Health Information Act
HIA requires custodians (either named healthcare organizations or named professions in the Health Information Regulation) and affiliates (employees, volunteers, contractors and authorized staff who work for a custodian) to only collect, use and disclose health information in the most limited manner, with the highest degree of anonymity possible and only on a need-to-know basis.
- A training session, “HIA for Alberta Netcare Users,” can be found here.
- View the Roles & Responsibilities Quick Reference to learn more on how the HIA affects you as an Alberta Netcare user.
What is the Alberta Netcare Electronic Health Record (EHR)?
Can any healthcare provider access an individual's EHR?
- Authorized healthcare providers are asked for their unique username and password every time they access Alberta Netcare.
- The security controls utilized for the Alberta Netcare EHR are based on legislative requirements, security industry best-practices and standards of practice.
- Any access to the Alberta Netcare EHR is logged to an access log. These logs are audited monthly.
- Anyone who knowingly collects, uses or discloses health information inappropriately could be subject to fines and disciplinary measures.
Who is an authorized healthcare provider?
How do I know if a patient's EHR is masked?
What is HIA?
The provincial Health Information Act (HIA) establishes the rules that must be followed for the collection, use, disclosure and protection of health information. It balances the protection of privacy with enabling health information to be shared where appropriate. The HIA sets out the rules that help to protect individuals’ privacy through Alberta Netcare Masking.
Who is a custodian?
- Alberta Health and the Minister of Health
- Alberta Health Services
- Covenant Health
- Health Quality Council of Alberta
- Ambulance operators
- Nursing home operators
- Regulated members of health professions designated in the HIA
- Individuals or boards, councils, committees, commissions, panels, agencies, corporations or other entities designated in the Health Information Regulation
Refer to section 1(1)(a) in the HIA and section 2 in the Health Information Regulation for the complete definition and listing of designated custodians.
Who is an affiliate?
In relation to a custodian, the HIA defines "affiliate" as the following:
- an individual employed by the custodian
- a person who performs a service for the custodian as an appointee, volunteer or student or under a contract or agency relationship with the custodian
- a health services provider who is exercising the right to admit and treat patients at a hospital
- an information manager (e.g. your Electronic Medical Record or Pharmacy Management System vendor, or your document storage and shredding providers.)
Refer to sections 1(1)(a) and 1(3) in the HIA for the complete definition.
Who is an authorized custodian?
- establish and adopt privacy and security policies as required by section 63 of the HIA
- prepare and submit a Privacy Impact Assessment to the Information and Privacy Commissioner regarding their use of Alberta Netcare
- complete a Provincial Organizational Readiness Assessment with Alberta Health
- enter into an Information Manager Agreement with Alberta Health regarding their participation in Alberta Netcare
- receive Alberta Health's approval to access Alberta Netcare
Refer to section 3 in the Alberta Electronic Health Records Regulation for the complete authorized custodian requirements.
Currently, members of the following regulated health professions are eligible to become authorized custodians:
- College of Chiropractors of Alberta (CCOA)
- The Alberta College of Optometrists (ACO)
- The Alberta College of Pharmacy (ACP)
- The College of Dental surgeon of Alberta (CDSA)
- College of Registered Nurses of Alberta (CRNA)
- College of Physicians and Surgeons of Alberta (CPSA)
Alberta Health may add health professions to this listing in the future. If your profession is not listed, contact your health professional college for more information.