The Health Information Act (HIA) strikes a balance between the protection of privacy and enabling the appropriate amount of information sharing to provide health services and manage the health system.
You have rights under the HIA –
- You have a right to access a copy of your health information held by a custodian, subject to specific and limited exemptions.
- You have the right to request a correction or amendment of your health information held by a custodian.
- The HIA protects your health information and governs the collection, use and disclosure of that information.
- You have a right to know why your health information is being collected, used and disclosed.
- You have the right to make an expressed wish regarding the disclosure of your health information. A custodian is required to consider your concerns before disclosing your health information.
- You have a right to request an independent review of decisions made by a custodian regarding access to your information or a correction or amendment to your health information, within 60 days of being notified of the decision.
Request to Access Health Information form (PDF, 1 MB)
Consent for Disclosure form – Section 34 (PDF, 16 KB)
Notification to Alberta’s Minister of Health form (PDF, 175 KB)
HIA Appendix 1 and 2 – Forms and Model letters (PDF, 388 KB)
HIA Appendix 3 and 4 – Responsibilities and Components (PDF, 315 KB)
HIA Guideline Chapter 14 – Duty to Notify August 2018
Custodians and affiliates
A custodian is an organization or entity defined in section 1(1)(f) of the HIA or designated in section 2 of the Health Information Regulation. Examples of custodians include physicians, chiropractors, nurses, Alberta Health Services and Alberta Health.
An affiliate, as defined by section 1(1)(a) of the HIA, is an individual or organization employed by a custodian, or a person or entity that performs a service for a custodian as an appointee, volunteer or student, or under a contract or agency relationship with the custodian. Examples of affiliates include a receptionist or records clerk in a physician’s office, or a nurse working for Alberta Health Services.
Mandatory breach reporting
The HIA requires a custodian to, as soon as practicable, give notice in accordance with the regulations of a loss of, unauthorized access to, or disclosure of individually identifying health information in the custody or control of the custodian if there is a risk of harm to an individual as a result of the loss or unauthorized access or disclosure.
When the custodian determines that there is a risk of harm due to a breach, notice is to be given in writing to the affected individual(s), the Information and Privacy Commissioner of Alberta, and the Minister of Health.
Section 8.2 of the Health Information Regulation sets out the factors that custodians must consider when determining if the breach created any risk of harm to any individual. The assessment of harm must be done by the custodian.
Alberta’s Information and Privacy Commissioner is an independent officer of the Alberta Legislature who works to protect the information access and privacy rights of all Albertans. The Office of the Information and Privacy Commissioner (OIPC) is the regulator responsible for ensuring custodian and affiliate compliance with the HIA.
The HIA establishes the role and responsibilities of the OIPC. Under the HIA, the OIPC may:
- provide independent review and resolution of requests for review of custodian responses to access to information or correction requests and complaints related to the collection, use, disclosure or retention of health information
- authorize a custodian to disregard a request for access or correction
- investigate any matters relating to the application of the HIA, or in regards to the destruction of records set out in an enactment of Alberta, whether requested or not
- inform the public about the HIA
- investigate any disclosure of information from an affiliate that the affiliate believes is being collected, used or disclosed in contravention of the HIA
- receive comments from the public concerning the administration of the HIA
- engage in or commission a study of anything affecting the achievement of the purposes of the HIA
- comment on the implications for access to health information or for protection of health information of privacy impact assessments submitted to the Commissioner
- comment on the implications for protection of health information of using or disclosing health information for the purpose of performing data matching
- give advice and recommendations of general application to a custodian on matters respecting the rights or obligations of custodians under the HIA
- bring to the attention of a custodian any failure by the custodian to assist applicants in making an access request
- exchange information with an extra-provincial commissioner and enter into information sharing and other agreements with extra-provincial commissioners for the purpose of coordinating activities and handling complaints involving 2 or more jurisdictions
Access to your information
Under the HIA, you have the right of access to your health information that is held by a custodian. To request a copy of your health information, you must submit an access request to the custodian who you believe has custody or control of the information you are looking for. A custodian may require the request to be made in writing, using either the:
- Request to Access Health Information form (PDF, 1 MB) or
- the provider may request you use their own access request form
A custodian may charge a fee of $25 for producing a copy of an individual’s health information. This fee includes the cost of photocopying/printing the first 20 pages of the record, preparing the document, removing information as necessary, and reviewing the record. Additional fees may be charged as outlined in the Schedule found in the Health Information Regulation. This fee can be waived if agreed upon by the custodian.
Within 30 days of receiving your request, the custodian must provide you with access to the record, or notify you of the reason why the request has been refused.
If the custodian refuses to provide access, or refuses to waive fees, you have the right to ask the OIPC to review the custodian’s decision. You must submit your request for review within 60 days of receiving the decision.
You can request records from Alberta Health, through the Freedom of Information and Protection of Privacy Office at 780-422-5111.
Correction or amendments
Under the HIA, you have a right to request a correction or amendment to facts included in your health information. To do this, you must make a request in writing to the custodian who has custody or control of the record. Within 30 days of receiving your request, the custodian must make the correction or amendment, or notify you of the reason why the correction or amendment has been refused.
If the custodian refuses to make the correction, you have 2 options, but cannot do both:
- You have the right to ask the OIPC to review the custodian’s decision. You must submit your request for review within 60 days of receiving the decision. Contact the OIPC at 780-422-6860 or email@example.com .
- You can attach a statement of disagreement to the record in question. A statement of disagreement sets out, in 500 words or less, the requested correction or amendment and the applicant’s reasons for disagreeing with the decision of the custodian. The statement of disagreement must be submitted to the custodian within 30 days after the written notice of refusal has been given to the applicant. The custodian must, if reasonably practicable, attach the statement to the record in question, and provide a copy of the statement of disagreement to any person to whom the custodian has disclosed the record in the year preceding the applicant’s correction or amendment request.
Disclosure of information
Disclosure without consent
The HIA provides limited and specific circumstances where a custodian can disclose your information to a third party without your consent. Some examples include disclosing information:
- to another custodian, for the purpose of providing an individual with health services
- to any person, if the custodian reasonably believes that the disclosure will avert or minimize a risk of harm to the health or safety of a minor, or an imminent danger to any person
- if authorized or required by another enactment of Alberta or Canada, for example, the Public Health Act
- to a police service if the custodian reasonably believes the information relates to the possible commission of an offence under an enactment of Alberta or Canada, for example, the Criminal Code of Canada, and the disclosure will protect the health and safety of Albertans
Disclosure with consent
Except for limited circumstances specified in the HIA, a custodian must get your written consent before releasing information to a third party, such as a family member, lawyer, or insurance company. Consent allows for disclosure to anyone for any purpose, according to the terms of the consent.
- Consent for Disclosure form – Section 34 (PDF, 16 KB)
The HIA does not explicitly speak to records retention. Current retention requirements are set by the organizations named as custodians or by professional colleges of regulated health professions. For questions regarding how long records are to be kept, contact the appropriate organization or professional college. The HIA does require custodians to protect the confidentiality and security of health information (section 60) throughout the entire record lifecycle, including during storage, but does not prescribe the means by which this should be done.
Other legislation may place retention requirements on health information. For example, under the Hospitals Act (section 15(1)), hospitals must retain diagnostic and treatment records for 10 years after the date of discharge, or 2 years after the patient reaches or would have reached the age of 18, whichever is longer.
Fees for transfer of records
The HIA does not establish fees for the transfer of records to another care provider. For questions regarding fees for records transfer, contact the appropriate professional college.
To connect with the HIA help desk:
Attention: Health Information Act Help Desk
P.O. Box 1360, Station Main
Edmonton, AB T5J 2N3