Strengthen your clinic with a professional PIA
Custodians of patient information in Alberta are required (by section 64 of the Health Information Act (HIA)) to submit a Privacy Impact Assessment (PIA) to the Office of the Information and Privacy Commissioner (OIPC). An OIPC accepted PIA demonstrates your commitment and ability to protect patient privacy and establishes the policies and procedures that keep you and your patients safe from the loss or exposure of confidential information.The process of completing a PIA identifies risks to the security of your clinic and builds a plan for mitigating that liability.
Use this site as a resource to learn about your clinic's compliance responsibilities under the HIA and the requirements for submitting a PIA. The answers you'll find here are curated by experts with decades of experience in privacy compliance in Alberta, with over 1,200 completed Privacy Impact Assessments.
Find out why a Netcare PIA is not enough
The First 5 Steps to Privacy Compliance
What do you need from a privacy compliance partner?
Ongoing privacy compliance is critical to your business. Proper privacy management often requires a partner with expertise.
Choosing the right professionals to help with your PIA will expedite your process and diminish time and effort required on your end significantly.
Properly experienced consultants with the right resources offer a great deal more than a basic Privacy Impact Assessment. Your privacy compliance and security needs will continue to evolve after the initial assessment is accepted. This list helps you identify the support you will need on an ongoing basis from your compliance support partner.
Brightsquid Privacy Support Services provide the expertise, foundations, and ongoing consultation you need to establish and maintain privacy compliance while also actively preventing privacy breaches.
Full clinic Privacy Impact Assessment (PIA)
A fixed price and defined delivery timeline with no overages or surprise fees
Revisions through acceptance
Netcare PIA - All requirements for Netcare opt-in
Support with HIA mandatory Agreements: IMA, VNDA, etc.
Privacy Compliance Training for your team (3hrs)
Privacy Resources: handbooks, checklists, newsletters, video tips
Secure-Mail for privacy-compliant communication and automatic privacy breach prevention
Quarterly privacy check-ins
Cyber threat awareness training
Privacy breach prevention training
Privacy Officer support hotline
Privacy breach response and recovery guidance
Regulatory policy change PIA updates
Data migration planning and assistance
1,500+ PIAs written and accepted
A team of certified privacy professionals to support you without interruption
Annual Privacy Conference and Workshop
Top privacy risks clinics face:
Healthcare clinics are particularly susceptible to privacy and security breaches. A Privacy Impact Assessment can provide a blueprint on beast practices that secure your clinic data against the threat of cyber attack.
The cost of theft:
Private patient information is 50 times more valuable on the black market than credit card data. Criminals can use stolen patient data to assume a patient’s identity, causing severe financial and reputational damage, but also putting patient health at risk by contaminating their medical record.
The cost of non-compliance:
Privacy regulations in healthcare exist to keep patient information safe, and protect your practice from the consequences of a breach or malicious attack. Failure to comply with regulations can constitute a breach and cost heavily in fines and other punitive measures including loss of patients.
The cost of losing patients:
Clinics publically known to have lost private patient information have seen as much as a 70% drop in patient loyalty. And it’s hard to get them back. Research shows Canadians are willing to travel up to 50km if local providers aren’t careful with their confidential information.
The real threat of ransomware:
Ransomware is malicious software that infects clinic networks and locks away important information such as digital patient files until a ransom is paid. Clinics are a target because of the black market value of patient records and the fact that most clinics believe they are too insignificant to be a target. In reality, attackers can make over $1,000,000 from the patients records taken from just one clinic - and that's after they've already taken a ransom to release the information.
When ransomware locks away patient records, clinics are typically shut down for a few days until they're able to recover the lost data.
Attacks like this are considered a privacy breach because the clinic has lost control of its patient's private information. In jurisdictions where breach reporting is mandatory, infected clinics are likely required to notify patients (by phone and/or letter) and even the news to make all affected parties aware that their private information has leaked and their identity is at risk. Typically regulations require identity monitoring for each impacted patient for one to two years.
Cybercriminals have realized that backups provide an escape for their victims. Now, more ransomware attacks steal data and threaten to release it on the Internet if a ransom is not paid.