6 ms·
"In this hypothetical it is not a privacy violation under ... PHIPA (Ontario, Canada) as consent would not be required." That is not categorically true, PHIPA
by JamisonM 3y ago
"In this hypothetical it is not a privacy violation under ... PHIPA (Ontario, Canada) as consent would not be required."
That is not categorically true, PHIPA requires research ethics board to review research disclosures to determine if consent is required. So what is "too much" information that might violate privacy under Ontario law is a moving target, as our ability to violate privacy with less and less information progresses the standard should be more and more restrictive.
Research use of course does not mean that the data needs to be public, as in my example, and raw data is often not made public. In your example it was, if that same database were created today I am confident the ethics board enlisted to review the disclosure would disallow it.
- haldujai 3y agoUnder PHIPA you can essentially use PHI for: direct patient care, research, or quality improvement. All QI does not need patient consent. Most research also does not need patient consent. Research requires REB approval. Institutional policy usually requires a REB to determine that the proposed initiative is not research but this varies. It is trivial to get QI approved. The act of deidentification is considered a "use" and therefore would require an REB approval or be structured as QI. However, once deidentified the data is no longer protected under PHIPA and can be used for anything. There is some nuance to this, such as you can't have a planned use of the deidentified data and not have disclosed it in the initial QI or research plan, but you can subsequently use the data as long as it was not planned at the time of initial application. Without getting lost in the weeds, there is little protection on deidentified data once it exists.
- JamisonM 3y ago> Without getting lost in the weeds, there is little protection on deidentified data once it exists. That's what I said I think.. the law is about making it exist and the standard for being allowed to make it is dictated by the REB - so that's a moving target, you can't say specifically what would be allowed today will be allowed 5 years from now.
- haldujai 3y agoApologies, I may have misunderstood you to extend it to deidentified data. There are easier non-REB exceptions to consent that can facilitate deidentification and subsequent use that are commonly used: PHIPA sets out a limited set of acceptable uses of personal health information without consent, including, for example, the following purposes: • planning or delivering programs or services • risk management, error management or activities to improve or maintain the quality of care or any related program or service • educating agents to provide health care
- JamisonM 3y agoThese are "uses" of data but they don't seem to in any way involve making the data public - I think if you published deidentified data to a public forum of any kind under the auspice of "educating agents" you'd get a very big fine! (You need example charts to educate certain healthcare workers, using real ones with the name blanked out is fine - publishing that on the Internet probably going to get you a violation.) These are just standard legislative exceptions saying "you can use the data you have to run the operation without fear of getting in trouble" not publication rules. ETA: You obviously know about the legislation, if you know of instances of orgs using these rules to publish data.. blow that damn whistle!
- haldujai 3y agoThere is no protection against the use and disclosure of deidentified health information as regulated by PHIPA or the IPC of Ontario. The IPC has clarified through guidance that deid data is not protected however the act of deid constitutes “use” and therefore must be through an approved means. These scenarios are approved exceptions to patient consent for use. Some institutions and systems have internal policies that add exceed PHIPA. For example ConnectingOntario which is the closest thing to a provincial EMR only allows access for direct patient care (i.e. not even REB approved research). Some academic hospitals also add approval requirements for the disclosure of deid data to other institutions or on credentialed access repositories. I started my medical career in Ontario and this is done all the time for things like publishing case reports, online (or non-institutional) lectures and case banks (e.g. on the publicly accessible Radiopaedia). Not sure what you mean by whistleblowing, this is completely legal in both Ontario and the US and in my opinion entirely ethical (for the most part). I’m not saying it’s a good idea or ethical to use these exceptions to consent for posting marketing materials on TikTok. The CPSO which regulates physicians may still find the action unprofessional/unethical for reasons not related to violating the law, but their standard is different (“behavior unbecoming of the profession” and “behavior that degrades patient trust in the practice of physicians”). On a side note I think I’m getting old but what does “ETA” mean (other than estimated time to arrival)?