common services, Ontario laboratories information system and ONE Mail.

An EHR is a secure electronic record of an individual’s critical health history, such as medications, X-rays and lab results, which can be accessed and shared by authorized health care practitioners (e.g., doctors, nurses and lab technicians). For more information on what is contained in the EHR, refer to EHRs Explained.

Legislative Authority

PHIPA is the provincial statute regulating the management of PHI and the protection of the confidentiality and privacy of that information, while facilitating the effective delivery of health care services.

PHIPA imposes various obligations on health information custodians, such as primary care providers or family physicians, who collect, use and disclose personal health information. eHealth Ontario may act in a number of capacities, as described in PHIPA and O.Reg. 329/04: as an agent to a health information custodian, a health information network provider, or an electronic service provider. In addition, section 6.2 of O.Reg. 329/04 to PHIPA was amended on June 30, 2011 to clarify that eHealth Ontario can create or maintain EHRs as a service for health information custodians. Each role pertains to eHealth Ontario’s relationship to one or more health information custodians. The health information custodians remain fully accountable to the individuals receiving health care and for the privacy practices associated with PHI. eHealth Ontario does not collect, use or disclose personal health information for its own purposes, therefore is not a health information custodian, and does not make any independent decisions with respect to the handling of personal health information. Rather, we comply with the privacy practices of the health information custodians on whose behalf we acts as an agent or provide other services under sections 6.1 and 6.2 of O.Reg 329/04.

Practices and safeguards to protect the confidentiality and security of personal health information

Each initiative we undertake is reviewed to consider broader privacy implications and ensure the appropriate measures are implemented to reduce or eliminate any privacy risk. We have implemented strong administrative, physical and technical safeguards, consistent with industry best practices, to protect the personal health information being transferred, processed or stored from theft, loss, unauthorized use, modification, disclosure, destruction and/or damage. These safeguards include security software and encryption protocols, firewalls, locks and other access controls, privacy impact assessments, staff training and confidentiality agreements. Privacy safeguards include:

  • Appointment of a Chief Privacy Officer
  • Privacy assessments to identify privacy risks performed on all projects and initiatives
  • A comprehensive suite of privacy policies, reviewed at least every two years, which outline our information handling practices
  • All staff completes privacy and security training upon joining and annually thereafter to understand their obligations in their day-to-day work, including undergoing role-based training where there is access to personal information or personal health information
  • Access controls to ensure individuals are granted access for the time and purpose required to perform their role

For more information on the privacy assessments conducted by eHealth Ontario, refer to Privacy Impact Assessments.


Your Privacy Rights

Accessing and correcting your records of personal health information

PHIPA provides you with the right to access your personal health information and, if you believe it is incorrect, inaccurate or out of date, to ask for it to be corrected. Refer to Accessing Your EHR for more information on how to access your information in the EHR or request a correction.

Withdrawing your consent for access to your personal health information in EHRs

If you wish to block or restrict access to your personal health information to any or all health care providers who access EHRs, refer to Managing Access to your EHR.

Contact

If you have questions or concerns regarding our privacy practices, please contact our Chief Privacy Officer:

Laura Davison
Chief Privacy Officer
Privacy Office
eHealth Ontario
P.O. Box 148
Toronto, Ontario
M5B 2E7

Tel: (416) 946-4767
Toll free: 1-888-411-7742 x 64767

416-586-4397 or 1-866-831-0107

privacy@ehealthontario.on.ca


Complaints

You have the right to contact the office of the Information and Privacy Commissioner of Ontario if you have a complaint about eHealth Ontario’s privacy policies and information handling practices. The Commissioner can be reached at:

Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400
Toronto, Ontario
M5G 2C8

Tel: (416) 326-3333
Toll free: 1-800-387-0073

(416) 325-9195

http://www.ipc.on.ca

Contact us for more information about our privacy office, practices and policies.

Get In Touch With Us

Sign Up for our Newsletter

Stay up-to-date with what’s happening at eHealth Ontario by signing up for our newsletter. We’ll keep you informed of eHealth Ontario’s progress and new developments. Rest assured, though we’re constantly making progress, we’ll only send emails periodically, we never share your information, and you can unsubscribe at any time.

    • For health care professionals

    • ConnectingOntario ClinicalViewer
    • cSWO ClinicalConnect
    • ONE Mail Direct
    • ONE ID
    • eHealth Portal
    • DPV
    • ENITS

© Copyright eHealth Ontario 2008 - 2019

  • Privacy Statement
  • Accessibility
  • Acceptable Use Policy

Follow eHealth Ontario

  • eHealth Ontario on LinkedIn
  • eHealth Ontario on YouTube
  • eHealth Ontario RSS Feed

© Copyright eHealth Ontario 2008 - 2019

  • Privacy Statement
  • Accessibility
  • Acceptable Use Policy

Follow eHealth Ontario

  • eHealth Ontario on LinkedIn
  • eHealth Ontario on YouTube
  • eHealth Ontario RSS Feed
Ontario Footer Graphic
Ontario Footer Line Graphic Ontario Logo