FNHSO Privacy and Security Framework Forum Nov 19, 2014 BC First Nations Panorama Support.

Slides:



Advertisements
Similar presentations
Wait Times Guarantee Pilot A partnership between Saint Elizabeth Health Care and the Assembly of Manitoba Chiefs.
Advertisements

Step by step guide.
From QA to QI: The Kentucky Journey. In the beginning, we were alone and compliance reigned.
Openness and Transparency in Local Governments and Smaller Organizations June 5, 2014.
1. As a Florida KidCare community partner families entrust you to not only help them navigate the Florida KidCare system but to keep the information they.
Topics Rule Changes Skagit County, WA HIPAA Magic Bullet HIPAA Culture of Compliance Foundation to HIPAA Privacy and Security Compliance Security Officer.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Quality Improvement/ Quality Assurance Amelia Broussard, PhD, RN, MPH Christopher Gibbs, JD, MPH.
Data Incident Notification Policies and Procedures Tracy Mitrano Steve Schuster.
Support for those Bereaved and Affected by Suicide Gina Perigo, Public Health Practitioner Liverpool City Council.
Supportive Services for Veteran Families (SSVF) Data Bigger Picture Updated 5/22/14.
Developing a Records & Information Retention & Disposition Program:
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
Title I Needs Assessment and Program Evaluation
Mitun PatelMXP07U. Organisational structure Top management; this includes the organisation’s general manager and its executives Department managers; this.
PM Summit Overview Daniel Vitek MBA, PMP – Consultant to CDC.
ESC/EN Engineering Process Compliance Procedures August 2002.
FPSC Safety, LLC ISO AUDIT.
Development of a Customized First Nations Privacy & Security Toolkit
1 HIPAA Security Overview Centers for Medicare & Medicaid Services (CMS)
8/28/2015 The Family Educational Rights and Privacy Act (FERPA)  Also known as the Buckley Amendment.  Statute: 20 U.S.C. 1232g; Regulations: 34 CFR.
CHAPTER 5 Infrastructure Components PART I. 2 ESGD5125 SEM II 2009/2010 Dr. Samy Abu Naser 2 Learning Objectives: To discuss: The need for SQA procedures.
GTA Shared Assessment Education Shared Assessment Education.
Quick Guide to help your transition
Case Study: Department of Revenue Data Breach National Association of State Auditors, Comptrollers and Treasurers March 21, 2013.
Lecture #9 Project Quality Management Quality Processes- Quality Assurance and Quality Control Ghazala Amin.
MyFloridaMarketPlace Roundtable January 21, :00 a.m. – 12:00 p.m. MyFloridaMarketPlace.
Coordination and Net Working on DRR Rapid Emergency Assessment and Coordination Team (REACT) Bishkek November, 2009.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
Virginia’s Person Centered Planning Process. The Four Phases of Planning Sharing Information Getting ready for planning Planning Together Keeping Track.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
On Site Review Process Office of Field Services Last Revised 8/15/2011.
New Regulations: Questions and Answers Infant & Toddler Connection of Virginia Statewide Meeting September 25,
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
Copyright © Emerson Strategic Group, Inc. All Rights Reserved 1 Ninth National HIPAA Summit Auditing for Privacy Compliance: A Case Study September.
Publication Schemes Natasha Bodden Freedom of Information Unit November, 2009.
1 Monitoring/Evaluation Program Overview December 3, 2008 Title III Director’s Meeting.
CHMRAT Roll Out th February 2013 Practice Support and Development Officer GNC.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
Tripartite Declaration of Principles concerning Multinational Enterprises and Social Policy (MNE Declaration) Multinational enterprises and social policy.
CONFIDENTIALITY. Three Confidentiality Laws 1.FERPA-Family Education Rights and Privacy Act (State Policy 4350: Procedures for the Collection, Maintenance.
FNHSO Privacy and Security Framework Forum Mar 15, 2016 BC First Nations Panorama Support.
FNHSO PANORAMA DATA GOVERNANCE FORUM Kick-off Meeting July 8, 2014.
FNHSO Privacy and Security Framework Forum Feb 16, 2016 BC First Nations Panorama Support.
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting April 12, 2016.
Software Engineering Process - II 7.1 Unit 7: Quality Management Software Engineering Process - II.
FNHSO Privacy and Security Framework Forum Jan 19, 2016 BC First Nations Panorama Support.
FNHSO Privacy and Security Framework Forum June 16, 2015 BC First Nations Panorama Support.
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting December 8, 2015.
Welcome to Workforce 3 One U.S. Department of Labor Employment and Training Administration Webinar Date: Thursday, October 23, 2014 Presented by: Division.
FNHSO Privacy and Security Framework Forum October 15, 2014 BC First Nations Panorama Support.
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting March 8, 2016.
FNHSO Panorama Data Governance Forum
Module 4: Structuring the District Implementation Team for Success
FNHSO Privacy and Security Framework Forum Jan 19, 2016
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Privacy and Security Framework Forum Sept 20, 2016
FNHSO Panorama Data Governance Forum
FNHSO Privacy and Security Framework Forum April 16, 2014
How we’ll prepare for the General Data Protection Regulation (GDPR)
Supporting SEACs across the Province:
GDPR Session
HUD’s Coordinated Entry Data & Management Guide
Audit.
Planning Services Meeting Client Communications
Compliance Manual Update Staff Requirements Check
Presentation transcript:

FNHSO Privacy and Security Framework Forum Nov 19, 2014 BC First Nations Panorama Support

Agenda  Roll-call  Panorama Access Audit – Update on Privacy Reports being developed to support audit requirements  Client Personal Information Collection  Updates to Client / Guardian Notification and Consent Policy  Updates to Breach Management Procedures  ISA Compliance  Round table discussion FNSHO P&S Framework Forum

Roll Call  Kwakiutl District Council Health Services  Seabird Island Band's Health Services Department  Three Corners Health Services Society  Tla’amin Community Health Services  Westbank First Nation Health and Wellness  Saulteau First Nation Health Services  Nuu-chah-nulth Tribal Council – Community and Human Services  Okanagan Indian Band Health Services  Cowichan Tribes - Ts’ewulhtun Health Services FNSHO P&S Framework Forum

Access Audit Requirements  Identified in  B.C. Ministry of Health eHealth conformance Standards – Information Privacy  ISA  eHeath Best Practices  Panorama Data Governance Framework  Require each organization to conduct  Regular proactive audits  Random audits or spot checks  Reactive audits FNSHO P&S Framework Forum

Update on Privacy Reports to Support Access Audit Requirements FNSHO P&S Framework Forum

Same Name Lookup (AA005)  Purpose  Identify users who have accessed their record or a record of a family member with the same last name FNSHO P&S Framework Forum

High Volume Client Accesses All Users (AA006)  Purpose  Identify clients with an unusually high number of accesses relative to other clients accessed within the same date range and JORG FNSHO P&S Framework Forum

AA007 High Volume Client Accesses Unique Users  Purpose  Identify clients with an unusually high number of unique user accesses relative to other clients accessed within the same date range and JORG FNSHO P&S Framework Forum

AA008 High Volume User Accesses Unique Clients  Purpose  Identify users with an unusually high number of unique client accesses relative to other user access within the same date range and JORG FNSHO P&S Framework Forum

Client Personal Information Collection FNSHO P&S Framework Forum  Three modes of collecting personal information from clients  In person  Home-visits  On the phone  Informed, implied consent for the collection, user and disclosure of personal information  Verbal  Posters  Pamphlets  Telephone Scripts

Updates to Client / Guardian Notification and Consent Policy  Client/Guardian Notification and Consent Policy:  Update to include collection of personal information over the telephone  Appendix Tool: Telephone Privacy Script FNSHO P&S Framework Forum

Updates to Privacy Breach Management Procedures  Procedures specific to Panorama breaches  Contact Panorama Operations Privacy Services and Central Data Steward FNSHO P&S Framework Forum

Panorama Data Governance Committee: ISA Compliance FNSHO P&S Framework Forum

ISA Compliance Options (1) 1. Invoke clause 12.2 of the Panorama ISA and request each Party provide the Central Data Steward with a copy of its most recent (within the previous month) audit and privacy and security review reports. 2. Invoke clause 12.1 of the Panorama ISA with the Central Data Steward conducting audits on the privacy and security practices of all Parties.

ISA Compliance Options (2) 3. Development of a simplified standard assessment template for Parties to assess their own compliance to certain key requirements. The template would be used by each Party to report their level of compliance to the Panorama Data Governance Committee immediately and then on an annual basis going forward. 4. Addressing the issues of non-compliance on a case-by-case basis, with the Central Data Steward working with a Party to resolve a specific issue.

ISA Compliance Options (3)  Option 3 is being recommended  Overall, the compliance approach being described seems to be well aligned with the eHealth Conformance Standards compliance model followed by FN PIP and FNHSOs implementing Panorama  The “assessment template” described for option 3 is similar in concept and content to the FN PIP “P&S Checklist”  More frequent, structured assessment and reporting to MoH may be necessary  The FN PIP team will continue to provide info on this topic as it becomes available

Roundtable Review  Any changes to Panorama users (add/remove) ?  Questions or concerns?  Agenda items for next meeting? FNSHO P&S Framework Forum