CA Core+ v1.1.0 DFT-preBallot
DFT-preBallot - The specification is a DFT-preBallot version of CA Core+ for collecting community feedback. For a full list of available versions, see the Directory of published versions
This section outlines privacy and security considerations for implementations using CA Core+. It draws on existing national and international best practices, including guidance from Infoway, HL7 International, and other pan-Canadian initiatives. This guidance is informative and does not relieve implementers of their obligations to comply with jurisdictional and organizational policies, laws, and standards.
CA Core+ implementers are expected to consider privacy and security throughout the lifecycle of their applications—from design to deployment and operation. Privacy and security requirements vary by jurisdiction, and developers must align their safeguards, consent mechanisms, and data handling procedures accordingly. For more guidance on implementing security in the Canadian context visit CA:Sec in the Canadian Reference Architecture.
Privacy is foundational when exchanging patient data. Implementers must:
Note: Each jurisdiction in Canada has its own privacy regulations. Implementers must ensure that deployments comply with the applicable laws and standards in the jurisdiction where the system is used.