{"id":28813,"date":"2021-11-18T12:30:17","date_gmt":"2021-11-18T12:30:17","guid":{"rendered":"https:\/\/www.syscreations.ca\/blog\/?p=28813"},"modified":"2021-11-18T12:30:18","modified_gmt":"2021-11-18T12:30:18","slug":"phipa-for-healthcare-apps","status":"publish","type":"post","link":"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/","title":{"rendered":"PHIPA Compliance for Healthcare Mobile Apps: Clear Your all Doubts with Our PHIPA Experts"},"content":{"rendered":"\n<p>This blog is for those who own a healthcare mobile app or plan to build one but have doubts regarding PHIPA compliance.&nbsp;<\/p>\n\n\n\n<p>You can expect to learn more about PHIPA rules and regulations which may apply to your healthcare app.&nbsp;<\/p>\n\n\n\n<p>And if you still cannot figure it out, you can hire our PHIPA compliance experts who have been dealing with healthcare compliance for more than 7 years.&nbsp;<\/p>\n\n\n\n<p>So, let\u2019s start.&nbsp;<\/p>\n\n\n\n<h1><strong>Frequently asked questions around PHIPA compliance for healthcare mobile apps&nbsp;<\/strong><\/h1>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">1) Does PHIPA apply to my healthcare mobile app?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>PHIPA is the dedicated healthcare-specific privacy law imposed by the Ontario provincial government.&nbsp;<\/p>\n\n\n\n<p>So, it does apply to your healthcare mobile app in major two conditions.&nbsp;<\/p>\n\n\n\n<ul><li>If your healthcare app collects, stores and shares personal as well as medical information of patients.&nbsp;<\/li><li>And if your healthcare app is available in Ontario.&nbsp;<\/li><\/ul>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">2) How does PHIPA affect my healthcare mobile app?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>Well, the motive of PHIPA is to establish rules and regulations for the collection, use and disclosure of personal information of patients.&nbsp;<\/p>\n\n\n\n<p>It sets out the rules which define in which conditions you can save, use and share patient data and which are the privacy measures you must put in place to ensure data privacy and security.&nbsp;<\/p>\n\n\n\n<p>So, if you follow all the regulations of PHIPA, you end up making your healthcare mobile app most private and secure.&nbsp;<\/p>\n\n\n\n<p>But if you practice non-compliance, you would become liable for a hefty fine by the privacy commissioner.&nbsp;<\/p>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">3) What rights do my app users have under PHIPA?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<ul><li>You need to inform them of the purpose for which you are collecting, storing and sharing their personal health data.&nbsp;<\/li><li>You have to notify them in the case of stolen and lost data. You also need to notify them if any unauthorized person gets access to their data.&nbsp;<\/li><li>They can refuse to give you consent for storing, using and sharing their personal health data.&nbsp;<\/li><li>They can withdraw the consent.&nbsp;<\/li><li>They can ask you to provide a copy of their personal health information.&nbsp;<\/li><li>They can request you to make corrections to their data.&nbsp;<\/li><\/ul>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">4) Which types of patient data my app must handle with regard to the PHIPA act?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>PHIPA clearly states that any \u2018identifying information\u2019 about an individual is protected under the act. This identifying information includes,&nbsp;<\/p>\n\n\n\n<ul><li>Any data related to patients physical and mental condition&nbsp;<\/li><li>Any data related to medical history of patients\u2019 family&nbsp;<\/li><li>Any data related to patients\u2019 eligibility for healthcare or for coverage for healthcare<\/li><li>Patients\u2019 health number&nbsp;<\/li><li>Healthcare provider or a substitute decision-maker of a patient&nbsp;<\/li><\/ul>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">5) How long does my healthcare app need to keep personal data of patients?\u00a0<\/span><\/strong><\/p>\n\n\n\n<p>PHIPA requires you to keep patient data in such a manner that you are able to provide data back to the patients if they ask for it &#8211; anytime.&nbsp;<\/p>\n\n\n\n<p>However, PHIPA does not include any specific years for how long you must keep patient data. Thus, you must refer to your governing legislation to know applicable record retention requirements.&nbsp;<\/p>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">6) What do I have to keep in mind if I need to collect, use and share the data of my users?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>Well, you can surely store, use and share the personal data of your users &#8211; but under some conditions.&nbsp;<\/p>\n\n\n\n<p>The most important condition is you must obtain the consent of users before handling their data.&nbsp;<\/p>\n\n\n\n<p>PHIPA also defines 4 major characteristics of consent.&nbsp;<\/p>\n\n\n\n<ul><li>It must be knowledgeable<\/li><li>It must be voluntary&nbsp;<\/li><li>It must be related to the information in question&nbsp;<\/li><li>It must be given by individual&nbsp;&nbsp;<\/li><\/ul>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">7) How must my healthcare app use the personal healthcare data of patients?\u00a0<\/span><\/strong><\/p>\n\n\n\n<p>Your healthcare app must address these 3 conditions to use data legally.&nbsp;<\/p>\n\n\n\n<ul><li>It must ask for patients\u2019 consent before using their data.&nbsp;<\/li><li>It must not use any data of patients if some other data serve the same purpose.&nbsp;<\/li><li>You need to use data only if there is a valid purpose behind it.&nbsp;<\/li><li>It must ensure that patient data is complete, accurate and up-to-date as is necessary for the purposes.&nbsp;<\/li><\/ul>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">8) Do I need to save, use and share patient data only in Ontario or Canada?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>No, PHIPA does not make it mandatory to save, use and share patient data only in Ontario or Canada.&nbsp;<\/p>\n\n\n\n<p>You can store, use and share it even outside of Ontario and Canada. But you must ensure there are administrative and technical safeguards in place &#8211; wherever patient data is stored.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">9) Is PIA (Privacy Impact Assessment) mandatory under PHIPA?<\/span> <\/strong>\u00a0<\/p>\n\n\n\n<p>PIA reveals all privacy vulnerabilities an entire organization has. Under HIA (Health Information Act of Alberta), it is mandatory.&nbsp;<\/p>\n\n\n\n<p>But talking about PHIPA, PIA is not mandatory. However, we would suggest you carry out PIA to eliminate the last-possible privacy vulnerability out of your entire organization.&nbsp;<\/p>\n\n\n\n<p><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\">10) What if I don\u2019t build a PHIPA-compliant healthcare app in Ontario?<\/span>\u00a0<\/strong><\/p>\n\n\n\n<p>If you commit an offence under PHIPA, you as an organization or startup can be liable for a fine of up to $250,000.&nbsp;<\/p>\n\n\n\n<p>And in some cases, you may be subject to a civil suit for damages for breach of privacy.<\/p>\n\n\n\n<h2><strong>One lesson we\u2019ve learned in our 7+ years of practice as PHIPA experts in Ontario&nbsp;&nbsp;<\/strong><\/h2>\n\n\n\n<p><em>\u201cHealthcare compliance isn\u2019t a choice. IT IS THE ONLY CHOICE! Because Canadians are serious about data privacy and security. And the government is even more.\u201d\u00a0<\/em><\/p>\n\n\n\n<p>So, for your understanding of how we help you be compliant with applicable healthcare privacy laws (HIPAA, PHIPA, PIPEDA, HIA or anything), let us share two real case studies.&nbsp;<\/p>\n\n\n\n<p><strong>Case study 1: <\/strong><a href=\"https:\/\/www.syscreations.ca\/healthcare-app-regulations-canada\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\"><u>How we made a healthcare app compliant with HIPAA?<\/u><\/span><\/strong><\/a><strong>&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>Case study 2: <\/strong><a href=\"https:\/\/www.syscreations.ca\/how-to-execute-pia\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><span style=\"color:#7b68ee\" class=\"has-inline-color\"><u>How did we execute PIA on a healthcare project?<\/u><\/span><\/strong><\/a><strong>&nbsp;<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog is for those who own a healthcare mobile app or plan to build one but have doubts regarding PHIPA compliance.&nbsp; You can expect to learn more about PHIPA rules and regulations which may apply to your healthcare app.&nbsp; And if you still cannot figure it out, you can hire our PHIPA compliance experts [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":28817,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[12],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.1.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>PHIPA Compliance for Healthcare Mobile Apps: Top 10 FAQs<\/title>\n<meta name=\"description\" content=\"Wondering what it takes to make your healthcare app compliant with PHIPA? Check out our top 10 FAQs on PHIPA compliance for healthcare mobile apps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PHIPA Compliance for Healthcare Mobile Apps: Top 10 FAQs\" \/>\n<meta property=\"og:description\" content=\"Wondering what it takes to make your healthcare app compliant with PHIPA? Check out our top 10 FAQs on PHIPA compliance for healthcare mobile apps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\" \/>\n<meta property=\"og:site_name\" content=\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-18T12:30:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-18T12:30:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2021\/11\/Blog-Image-59.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data1\" content=\"5 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"description\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.syscreations.ca\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2021\/11\/Blog-Image-59.jpg\",\"contentUrl\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2021\/11\/Blog-Image-59.jpg\",\"width\":1280,\"height\":720},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/#webpage\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\",\"name\":\"PHIPA Compliance for Healthcare Mobile Apps: Top 10 FAQs\",\"isPartOf\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/#primaryimage\"},\"datePublished\":\"2021-11-18T12:30:17+00:00\",\"dateModified\":\"2021-11-18T12:30:18+00:00\",\"author\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/c09c2823449c6b5e7b11fd98b3897f9a\"},\"description\":\"Wondering what it takes to make your healthcare app compliant with PHIPA? Check out our top 10 FAQs on PHIPA compliance for healthcare mobile apps.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/phipa-for-healthcare-apps\/\",\"name\":\"PHIPA Compliance for Healthcare Mobile Apps: Clear Your all Doubts with Our PHIPA Experts\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/c09c2823449c6b5e7b11fd98b3897f9a\",\"name\":\"Parth Patel\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e69b7008ca1aaee24496ae0be968f8af?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e69b7008ca1aaee24496ae0be968f8af?s=96&d=mm&r=g\",\"caption\":\"Parth Patel\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/28813"}],"collection":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/comments?post=28813"}],"version-history":[{"count":4,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/28813\/revisions"}],"predecessor-version":[{"id":28818,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/28813\/revisions\/28818"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media\/28817"}],"wp:attachment":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media?parent=28813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/categories?post=28813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/tags?post=28813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}