Ontario Health
Ontario Clinical Report Exchange Implementation Guide v1.0.0 - Trial Use
fhir-logo
  • Index
  • Home
    • Home
    • Introduction
    • Relationship to Other Specifications
    • Scope
    • Glossary
  • Business Context
    • Business Context
    • Business Model
    • Business Data
    • Use Cases
    • Business Rules
  • Technical Context
    • Technical Context
    • Implementer Responsibility
    • Conformance Rules
    • Connectivity Summary
  • FHIR Artifacts
    • FHIR Artifacts
    • Interactions
    • Profiles
    • Extensions
    • Terminology
    • System URIs
    • Examples
    • Capability Statement
    • Response Handling
    • Downloads
  • Change Log
    • Change Log
    • Known Issues & Future Developments
    • Revision History
    1. Index
    2. Technical Context
    3. Implementer Responsibility

For a full list of available versions, see the Directory of published versions

3.1. Implementer Responsibility

3.1.1. Privacy and Security

Prior to implementing this specification, an organization shall complete security and privacy risk assessments and address the recommendations of those assessments. Care should be taken to ensure the confidentiality and integrity of Personal Health Information in transit and at rest can be maintained at a level that is appropriate.

The information which systems receive when submitting/receiving OCRE data is considered Personal Information (PI) and Personal Health Information (PHI) within the meaning of PHIPA. Access to personal health information must be restricted to Health Information Custodian (HIC) or an agent acting on behalf of the HIC and collected, used or disclosed on a need-to-know basis, as specified in data sharing agreements and legislation, including PHIPA.​ Furthermore, Health Information Custodian (HIC) or an agent acting on behalf of the HIC must consider if personal health information is necessary for the purposes of exchanging data with OCRE solution. If personal health information is necessary, Health Information Custodian (HIC) or an agent acting on behalf of the HIC must consider how much personal health information is reasonably necessary for the purpose of exchanging data with OCRE solution. Under PHIPA, Health Information Custodian (HIC) or an agent acting on behalf of the HIC must not collect, use or disclose personal health information if other information will serve the purpose or collect, use or disclose more personal health information that is reasonably necessary to meet the purpose, among other requirements.

As a result, access to the health patient information must be restricted as specified in data-sharing agreements and corresponding legislation.

Enforcement of Consent Directives
The point of service systems (e.g. EMRs, etc.) will subscribe to OH Pub/Sub services to receive OCRE reports. Ontario Health operates the Publish/Subscribe (Pub/Sub) service in the role of a Health Information Network Provider (HINP) under PHIPA s. 17. The Pub/Sub Service does not make disclosure decisions. The OCRE data contributor is the Health Information Custodian responsible for the patient’s personal health information and MUST enforce consent directives and masking prior to submitting data to OCRE.


3.1.2. User Credentials

To support all instances where personal health information is collected, used, and disclosed, user credential information identifying either the initiating user or the initiating system SHALL be included in each data transfer between the source and target systems. This information is required for audit and logging purposes and for message processing.

When a request is initiated by an authenticated end user, the user’s credential information SHALL be supplied. When a request is initiated by a system-to-system interaction (with no PHI disclosure to an individual user) the system-level credential or service identity SHALL be supplied instead. Refer to the Connectivity section for further details.


3.1.4. Auditing

The PoS must audit user-initiated activities such as HTTP GET or POST requests. Audit logs are maintained by the PoS System to audit PHI disclosure to their end users. PoS systems must audit PHI disclosure to their end users.


3.1.5. Logging

The PoS System must log all user-initiated or system-initiated activities such as HTTP GET or POST requests.

  • Both sending and receiving systems using OCRE solution MUST log all activity performed via the API.
  • When a system submits data to OCRE solution, the system MUST include the requester information in the submission.
  • When a system receives data from OCRE solution, it must log the notification of receiving data from OCRE.

Furthermore:

  • Application logs are tracked by the PoS System for activities performed by the system. PHI must not be stored in application log files.
  • Access logs are tracked by the PoS System when the user accesses the PoS System. PI may be stored in access logs.
  • Application logs should log the API request/response HTTP responses codes and operational outcome.

All of the above logs are retained in accordance with the HIC’s obligation as defined by applicable PHIPA agreements or other agreements with Ontario Health.


Version: 1.0.0 FHIR Version: R4.0.1

Powered by SIMPLIFIER.NET

HL7® and FHIR® are the registered trademarks of Health Level Seven International