By Michael Power

The federal and provincial governments of Canada have invested billions to develop health information technology, but privacy concerns loom. Public support for EHRs, says Michael Power, will be tied to how well patients’ private information is protected. Power describes Canada’s EHR landscape here.

In Canada, the provinces and territories manage and deliver health services to their residents; the federal government provides a large degree of funding under the authority of the Canada Health Act, which specifies criteria and conditions that provinces and territories must meet in order to qualify for financial transfers.

To facilitate the sharing of health information among healthcare providers across the continuum of care, the federal government, through Canada Health Infoway, has made significant investments in regional and provincial electronic health record systems. To date, Infoway has invested $1.6 billion and committed a further $500 million in early 2009 to several hundred EHR projects. The provinces have also contributed significant funds to implement healthcare information technology.

It is important to emphasize that “EHR” in Canada specifically refers to patient-centric, longitudinal health record systems that contain a subset of data of interest to multiple providers. Electronic medical records (EMRs) in Canada, on the other hand, are provider-centric and contain substantial patient detail that may not be of interest to other providers. This distinction does not appear to apply in the U.S.

Most of the development to date has focused on infrastructure and systems to digitize and transport key elements (e.g. network, applications, registries) and electronic medical record systems in hospitals. Because of a low level of EMRs held by primary care providers, adoption and implementation of EMRs (a necessary component in any EHR system) is moving to the forefront as the next challenge to address. A number of provinces are moving to an ASP model for EMRs (British Columbia, Ontario, Alberta, Nova Scotia and Saskatchewan).

Privacy and security considerations loom large because EHRs, in the Canadian eHealth model, are designed to facilitate the sharing of data for patient care, public health surveillance, and health research, and in electronic communication between and amongst patients and providers. For patients, there is a fear of undesirable consequences, including financial loss or the loss of personal dignity (e.g. discrimination or social stigma) arising from the misuse of data. Public support for EHRs can be tied to how well healthcare providers and governments keep PHI private and secure.

A number of provinces have health-specific privacy legislation (British Columbia, Alberta, Saskatchewan, Manitoba, Ontario) and others are contemplating enactment of such statutes (New Brunswick, Nova Scotia, Newfoundland). Other statutes exist that affect the collection, use, and disclosure of personal health information.

British Columbia has enacted the E-Health (Personal Health Information Access and Protection of Privacy) Act. This statute, among other things, creates a framework for the creation of Health Information Banks; allows individuals to issue “disclosure directives;” and creates a Data Stewardship Committee to evaluate research requests for information. Whether this is sufficient is debatable given the emergence of the “BC Big Opt Out” campaign (www.bcoptout.ca), which promotes “opting out” of the provision of PHI to “eHealth.” Alberta has proposed amendments to its Health Information Act to effectively dispense with consent (a custodian will no longer be required to consider a patient’s wishes about the exchange of health information via Alberta Netcare) and permitting the government to require custodians to make health information available via Alberta Netcare. Alberta’s Privacy Commissioner has been critical of these changes and the enactment of these amendments seems to have stalled.

It can be argued that the Canadian experience with the deployment of EHRs has seen technology outpace policy and concerns about privacy (or perhaps more accurately how to deal with privacy issues) have affected the development of provincial EHRs. The whole area of de-identification policy, the misalignment of legacy IT systems and privacy policy requirements, the need for the aggressive use of audit capabilities (i.e. a strong monitoring policy), and the lack of comprehensive privacy programs at all levels of healthcare delivery all point to further attention to privacy being necessary in order to avoid a loss of patients’ trust and confidence.

Governance and data custodianship loom large as issues where sharing of sensitive data is a major system requirement. It is arguable that current legislation and rules of conduct governing the healthcare professions do not adequately address responsibilities for health IT systems’ operations. Similarly, how EHR/EMR custodians will manage and apply consent directives across multiple patient/provider identities, domains, and even jurisdictions remains a challenge.

Privacy is recognized clearly as an issue to address and, to some degree, is being addressed. Canada Health Infoway has produced privacy and security requirements in the form of a conceptual architecture and is working with provincial and territorial representatives to address privacy governance issues. Provincial privacy commissioners remain vigilant in the enforcement of health privacy statutes, and RFPs for provincial e-health initiatives show a clear attention to the privacy aspects of such initiatives. The devil, as they say, is in the details, and EHR initiatives, whether in Canada or elsewhere, will need to demonstrate alignment between political objectives of protecting privacy and workable technical and process measures that achieve those requirements while meeting the needs for a more efficient and effective healthcare system.

Michael Power is a Toronto-based legal advisor/consultant on privacy and information risk management issues, serving both public and private-sector clients. Mr. Power writes and speaks extensively on privacy and information security issues and previously served as vice president of privacy and security at eHealth Ontario. He may be reached at


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»