vanessa halter - nehta - national e-health transition authority - privacy & confidentiality in...

14
National E-Health Transition Authority www.nehta.gov.au 1 Privacy & Confidentiality in Health: Digital Records eMedication Management Conference 15 March 2016 Vanessa Halter, CIPM Senior Privacy and eHealth Compliance Advisor

Upload: informa-australia

Post on 14-Apr-2017

379 views

Category:

Health & Medicine


1 download

TRANSCRIPT

Page 1: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

National E-Health Transition Authority www.nehta.gov.au1

Privacy & Confidentiality in Health:

Digital Records

eMedication Management Conference

15 March 2016

Vanessa Halter, CIPMSenior Privacy and eHealth Compliance Advisor

Page 2: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

2 National E-Health Transition Authority www.nehta.gov.au

What does ‘privacy’ mean to you?

Like Love Haha Yay Wow Sad Angry

Page 3: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

3 National E-Health Transition Authority www.nehta.gov.au

The potential for sharing health and information is a huge driver to implement eHealth.

However, increased availability does mean increased potential for privacy and

confidentiality breaches.

Previous attendees have raised …

Page 4: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

4 National E-Health Transition Authority www.nehta.gov.au

Page 5: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

5 National E-Health Transition Authority www.nehta.gov.au

Page 6: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

6 National E-Health Transition Authority www.nehta.gov.au

Business case for privacy

Ethical and professional obligations:

Accreditation/registration

Integrity of the health system:

strong privacy will promote confidence in

healthcare services

Reputational damage:

for you and your patients

Legislative obligations: Australian Privacy

Principles

Page 7: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

7 National E-Health Transition Authority www.nehta.gov.au

Privacy champion

Knows the business

Knows privacy

Builds privacy into design, policy and process

Page 8: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

8 National E-Health Transition Authority www.nehta.gov.au

Collection

Use

StorageDisclosure

Destruction

Assess -> Address -> Monitor

Page 9: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

9 National E-Health Transition Authority www.nehta.gov.au

Assess -> Address -> Monitor

• Who can access it?

• Is the information backed up/disaster recovery?

• Is it stored ‘securely’?

• Physical and technical controls

• What are the data breach/incident procedures?

Page 10: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

10 National E-Health Transition Authority www.nehta.gov.au

Staff training

Staff can be your biggest asset but potentially your biggest privacy risk…

Training should be about empowering staff to confidently and competently uphold privacy

Training as part of

induction, and ongoing ‘refresher’

Content should be relevant to

the business

Keep a record as part of

employment files

Page 11: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

11 National E-Health Transition Authority www.nehta.gov.auApollo 13, n.d. film photograph, viewed 7 March 2016<http://www.ncregister.com/images/uploads/apollo-13.jpg>

Page 12: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

12 National E-Health Transition Authority www.nehta.gov.au

Privacy take homes

• Houston

• We

• Have

• A

• Problem

Page 13: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

13 National E-Health Transition Authority www.nehta.gov.au

Privacy take homes

• H

• W

• H

• A

• P

andling privacy across entire patient journey

hy you should care: Business Case for privacy

ave a Privacy Champion

ssess > Address > Monitor your privacy risks

rivacy training

Page 14: Vanessa Halter - nehta - National E-Health Transition Authority - Privacy & Confidentiality in Health: Digital Records

14 National E-Health Transition Authority www.nehta.gov.au

[email protected]

1300 901 001

Vanessa Halter, CIPMSenior Privacy and eHealth Compliance [email protected]