Saturday, July 17, 2004

Article: Video of workers ruled OK

The London Free Press has an article on the recent Federal Court of Canada decision about video surveillance at the CPR Yards in Toronto (see my blog entry on the case):

London Free Press: Business Section - Video of workers ruled OK:

"A recent decision of the Federal Court dismissed a complaint against Canadian Pacific Railway by one of its employees under the Personal Information Protection and Electronic Documents Act (PIPEDA). This decision reversed a decision of the privacy commissioner. PIPEDA is federal privacy legislation that governs the use and collection of personal information. The act allows organizations to collect, use or disclose personal information only for appropriate purposes and -- with certain exceptions -- only with consent. "

Full text here ...

Friday, July 16, 2004

Bill 31 (PHIPA) Training

National Privacy Services Inc. and ClinCoach Inc. have officially announced a series of training courses designed to assist physicians and other regulated healthcare professionals in addressing the Personal Health Information Protection Act, also known as Bill 31 and PHIPA.

Thanks to the alliance between NPSi and ClinCoach, the program will include a very comprehensive and practical course for those engaged in clinical research.

The updated brochure is available at http://www.privacylaw.ca/privacy/Bill_31_training.htm, which also includes an outline of the program.

More information is available on NPSi's training page, and you can register online here.

Tuesday, July 13, 2004

Article: New privacy legislation not main driver behind local shredding company's growth

I suppose the important thing is that they are getting more business...

New privacy legislation not main driver behind local shredding company's growth

By Ottawa Business Journal Staff
Mon, Jul 12, 2004 3:00 PM EST

Mr. Mannion attributes his branch's recent success to stepped-up promotion.

"Where we've seen our growth is by being proactive," he said. New privacy legislation has not brought a noticeable influx of business, Mr. Mannion said, though Shred-It did run commercials in Ottawa last fall, reminding businesses that, effective Jan. 1, privacy rules in the Personal Information Protection and Electronic Documents Act (PIPEDA) would apply to companies under provincial, as well as federal, jurisdiction.

"We haven't seen the deluge that a lot of people might have been expecting," he said.

Full text of the story here ...

Sunday, July 11, 2004

Bill 31 Training - Personal Health Information Protection Act (Ontario)

An Unprecedented Training Opportunity

ClinCoach and National Privacy Services have developed a range of training courses to assist health and health research professionals in adapting to and complying with Ontario's new Bill 31, the Personal Health Information Protection Act (aka PHIPA). This law comes into force on November 1, 2004 and has significant requirements for "health information custodians", including all regulated health professionals (physicians, physiotherapists, etc.), hospitals, nursing homes, and more.

The administrative requirements are similar to those of PIPEDA (hopefully the federal cabinet will deem the entire statute to be "substantially similar" to PIPEDA), and there are limited resources available to get healthcare professionals in compliance by the November 1 deadline. No matter what, it is not business as usual. The consent requirements are more specific for healthcare, but they are not exactly user friendly.

The new law also contains specific requirements for clinical researcher and Paula's years of experience in clinical research and clinical research education will prove to be a tremendous asset to attendees of our course designed for clinical research professionals.

From August to October, we will be offering our PHIPA training courses in Ottawa and Toronto. We will likely be hitting other centres in the rest of Ontario through late October and into the fall.

Training for Bill 31 - Personal Health Information Protection Act (Ontario):

"On November 1, 2004, the Personal Health Information Protection Act comes into force for Ontario's healthcare community. The new regime means it is no longer "business as usual" for regulated health professionals, hospitals and clinics. The rules have also changed for clinical research.

National Privacy Services Inc. (NPSi) and ClinCoach each have proven track records in delivering practical and effective privacy training for the healthcare sector. Together, we have designed a range of Bill-31 training courses specifically tailored for the medical community's varied roles and environments. Unlike other workshops and conferences you may have seen elsewhere, NPSi and ClinCoach provide solid training: in-depth, concise guidance on how to implement Bill 31 in your practice, all of which will be sufficient for continuing education credits. "

For more information, check out our brochure (advance copy available here) and the websites of National Privacy Services and ClinCoach.

Wednesday, July 07, 2004

ClinCoach and NPSi Alliance for Clinical Research Privacy

National Privacy Services Inc. and ClinCoach Inc. are going to announce tomorrow the establishment of a unique alliance to provide privacy training services for those involved with clinical research. ClinCoach is a leading, international provider of training for clinical research best practices, including the provision of Clinical Research Standard Operating Procedures. With NPSi, ClinCoach is developing a Standard Operating Procedures for interjurisdictional privacy best practices, designed to assist clinical researchers in complying with PIPEDA, PHIPA and other privacy laws.

ClinCoach and NPSi Alliance for Clinical Research Privacy:

"Standard Operating Procedures for Clinical Research

ClinCoach and NPSi have developed standardized means of integrating privacy best practices and legal requirements into clinical research, offering the first-of-its-kind Privacy Standard Operating Procedures for clinical trials. The best practices contained in the Privacy SOPs are designed to be compliant with Canada's multiple health privacy regimes, including PIPEDA, PHIPA: the Personal Health Information Protection Act and various laws in all Canadian provinces. These SOPs offer a privacy solution to sponsors in multi-centre trials located at sites across Canada."

You can check out the announcement at the websites of National Privacy Services Inc. and ClinCoach Inc. starting tomorrow.

Also, stay tuned for an announcement about Bill 31 training of Ontario's health professionals and institutions.

Tuesday, July 06, 2004

Thoughts from a Management Lawyer: Yet Another Surveillance Case

Michael Fitzgibbon's labour law blog has a reference to another workplace surveillance case, this time from the B.C. Court of Appeal: See Thoughts from a Management Lawyer: Yet Another Surveillance Case.

Correction: Coming into force of Bill 31

In an earlier blog entry, I suggested that the bulk of Ontario's Personal Health Information Protection Act will come into force on January 1, 2005. That was incorrect. The version of the bill passed by the legislature had November 1, 2004 as the effective date:

PART IX COMMENCEMENT AND SHORT TITLE

Commencement

99. (1) Subject to subsection (2), this Schedule comes into force on the day the Health Information Protection Act, 2004

receives Royal Assent.

Same

(2) Sections 1 to 72 and 75 to 98 come into force on November 1, 2004.

Short title

100. The short title of the Act set out in this Schedule is the Personal Health Information Protection Act, 2004.

Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Monday, July 05, 2004

Proposed Bill 31 Regulations published

The Ontario Ministry of Health and Long-Term Care has published a notice of proposed regulations under Bill 31. The public and interested parties are invited to comment on the proposed regulations (deadline: September 3, 2004):

Notice of Proposed Regulations- Invitation to Provide Comments on Proposed Regulations:

"The Minister of Health and Long-Term Care on behalf of the Government of Ontario invites public comments on proposed regulations for the Personal Health Information Protection Act, 2004 and the Quality of Care Information Protection Act, 2004.

The public is invited to provide written comments on the draft regulations over a 60-day period, commencing on July 3, 2004 and ending on September 3, 2004.

Please be as specific as possible, and provide reasons for any suggested changes or additions. All comments and submissions received during the comment period will be considered during final preparation of the regulation.

The proposed regulations are available at this link.

Addition: For information about Bill 31 (PHIPA) training, see http://www.privlaw.com/pages/training_courses.htm

Event: Privacy International 2004 UK Big Brother Awards

Privacy International will be hosting the annual UK Big Brother Awards in London on July 28, 2004. The international lobby group always produces a very interesting list of initiatives and incidents, all of which should not be missed. Prizes are being awarded for the "Most Invasive Company" and "Most Appalling Project", among others. (Thanks to Slasdot and the Register for the link):

Privacy International 2004 UK Big Brother Awards:

"On July 28th 2004, Privacy International will stage the 6th annual UK Big Brother Awards to recognise the people and organisations that have done the most to devastate privacy & civil liberties in the UK.

Now an annual event in seventeen countries, Privacy International's Big Brother Awards bring together a rich and unique mix of all ideologies and backgrounds. This year, for the first time, the award night will be open to the general public. A space for a thousand people has been reserved at the London School of Economics, which is hosting the event on the night."

Friday, July 02, 2004

Article: Breach of trust -- it's about keeping customers

This is a slightly older article, but I just happened across it today. It highlights something that I try to drill into my clients. Protecting customer personal information is not just about compliance, it is about keeping customers.

Breach Of Trust > May 3, 2004:

Breach Of Trust May 3, 2004
Data breaches are a constant threat and put companies in danger of losing their most valuable asset: customer trust
By George V. Hulme

When Christina Guilbert got a call from her bank in March about an attempt to steal money from her account, she was alarmed--and suspicious. How could someone access her account from an automated teller machine in England when her ATM card was in her home in Boston? Was the caller really a bank representative or a thief fabricating a story in an attempt to get account information from her? "With all of the scams on the Internet, I knew they could try the same thing using the phone," Guilbert says.

Guilbert had the bank rep confirm his identity by providing information on a recent transaction on her account. The bank blocked the attempted withdrawal, but Guilbert, who works at a public-relations firm, still doesn't know how the overseas thief got her account information. Guilbert's faith in doing any kind of business online has been destroyed. "I was concerned about shopping online before; now I won't shop online at all," she says. ...

Full text here ...