This guide is a general summary and is not intended as legal advice. For guidance specific to your practice, consult a legal professional or your regulatory body.
Is Jane PIPA compliant?
Yes, Jane is compliant with Alberta's Personal Information Protection Act (PIPA).
Does PIPA apply to my clinic?
Alberta's PIPA applies to private sector organizations and businesses in Alberta. PIPA sets out the rules for how private organizations collect, use, and disclose personal information, including employee information (with specific exceptions).
While PIPA generally applies to practitioners who are not governed by the Health Information Act (HIA), both laws could apply to you depending on the context of your services. If you are designated as a "custodian" under Section 2(1) and 2(2) of the Health Information Regulation, or an "affiliate" of a custodian, see this guide for more information.
If you're unsure whether PIPA applies to your organization, contact your regulatory body for guidance.
How does PIPA apply to my clinic?
Below are a few common principles in Alberta PIPA that apply to small businesses and clinics.
Consent
Clinics generally need consent to collect, use, or disclose a patient's personal information. Patients can withdraw or change their consent at any time. If a patient withdraws consent, your clinic needs to stop collecting, using, or disclosing their personal information immediately.
PIPA does allow collection without consent in limited circumstances, like when collecting the information is clearly in the interests of the individual and consent either can't be obtained from the patient in a timely way or the patient wouldn't reasonably be expected to withhold consent.
Limiting collection
Clinics must only collect a person's information for "reasonable purposes," such as providing care to a patient or processing payment for their appointments. Additionally, clinics must only collect information that's actually needed for those purposes.
In other words, don't collect more information than you have to, and make sure the reason you're collecting information would make sense to the average person.
Limiting use and disclosure
After you've collected a patient's information for a reasonable purpose, make sure their information is only used and disclosed for that purpose (unless it's otherwise required by law). This includes:
- Limiting employees' access to sensitive information if they don't need it for their role
- Not using a patient's information for something they didn't consent to or wouldn't think is reasonable in the circumstances
Access requests
Patients can request access to their own personal information in writing. Your clinic has 45 days to respond, and can apply for an extension in certain circumstances.
Your clinic may refuse access, in whole or in part, in certain circumstances, including if:
- The information would reveal someone else's personal information
- Sharing it would risk harm to the life of the patient or another person
Corrections
Patients can request a correction or amendment of their personal information if they believe it contains an inaccuracy or error. Your clinic must make the correction as soon as reasonably possible and notify any other organization the information was previously shared with. If your clinic doesn't grant the correction, you must add a note to the file explaining why.
Safeguards
Your clinic must have policies and procedures in place to protect personal information, covering physical, administrative, and technical safeguards. Check out Jane's Cloud Security White Paper to understand the safeguards we have implemented behind-the-scenes.
Breach reporting
Your clinic must report a breach to the Office of the Information and Privacy Commissioner (OIPC) if there's a "real risk of significant harm" to a patient.
Privacy Impact Assessments (PIAs)
Unlike the HIA, PIPA doesn't require your clinic to submit a Privacy Impact Assessment (PIA). Submitting a PIA to the OIPC is voluntary for organizations governed by PIPA. That said, the OIPC encourages voluntary submissions for projects involving the collection, use, and disclosure of personal information, particularly when multiple parties are involved.
You can find full submission guidelines on the OIPC's Privacy Impact Assessment Requirements page.
How does Jane enable my compliance with PIPA?
Jane includes several technical features to help Alberta clinics meet PIPA safeguard requirements.
- Signed, locked, and timestamped charts: to support integrity of clinical records.
- Access controls: the Account Owner determines which staff members can access which information in Jane.
- Individual user accounts: all Jane users can log in individually, and all activity in Jane is tied to their account. Passwords can be easily reset at any time.
- Behaviour tracking: actions taken by a logged-in user are recorded, and clinic owners can audit this through the Activity Log.
- Secure data storage: personal information is stored in secure and compliant data centres, with regular backups performed on secondary servers.
- Flexible charting: to help meet regulatory documentation requirements.
- Intentional deletion: Jane restricts the ability to delete patient records for which health information has been added.
- Controlled disclosure: sharing of personal information is managed at the patient level.
- Intake Forms: customizable electronic forms for alerting patients of their privacy rights and collecting consent.
- Keyboard shortcut to blur patient names: for added privacy in busy clinic settings.
- Real-time data saving: information is saved as it's entered in Jane.
- Privacy commitments from Jane: see Jane's Privacy Policy and Terms & Conditions.
Software like Jane has tools to support your compliance with PIPA, but it can't cover every aspect for you. You'll also need to implement safeguards like privacy and security training for staff, strong employment contracts, and a password policy.
For a full overview of Jane's security features, check out our Privacy, Security, and Compliance Hub.
Still have questions?
Have questions about this guide or anything else related to privacy? Email Privacy and Security Support at [email protected].