Privacy Impact Assessment
A Physician Office System Program (POSP) resource will be
assigned to your clinic after the kick-off meeting. This resource
will work with you to establish your privacy impact assessment
(PIA).
You must have a PIA and corresponding Health Information
Act file number to be eligible for POSP funding. You must have
submitted a PIA to the Office of the Information and Privacy
Commissioner (OIPC) and received a Health Information Act file
number before your EMR solution goes live.
A PIA is a due diligence exercise in which a custodian (e.g., a
physician) of health information identifies, analyzes and addresses
potential privacy risks that might occur in the course of a
clinic's operations. For example, there is potential for privacy
risk in administrative practices and within information systems
relating to the collection, use or disclosure of individually
identifying health information.
A PIA provides documented assurance to your clinic, the OIPC and
the public that all privacy issues related to a particular
initiative have been identified and addressed.
A PIA is a mandatory exercise during your transition to an
electronic medical record (EMR) solution. During the PIA, a POSP
resource assists you in reviewing and documenting the physical,
technical and administrative privacy and security functions. The
POSP online General Privacy Training program must
be completed before an EMR transition advisor for privacy can be
assigned to a clinic
Download
Privacy Officer Handbook
Download Privacy Services Summary