Updated: June 2022
As a health information custodian (HIC), Nucleus Independent Living (Nucleus), the CEO and its Board of Directors are committed to respecting the privacy rights of individuals and due to its sensitivity, ensuring a high level of protection of the personal health information (PHI) Nucleus Independent Living has in its custody and control.
To ensure that Nucleus Independent Living, its agents and health information network provider (HINP) comply with the Personal Health Information Protection Act (PHIPA).
agent – Includes any person who is authorized by a health information custodian to perform services or activities on the custodian’s behalf and for the purposes of that custodian. An agent may include an individual or company that contracts with, is employed by or volunteers for a health information custodian and, as a result, may have access to personal health information.
circle of care – A term of reference not defined under PHIPA but used to describe health information custodians and their authorized agents who are permitted to rely on an individual’s implied consent when collecting, using or disclosing personal health information for the purpose of providing health care or assisting in providing health care.
collect – The gathering, acquiring, receiving or obtaining of personal health information. This means that personal health information can be collected by a health information custodian or an authorized agent.
consent –
a. Express consent to the collection, use or disclosure of PHI by a health information custodian is explicit and direct. It may be given verbally, in writing or by electronic means.
b. Implied consent permits a health care custodian to infer from the surrounding circumstances that an individual would reasonably agree to the collection, use or disclosure of his/her personal health information. Also refer to ‘circle of care.’
custody (of the record) – The best evidence of custody means the keeping, care, watch, preservation or security of the record for a legitimate purpose, not mere possession.
control (of the record) – Means the power or authority to make a decision about the use or disclosure of the record even if not in the possession of the organization.
disclose – Means to release or make personal health information available to another person, organization or health information custodian; it does not mean to use the information. It does not include providing information directly back to the person who provided it in the first place, whether or not the information has been altered, so long as it does not include additional identifying information.
health care – Means any observation, examination, assessment, care, service or procedure
provided for a health-related purpose and that is carried out or provided:
health information custodian – A health information custodian is a listed individual or organization under PHIPA that, as a result of its power or duties, has custody or control of personal health information.
health information network provider – A person or organization who supplies goods and services to two or more HICs that enable the HICs to collect, use, modify, disclose, retain or dispose of PHI electronically.
Information and Privacy Commissioner of Ontario – The regulatory agency responsible for overseeing compliance with and enforcing PHIPA.
Nucleus Independent Living – A non-profit organization fully funded by the Ministry of Health and Long-Term Care (MOHLTC) and governed by a Board of Directors. Formally named Nucleus Housing the organization was officially established in 1983 to provide housing for individuals with physical disabilities. Since its inception, Nucleus has grown to include a wide range of outreach services in the community.
personal health information – “Identifying information” collected about an individual, whether oral or recorded. “Identifying information” includes health information that could identify an individual when used alone or in conjunction with other information. PHI includes information about an individual’s health or health care history in relation to:
Personal Health Information Protection Act – Ontario’s health-specific privacy legislation that came into force in 2004. This law governs the manner in which personal health information may be collected, used and disclosed within the health care system. It also regulates individuals and organizations that receive personal information from health care professionals.
privacy breach – A privacy breach includes the collection, use or disclosure of PI/PHI that is not in compliance with applicable privacy law, or circumstances where PI/PHI is stolen, lost or subject to unauthorized or inappropriate collection, use or disclosure, copying, modification, retention or disposal, whether at rest, in transit or while in use.
privacy impact assessment – A formal risk management tool used to identify the actual or potential effects that a proposed or existing information system, technology or program may have on individuals’ privacy.
safeguards – The physical, technological and administrative protective measures and security techniques that are designed to ensure that personal health information remains confidential, available and uncompromised. This includes measures such as encryption, passwords, and firewalls designed to prevent unauthorized access to information, to protect the integrity of computing resources, and to limit the potential damage that can be caused by unauthorized access.
use – The handling of or dealing with personal health information that is in the custody or control of a health information custodian or its authorized agent. This includes accessing or reproducing health information as required by the custodian.
withdrawal of consent (“Lock-box”) – A term of reference not defined under PHIPA but used to describe the right of an individual to instruct a health information custodian not to disclose specified personal health information to another custodian for the purpose of providing health care.
Information and Privacy Commissioner/Ontario PHIPA resources. [https://www.ipc.on.ca/english/phipa/]
Nucleus utilizes Caredove's software platform to remain compliant with the Personal Information Protection and Electronic Documents Act ("PIPEDA"). Caredove is committed to protecting the Personal Information of its users and the Personal Health Information of visitors, users and clients referred using the Caredove platform. To accomplish this, Caredove has put in place a Privacy & Security Program .
Nucleus Independent Living
2030 Bristol Circle, Suite 110
Oakville, Ontario L6H 0H2