Commitment
Hines Health Services is committed to maintaining the accuracy, confidentiality, and security of all health records entrusted to them. Particularly when records contain personally identifiable information (“Personal Information”). As part of this commitment, our privacy policy governs our actions as they relate to the collection, use and disclosure of Personal Information. Our privacy policy is based upon the values set by the Canadian Standards Association’s Model Code for the Protection of Personal Information and Canada’s Personal Information Protection and Electronic Documents Act.
Hines Health Services complies with the following privacy legislation and regulations.
- The Personal Information Protection Act (PIPA);
- The PIPA Regulation;
- The Health Information Act;
- The Health Information Act Guidelines and Practices Manual; and
- Personal Information Protection Act (PIPA) PIPAADVISORY #8 IMPLEMENTING REASONABLE SAFEGUARDS
Introduction
Hines Health Services is responsible for accuracy, maintenance, and protection of the Personal Information under our control. We achieve this in the following manner:
- Transparency of purpose
- Obtaining consent
- Proper storage including labelling, security and limiting access
- Clarity of disclosure
Purpose
The purposes for which we collect Personal Information will be identified before or at the time we collect the information. In certain circumstances, the purposes for which information is collected may be clear, and consent may be implied, such as where your name, e-mail address and phone numbers are provided as part of a testing process.
The Personal Information collected will be limited to those details necessary for the purposes identified.
Consent/ Disclosure
Law requires the employee’s written consent before access to clinical information can be provided to others. Confidentiality is not an absolute duty; therefore, the Provider can disclose personal information under certain circumstances, including:
- If it is required by law
- With the employee’s consent
- If it is justified in the public interest, including for the protection of the employee, him/herself and other staff, public or patients they may come into contact with
In compliance with the Personal Information Protection Act, and the Health Information Act employees are allowed access to their own private health information upon written request and approval of the Occupational Health Director. Prior to releasing information to the employee, an appointment must be made for the employee to review their private health information with a registered nurse.
Normally, employees give permission for reports to be sent to their employer at the same time they receive their copy. However, on occasions when this is not the case Hines Health Services will notify the Customer that the report will be delayed for this reason.
Records Retention
All information collected at Hines Health Services is appropriately labelled (if required) as per our Records Management Process. The following labels are used in the Records Management Process:
Private
- this label is used when the records contain any information relating to an identifiable person.
Confidential
- this label is used when we intend to limit access or place restrictions on the information use for any reason.
Proprietary
- this label is used when the record contains internal business information that may have a competitive or strategic advantage, or it contain exclusive legal rights, examples include business plans, workplace assessment impairment tool or other intellectual property unique to Hines Health Services.
Access
Hines Health Services will ensure that all information pertaining to health records remains Private and Confidential, accessible only to the company health professionals. All Private records will be protected by a minimum of two-factor authentication.
Storage
Hines Health Services will maintain health records for the customers either on paper and/or computer/disc. Hines Health Services will store files on site for two years, in a locked and secure area, and then archive files for up to 30 years depending upon legislative requirements, until they can be securely destroyed.
Data Security
To prevent unauthorized access, maintain data accuracy, and ensure the correct use of information, we have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect.
Limiting Use, Disclosure and Retention
Personal Information may only be used or disclosed for the purpose for which it was collected unless employees have otherwise consented, or when it is required or permitted by law. Personal Information will only be retained for the period required to fulfill the purpose for which we collected it or as may be required by law.
Policy Breach
A privacy breach is the loss of unauthorized access to, or disclosure of, personal information. Breaches can happen when personal information is stolen, lost, or mistakenly shared. Following the discovery of a breach of protected information, Hines Health Services will notify the affected individuals in writing or via email if the affected individual has agreed to receive such notices electronically. These notifications will be provided within 30 days following the discovery and will include a brief description of the breach and the types of information that were involved, the steps Hines Health Services will take to investigate the breach, mitigate the harm, and prevent further breaches.
Adherence and Sustainment
We have designated an individual who is responsible for compliance with our privacy policy. All Hines Health Services employees involved in the collection of personal information are required to participate in Records Management Training.
Questions
Please direct any questions you may have about this Privacy Policy or its practices to Hines Health Services Privacy Officer. Tracey DeMartin, Director of Operations tracey@hineshealth.ca 780-790-6909.

