NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
HR
Slice by Program

No excuses for SickKids, says Ontario privacy chief

By: Lisa Williams, senior writer, InterGovWorld.com(03-08-2007)

Commissioner orders stronger IT data protection

The theft of a laptop from a SickKids physician containing the personal health information of 2,900 patients has resulted in a swift order from Ontario's Information and Privacy Commissioner, Ann Cavoukian.

Cavoukian has ordered the Hospital for Sick Children in Toronto to implement specific protection mechanisms, including the encryption of any personal data that is taken off-site on a laptop or remote computing device.

The incident occurred on January 4 when a physician, who is also a researcher at the hospital, took the laptop home with him to analyze.

However, prior to going home, he parked his minivan in a downtown Toronto parking lot, leaving the laptop under a blanket between the van's front seats. Upon his return he discovered the front passenger window broken and the laptop stolen.

Stored in the stolen laptop was personal health data that included patients' names and information relating to their medical conditions.

Cavoukian did not mince words in her Commissioner's Message contained in the order.

"There is no excuse for unauthorized access to personal health information due to the theft or loss of a mobile computing device - any personal health information contained therein must be encrypted."

Cavoukian emphasized that when personal health information must be stored on portable electronic devices that only the minimum amount of information necessary should be stored, and for the least amount of time necessary.

"At a minimum, files or folders containing personal health information must be encrypted. It is essential to use up-to-date encryption techniques to ensure that personal health information is appropriately secured."

Provisions in health order HO-004 that the commissioner issued today under the Personal Health Information Protection Act (PHIPA) include:

- SickKids must develop and implement a comprehensive corporate policy that prohibits the removal of identifiable personal health information in electronic form from the hospital premises. In the event that personal health information in identifiable form needs to be removed in electronic form, it must be encrypted.

- The hospital must also develop and implement a hospital-wide endpoint electronic devices policy, applicable to both desktop and portable devices (laptops, PDAs), which mandates that any personal health information not stored on secure servers must either be de-identified or encrypted.

Cavoukian's message was not intended only for SickKids, she said. The commissioner is urging all health information custodians to regularly review their security and privacy policies relating to how health information on mobile computing devices is stored.

In a statement released from SickKids, the hospital noted its staff were working in full cooperation with the Information and Privacy Commissioner in an independent review of the incident.

The hospital said it was notifying patients who had participated in 10 different research studies about the stolen laptop.

According to a statement, the laptop was password-protected and SickKids said it was unlikely the data could be easily understood by someone who lacked clinical training.

Notification letters were sent to study participants who were active patients, added the statement. In certain circumstances, patients were notified in person at clinic appointments.

The hospital said it was pleased to be working with Cavoukian on a review of applicable policies and practices to ensure appropriate privacy and security safeguards were in place and that these were clearly and consistently communicated to hospital staff.

Related content:

Privacy watchdogs flag new crime of the century

Health care pros debate interoperability standards

Protect your health privacy

Does technology enabled health care need a reality check?

U.S. lawmakers push for data privacy legislation

Backup data on 365 000 patients stolen from car

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement

2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada