General Limits on Collections, Uses, and Disclosures

AuthorHalyna N. Perun; Michael Orr; Fannie Dimitriadis
Pages271-290
A. GENERALLY
The Personal Health Information Protection Act, 20041imposes certain general
limits on collection, use, and disclosure of personal health information by
health information custodians. Further, the Act extends similar limits on uses
and disclosures of personal health information by non-health information cus-
todians who have received the information from a custodian.2These limits are
often referred to as the “general limiting principles.” Although the Act does not
refer to the “general limiting principles,” the Ministry of Health and Long-
Term Care has commonly used this phrase to refer to the general limitations
on personal health information described in PHIPA.3
The limits articulated in PHIPA are consistent with the CSA Privacy Code
Principles.4First, the CSA Privacy Code provides that the collection of personal
information must be limited to that which is necessary for the purposes identified
by the organization.5Next, the information must be collected by fair and lawful
271
1 S.O. 2004, c. 3, Sch. A [PHIPA].
2 The rules for recipients are discussed in Chapter 12.
3Personal Health Information Protection Act, 2004: An Overview (November 2004) at slide 16,
published by the Ministry of Health and Long-Term Care, online: .on.ca>.
4 Schedule 1 to Personal Information Protection and Electronic Documents Act, S.C. 2000,
c. 5 [PIPEDA].
7General Limits on
Collections, Uses,
and Disclosures
means.6Further, organizations must not collect personal information indiscrimi-
nately. Both the amount and the type of information that organizations collect
must be limited to that which is necessary to fulfil the purposes identified.7PHIPA
extends these principles not only to the collection of personal health information,
but to the use and the disclosure of personal health information as well.
B. COLLECTION, USE, AND DISCLOSURE FOR A LAWFUL
PURPOSE
The most fundamental limit in PHIPA is the rule that a health information
custodian is prohibited from collecting, using, or disclosing8personal health
information about a patient unless either the custodian has the patient’s con-
sent9under the Act and the collection, use, or disclosure, as the case may be,
is, to the best of the custodian’s knowledge, necessary for a lawful purpose,10 or
the collection, use, or disclosure is permitted or required by PHIPA.11
In other words, consent is required for all collections, uses, and disclo-
sures of personal health information by a health information custodian unless
a specific provision of PHIPA permits the collection, use, or disclosure.12 Fur-
ther, unless the collection, use, or disclosure of the personal health informa-
tion is permitted without consent by a specific provision of PHIPA, it not only
requires a patient’s consent, but also can only be carried out if it is “to the best
of the custodian’s knowledge, necessary for a lawful purpose.”
Where PHIPA permits a specific collection, use, or disclosure of personal
health information without consent, this permission in PHIPA itself is, in
essence, recognizing a “lawful purpose,” and so no further modifier is necessary
272
5Ibid., Principle 4, at 4.4.
6Ibid.
7Ibid., Principle 4, at 4.4.1.
8 The definitions of the terms, “collect,” “use,” and “disclose” are outlined in Chapter 2,
Section E.
9 The requirement for consent and the kind of consent that a custodian needs in differ-
ent circumstances is set out in Chapter 5. The word “patient” includes the authorized
substitute decision-maker. See Chapter 6, Section D for a discussion about the author-
ity of substitute decision-makers.
10 PHIPA, s. 29(1)(a).
11 Ibid., s. 29(1)(b). The requirement for consent to the collection, use, or disclosure of
personal health information is consistent with section 7 of PIPEDA, above note 4.
12 Because of the language of s. 29(b), the provisions in the Act that permit a collection,
use, or disclosure of personal health information in specified circumstances are prop-
erly read as permitting such activity without consent.

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT