Privacy Checklist

Share

Test Your Privacy Knowledge

Check all that apply to you, then calculate your score at the end.

Score Yourself:

  • ✔ 20 to 22 checks = Privacy Pro
  • ✔ 15 to 19 checks = Privacy Aware (needs some improvement)
  • ✔ Less than 15 checks = Privacy Risk
    (review policies and training as soon as possible)

1. Understanding Your Role

  • I know whether I am acting as an agent or a health information custodian under the Personal Health Information Protection Act (PHIPA).
  • I understand my legal responsibilities for protecting personal health information (PHI).

2. Handling Patient Information

  • I only access personal health information when necessary for patient care.
  • I never share personal health information unless authorized and required for treatment.
  • I confirm patient identity before virtual or phone consultations.

3. Secure Communication

  • I use encrypted email or secure messaging platforms approved by my organization.
  • I avoid sending personal health information through regular email or text unless the patient gave consent and safeguards are in place.
  • I do not discuss patient details in public or open spaces.

4. Device and Workspace Security

  • I lock my computer when stepping away.
  • I use strong passwords and never share them.
  • I store paper records in locked cabinets when not in use.

5. Breach Awareness

  • I know what constitutes a privacy breach.
  • I report any suspected breach immediately to the health information custodian.
  • I understand my organization’s breach response process.

6. Training and Policies

  • I have completed privacy training in the last 12 months.
  • I have signed a confidentiality agreement.
  • I know where to find my organization’s privacy policies and procedures.

7. Patient Rights

  • I understand how patients can request access or corrections to their records.
  • I know who to direct patients to for privacy questions or complaints.

8. Best Practice Habits

  • I minimize the disclosure of personal health information and only share what’s necessary.
  • I regularly review privacy updates and refresh my knowledge.
  • I use secure platforms for virtual care and always get the patient’s consent.