Is Jane FIPPA/FOIPPA compliant?
FIPPA/FOIPPA is written for public bodies, not private businesses like Jane, so the compliance obligations in the Act (like handling access requests or PIAs) aren't Jane's to fulfill. But, when we're supporting a BC public body, we have a role to play as a service provider.
Does FIPPA/FOIPPA Apply to My Clinic in BC?
FIPPA/FOIPPA does not apply to most private clinics and practitioners. It applies to public bodies in British Columbia, including hospitals, public universities, school districts, regional health authorities, and provincial ministries.
If you're unsure whether FIPPA/FOIPPA applies to your organization, contact your regulatory body for guidance.
How does FIPPA/FOIPPA apply to my clinic?
Below are a few common principles in FIPPA/FOIPPA that apply to small businesses and clinics.
Public access rights
This principle outlines the rights someone has to access records held about them, including outlining the specific, limited exceptions in which access can be blocked (such as law enforcement involvement or personal privacy). This principle also allows individuals the right to correct records about themselves.
Privacy protection rules
As part of protecting the privacy of individuals, organizations are responsible for:
- Limiting collection to what is allowed by law for specific needs
- Using data only for the purpose it was collected for, unless agreed to by the individual involved or the law allows otherwise
- Implementing strong safeguards to protect against theft or loss
- Ensuring information remains correct and up-to-date
Accountability and oversight
As part of this principle, public bodies ensure responsibility for the data they hold and appropriate management of this data. An independent commissioner maintains oversight to review complaints and decisions and to enforce the law.
How does Jane enable my compliance with FIPPA/FOIPPA?
Jane has safeguards in place to support the protection of patient data, which can be with the safeguards your clinic applies. Jane is built to let you edit information whenever it needs updating.
Privacy Impact Assessments (PIAs) and Risk Assessments
FIPPA/FOIPPA no longer prohibits storing personal information outside Canada, but it doesn't give a free pass either. Before disclosing or storing sensitive personal information outside Canada, a Privacy Impact Assessment (PIA) must be completed, including a supplementary risk assessment specifically covering the foreign storage.
That assessment should address:
- Whether a third-party service provider holds the information, and where and how it's stored
- The likelihood of unauthorized access, use, or disclosure
- The potential impact to individuals if that occurs
- A risk response (technical, contractual, or administrative) proportionate to the risk identified
Data storage in Canada
A key piece to how FIPPA/FOIPPA relate to Jane is the use of features which may store or process data outside of Canada. This includes but is not limited to:
- SMS features
- AI Scribe
In the case of both features, data may be at least temporarily stored or processed outside of Canada, based on our relationship with non-Canadian vendors. BC public bodies have two options for maintaining FIPPA/FOIPPA compliance.
Option 1: Disable either or both features
If your organization requires all patient data to remain in Canada, you'll need to turn off text (SMS) reminders in Jane and avoid use of the AI Scribe feature.
Option 2: Collect patient consent
Under FIPPA/FOIPPA, public bodies are permitted to store and process personal information outside Canada if they have obtained the individual's consent. Instead of disabling these features, you can ask patients to consent to receiving text reminders sent via Jane and Twilio and/or using AI Scribe with their data.
You can build this consent into your existing intake forms. Our guide on Consent Forms walks through how to set that up.
Still have questions?
Have questions about this guide or anything else related to privacy? Email Privacy and Security Support at [email protected].