eCommunication Guidelines
eCommunication
Considerations for trustees for the protection of personal health information when using eCommunication tools
This document is intended to provide general advice to trustees to help them decide when using eCommunication tools is appropriate and if proceeding, how to protect personal health information in the process.
Background
eCommunication, or electronic communication, is an ever-expanding method of communicating between individuals and organizations. In healthcare, eCommunication tools have become the norm in assisting trustees in managing patients’ healthcare by communicating directly with patients and other healthcare providers. Some eCommunication tools that are being utilized by trustees include fax, email, text and picture messaging, video conferencing, mobile applications (apps), social media and patient portals. The tools used for eCommunication will continue to grow as technology advances and other forms of electronic communication are developed. This resource will discuss considerations for trustees when communicating personal health information (PHI) through eCommunication tools. For guidance on the management of text messaging and other instant messaging tools and tips for securing your mobile device, please refer to our resource: Best Practices for Managing the Use of Personal Email Accounts, Text Messaging and Other Instant Messaging Tools and Helpful Tips: Mobile Device Security.
This document will provide trustees with considerations when using eCommunication to assist them in complying with their obligation under The Health Information Protection Act (HIPA) and The Health Information Protection Regulations, 2023 (HIPA Regulations). For HIPA to apply, there must be three elements present: 1) a trustee as defined at section 2(1)(t) of HIPA or section 4 of HIPA Regulations; 2) there must be PHI as defined by section 2(1)(m) of HIPA or 3 of HIPA Regulations; and 3) the trustee must have custody or control of the PHI in question. For further clarification on when HIPA is engaged and who is considered to be ‘the trustee’, please refer to the blog, “A” Trustee vs. “THE” Trustee (updated).
There have been instances where OIPC found that a healthcare provider, that appears to fit the definition of a trustee, did not have custody or control of the PHI and thus, is not ‘the trustee’ of the PHI in the circumstances. An example of this can be found in Investigation Report 022-2018. In that investigation report, the former Commissioner determined that the non-profit corporation that owned the medical clinic had custody and control of PHI, not the physicians of the medical clinic. In that case, the non-profit corporation did not fit the definition of a trustee pursuant to HIPA; therefore, HIPA did not apply. However, it is best practice that anyone that has custody or control of PHI appropriately protect PHI, including when using any form of eCommunication.
Prior to Using eCommunication Tools, Trustees Should Determine if it is Appropriate, Necessary and Secure
Prior to using eCommunication tools, trustees should conduct a privacy impact assessment (PIA) to assist them in determining whether the use of eCommunication tools would be secure, appropriate and necessary, and whether the benefits outweigh the risks of electronic communication. For more information about conducting PIA’s, consult our resource: Privacy Impact Assessment: A Guidance Document.
Trustees are responsible for assessing the risks associated with utilizing eCommunication tools for communicating PHI. The risks associated with each eCommunication tool will vary based on risks inherent to each, actions taken or not taken by the trustee and the type and volume of PHI communicated through the eCommunication tool. For instance, there is less risk if only sending reminders or scheduling appointments instead of clinical information. Some of the risks that trustees may face when utilizing eCommunication for communicating PHI include:
- PHI may be sent to the correct addressee, but a third party could intercept the information (e.g., spouse, child, friend, etc).
- Malware, such as worms and Trojan viruses may compromise the integrity of PHI communicated through the eCommunication tool.
- Unintended recipients may receive PHI through misdirected eCommunications such as fax (see Investigation Report 032-2022), email, text or picture messaging often because sent to wrong person such as someone with a similar sounding name (see Investigation Report 103-2020) and/or wrong fax number, email address or phone number.
- Third parties, such as app developers, may use the information stored on the eCommunication tool for unauthorized internal or external use.
- Mobile devices that are used to communicate PHI through the eCommunication tools may be lost or stolen or not returned by those leaving employment if not office-issued.
- Information or images posted on social media may identify a patient through metadata or otherwise, thus compromising the privacy of the patient’s PHI.
- Information posted on social media and public forums may never be completely deleted from the internet.
- Unauthorized personnel may overhear a phone call or videoconference regarding PHI;
- Photos taken with a mobile device that capture a patient’s PHI sent through an eCommunication tool may be viewed by others without a need-to-know.
- PHI may be accessed intentionally, such as by hackers, even if a passcode, password or passphrase is in place.
- Unauthorized access to PHI may occur through unsecured and public networks (particularly free Wi-Fi networks in public places).
What Obligations do Trustees Have Under HIPA Regarding Protection of Personal Health Information When Utilizing eCommunications
The OIPC strongly recommends that trustees and their employees refrain from using eCommunication tools unless they can be set up to retain and store records effectively and securely. When considering the implementation of any new eCommunication tool, trustees should consult with its access and privacy experts, information technology and records management staff to discuss whether the use of the eCommunication tool is necessary and if so, how the trustee will ensure that PHI will be appropriately safeguarded.
HIPA and the HIPA Regulations provide rules regarding when a trustee may collect, use and disclose PHI. Section 23 of HIPA requires trustees to ensure the collection, use and disclosure of PHI is on a need-to-know basis which includes complying with the data minimization principle. Trustees must establish policies and procedures to restrict access to PHI by their employees without a need-to-know. Any unauthorized collection, use, or disclosure of PHI would be considered a privacy breach.
Section 16 of HIPA requires that a trustee have administrative, technical and physical safeguards to protect the integrity, accuracy and confidentiality of PHI in its custody or under its control from:
- Any reasonably anticipated threat, hazard or loss.
- Unauthorized access to or use, disclosure or modification.
- Otherwise ensure compliance with HIPA by its employees (also see section 5 of HIPA Regulations).
Administrative safeguards are controls that focus on the organization’s policies, procedures and maintenance of security measures that protect PHI.
Examples of administrative safeguards for trustees to consider when implementing the use of eCommunication includes:
-
Policies and procedures: Develop and implement strong and clear written policies and procedures and/or work standards for the use of eCommunication tools to protect PHI and ensure staff are aware of these and how to apply them in practice. Some topics that trustees should ensure the policies address include:
- Identify which eCommunication tools are permitted for communicating PHI and in what circumstances.
- Ensure staff are aware that all PHI communicated through eCommunication tools are official records and must be considered when processing access to information requests.
- Ensure staff are aware to limit the PHI collected, used and disclosed through eCommunication to meet the data minimization principle.
- Ensure procedures are in place for how to respond to a suspected privacy breach involving an eCommunication tool or a lost or stolen device that is used to communicate PHI through eCommunication tools.
- Ensure staff know steps to take in verifying the identify of individuals that they plan to communicate PHI with through eCommunication.
-
Consent Forms: Section 6 of HIPA indicates that consent to the collection, use or disclosure of PHI is informed if the individual who gives consent is provided with the information that a reasonable person in the same circumstances would require in order to make a decision about the collection, use or disclosure of PHI. Trustees planning to gather consent from patients to communicate with them via eCommunication should clarify what information they intend to communicate through these tools and the risks associated with using eCommunication before utilizing. Trustees and their staff should also know how to address patient’s consent directives (example: patient wishes to have appointment confirmation and reminders via eCommunication, but does not wish for test results or follow up information regarding a diagnosis to be sent via eCommunication). For more information on gathering informed consent, please refer to our resource: Best Practices for Gathering Informed Consent and the Content of Consent Forms.
- Confidentiality/Privacy Agreement: Ensure the Confidentiality Agreement/Privacy Agreement signed by staff includes reference to the eCommunication tools utilized by the trustee and what the expectations are when communicating PHI. For more guidance on this topic, please refer to our resource: Sample Privacy Agreement for Trustees: Protection of Personal Health Information.
-
Annual Access and Privacy Training: Trustees should train staff on how to properly safeguard PHI when using eCommunication tools as part of its annual access and privacy training and as a part of the orientation of any new hires.
-
Information Management Service Provider (IMSP) Agreements: Ensure that when engaging with IMSPs for eCommunication tools that detailed written agreements are in place. For guidance on what elements should be included in such agreements, refer to
section 18 of HIPA, section 7 of HIPA Regulations and our resource: Best Practices for Information Sharing Agreements.
-
Auditing Programs: Determine the frequency that access logs will be reviewed or audits conducted on the eCommunication tools to ensure that PHI is only accessed or viewed, modified or deleted with authorization. For more information about audit logs, consult our resource: Audit and Monitoring Guidelines for Trustees.
-
Records and Information Management Systems: Trustees should determine how information will be sent, received and captured using eCommunication and ensure that the records produced by all authorized eCommunication tools are included in the trustee’s overarching record management plans.
-
Records Retention and Destruction Schedules: Records created through all authorized eCommunication tools should be included in the trustee’s retention schedules and general records management planning. Trustees should also determine proper secure disposal methods of PHI from a device utilizing eCommunication tools or PHI stored in an eCommunication tool once the PHI has been transferred to a secure location.
- Access Restrictions: Determine which employees of the trustee require access to the eCommunication tools to ensure compliance with the need-to-know principle and have access privileges revoked when necessary (e.g., employee leave of absence or termination of employment).
Technical Safeguards are the technological controls that are utilized to protect PHI including controlling access to it.
Examples of technical safeguards for trustees to consider when implementing the use of eCommunication includes:
- Login Credentials: Ensure all users have separate username and strong password for accessing eCommunication systems and requiring that password-enabled screen locks and timeout features are engaged. Login credentials should not be shared and password attempts should also be limited. When an employee/contractor leaves (on a leave or permanently) the trustee organization, then the username and password should be deactivated immediately so they cannot access systems remotely.
-
Authentication Controls: Consider what type of file, program or data permissions will be used to limit users access to the eCommunication tools or the PHI collected, used or disclosed.
-
Software and Operating Systems: Disable unauthorized software on work-issued mobile and other computing devices and identify when Software and Operating Systems should be updated and the consequences if not done so in a timely manner.
-
Virus Protection: Ensure appropriate level of virus protection on devices where eCommunication tools are utilized and limit the types of apps or internet use on devices where eCommunication will be used to communicate PHI to minimize the risk of viruses.
-
Audit Capabilities: Ensure any systems used for eCommunication of PHI have appropriate logging and audit capabilities to monitor and audit the collection, use, viewing, disclosure, modification and deletion of PHI.
-
Secure Transmission of Data: Ensure PHI communicated through eCommunication is appropriately protected, such as through the use of encryption and/or password protection.
-
Backup and Secure Storage of PHI: Trustees should ensure that PHI collected through eCommunication tools are regularly backed up. Trustees should also determine if records can be automatically and securely retained on the trustee’s digital storage or if mobile device management or if Private Cloud Computing infrastructures will be utilized. If utilizing Cloud Computing infrastructures, determine where records are stored (ex. will the information be stored on servers outside of Canada) and ensure that the trustee will have control over how that information is protected, disclosed or accessed. Trustees should ensure the use of personal cloud services and their associated automatic back-up options (e.g., OneDrive or Dropbox) are not used on the trustee’s devices where eCommunication tools will be used. For PHI stored in eCommunication systems, trustees should determine if the information is encrypted.
- Format of electronic records: When using eCommunicaiton tools it is likely all records associated will be stored in an electronic format. To ensure the accessibility and integrity of the records, trustees should determine if the format the records are saved in will require separate software, or how to convert the record into a format that will be in an accessible and stable format.
Physical Safeguards are physical measures put in place to protect PHI and related buildings and equipment from unauthorized intrusion and natural and environmental hazards.
Examples of physical safeguards for trustees to consider when implementing the use of eCommunication includes:
-
Authorized personnel only: Restrict office access, use alarm systems and lock rooms where equipment is kept or servers are housed. Ensure no one without a need-to-know is present or is able to overhear or view PHI under discussion.
-
Mobile device management: It is preferable that any mobile devices are office-issued, not bring your own device (BYOD). Trustees should determine if it is necessary for devices that utilize eCommunication tools to be used off-site. If necessary, they must be appropriately secured in transit or when being used outside of the office (ex. transport in a locked briefcase or use a laptop lock when being used outside of the office).
- Clean Desk Policy: While clean desk policies are more commonly considered for safeguarding paper records, clean desk policies can also be implemented by trustees to prevent devices that are utilized to communicate PHI through eCommunication tools from being easily accessible to unauthorized users. Examples may be placing mobile devices (such as smart phones and tablets) in a locked desk while unattended and utilizing laptop locks.
Consult our resource Helpful Tips: Mobile Device Security, for more guidance on physical safeguards for mobile devices.
What eCommunication Tools are Being Utilized in the Healthcare Field and What are Some Considerations for Trustees
Telemedicine is a combined term meaning the remote delivery of health services and the use of technology to do so. Telemedicine can also be referred to as telehealth, telehomecare, and telepresence and telesurgery. The delivery of telemedicine can be done through the use of video conferencing, email, text and picture messaging, the use of apps and social media and patient portals.
Telemedicine provides a means of communication between a patient and their health care provider and can be used for a variety of reasons such as medical consultation and coaching for chronic diseases or clinical reasons such as downloading blood pressure readings.
Some considerations for trustees include:
- Conduct video conferences in a secure area for telemedicine programs to take place (ex. designated sound proof telehealth room) and encourage patients to also have a secure area for the video conference.
- Adopt appropriate physical safeguards (ex. equipment is in a locked and limit access to the room).
- Secure the application (ex. disable features not using like screen saving) and secure meetings (ex. keep the meeting link and password or passphrase private).
- Determine whether the telehealth video conferences are recorded.
- If video conferences will be recorded, determine what length of time they will be stored and how to integrate into the patient’s record.
- Ensure video conferences are conducted over a secure network connection. Determine if the data transmission will be encrypted.
- Have an incident response plan if you suspect malicious activity (i.e. meeting bombing).
Some considerations for trustees when using email or fax include:
- Use professional instead of personal web-based email accounts that may have weaker security and that records generated cannot be easily managed by the trustee.
- Limit the amount of personal health information being sent to what is absolutely necessary.
- Ensuring all PHI is in an attached document and is protected with encryption or passwords and communicate the password to the recipient using a separate method.
- For emails, read/received/delivery receipts should be used where possible.
- Disable autocomplete or autofill to avoid errors in the intended recipients’ email addresses.
- Consider de-identifying the PHI that will be communicated.
- Consider using a file-share service that restricts the users that can access the records and limits the amount of time the information is available to other parties.
- Consider whether it would be more appropriate to send an email notifying patients that new results or messages await in a patient portal.
- Use a fax cover sheet.
- Include a confidentiality clause specifying that the material is confidential and what to do if received in error.
- Ensure recipient email addresses are accurate and up-to-date.
- Ensure that suspicious emails or email addresses are reported to information technology staff for clearance or to block future emails.
For more information please see the Privacy Commissioner of Canada’s Tips for creating and managing your passwords.
As faxing is probably one of the most common ways in which PHI is shared between healthcare professionals, it is no surprise that privacy breaches involving misdirected faxes are a common occurrence. Too often, the root cause of these incidents is mixing up of physicians’ names in dictated and transcribed reports because of similar sounding names. More must be done to ensure accuracy of this information prior to sending via electronic means.
Trustees utilizing fax to communicate PHI should also refer to our resource: Faxing Personal Information and Personal Health Information: Safeguards and Responding to a Breach.
Some considerations for trustees include:
- Determine whether PHI communicated through Text and Picture Messaging is to be stored on the mobile device and how it will be integrated into the trustees records management system.
- Create policies and procedures/works standards and educate staff on acceptable and unacceptable uses of text and picture messaging.
- Determine what type of information can be communicated through text and picture messaging, such as whether it will be used solely for confirming or scheduling an appointment or if the trustee will use the eCommunication for other actions.
- Consider de-identifying the PHI and what will be communicated through text messaging.
- Ensure recipient contact information is accurate and up-to-date.
Mobile Applications (Apps)
Mobile applications (apps) are software created to be used on mobile devices such as smart phones and tablets. The use of apps may provide an alternative method of communicating between trustees and patients. Some health care providers are turning to the use of apps to document a patient’s PHI, order tests or as a medical reference (e.g., medical dictionary). Some considerations for trustees include:
- Trustees allowing the use of apps on mobile devices should consider developing a list of approved apps that can be installed on mobile devices to ensure the protection of PHI.
- Ensuring the app developers will not be accessing or sharing information for internal or external use.
- Ensure safeguards are in place to protect PHI stored in the app from being accessed by other apps on a patient’s mobile device.
- Limit what information the app will need access to on the patient’s device and ensure patients have the choice to opt-in to app permissions to share information.
For more tips on the use of apps, refer to the Office of the Privacy Commissioner of Canada’s resources: Ten Tips for Communicating Privacy Practices to Your App’s Users and Seizing Opportunity: Good Privacy Practices for Developing Mobile Apps.
Social Media
The use of social media to exchange information and knowledge and for connecting the profession of medicine to the general public is developing at a rapid pace, but have inherent risks. Trustees are using social media as a tool to provide indirect medical care, offer advice, promote good health and communicate with fellow health professionals. Common social media platforms are Facebook, Twitter, Instagram and even blogs. Some considerations for trustees include:
- Trustees should prohibit discussions with individuals regarding any specific concerns regarding their PHI in a public forum.
- Trustees should develop policies regarding the use of personal social media accounts by employees to ensure PHI is not shared through those accounts.
- If trustees are considering use of social media private messaging tools (such as Facebook messenger), they should determine how those records will be retained, and should consider limiting the type of information that can be discussed through those tools.
- Ensure content and images being posted on social media have been reviewed for information that may identify an individual including metadata.
Patient Portal
The adoption of the patient portal is growing in the delivery of health care. The patient portal is a new development aimed at not only providing patient’s online access to their PHI but also providing patients with the ability to communicate with trustees through the addition of PHI to their record. Some considerations for trustees include:
- Limit the amount and type of information a patient may add to their portal to avoid over-collection of PHI.
- Determine if patients will be able to access the patient portal on a mobile or mobile computing device (e.g., smartphone) or only on a desktop or laptop computer.
- Identify, if using mobile or computing devices, what information the patient portal may collect from the patient’s mobile device.
- Avoid storing sensitive information in the portal and determine if patients will have the option of masking or blocking information made available through the portal.
- Determine what technical safeguards will be implemented to protect patients’ PHI when they are accessing the portal through their personal devices (ex. Will the session timeout after a specified length of inactivity? What will the log-in requirements be for patients? Will there be notice that patients should refrain from accessing their PHI or saving log-in information for the portal on publicly accessible devices?).
Conclusion
The variety and capabilities of eCommunication tools will continue to grow with the advancement of technology and in turn, the number of trustees that utilize these tools will also increase. However, trustees need to ensure they consider the risks (see Protecting patient privacy when delivering care virtually) associated with using eCommunication to communicate PHI and take necessary steps to ensure the information is appropriately safeguarded in compliance with HIPA and HIPA Regulations before utilizing.
Contact Information
If you have any questions or concerns regarding eCommunication, please contact us: 306-787-8350 | toll free 1-877-748-2298
503 – 1801 Hamilton Street | Regina SK S4P 4B4 intake@oipc.sk.ca | www.oipc.sk.ca | @SaskIPC