Download presentation
Presentation is loading. Please wait.
Published byHugo Norman Modified over 8 years ago
1
FNHSO Privacy and Security Framework Forum Mar 15, 2016 BC First Nations Panorama Support
2
Agenda Roll-call General Updates Access Audit Model Round table discussion FNHSO P&S Framework Forum
3
Roll Call Kwakiutl District Council Health Services Seabird Island Band's Health Services Department Three Corners Health Services Society Tla’amin Community Health Services Westbank First Nation Health and Wellness Saulteau First Nation Health Services Nuu-chah-nulth Tribal Council – Community and Human Services Okanagan Indian Band Health Services Cowichan Tribes - Ts’ewulhtun Health Services Scw’exmx Community Health Service Society Inter Tribal Health Authority Pauquachin Health Centre Nazko Health Simpcw First Nation Nak’azdli Health Centre Ktunaxa Nation Council – Health Services Splatsin Health Services Sto:lo Service Agency Health FNHSO P&S Framework Forum
4
Context: Panorama Access Audit Program Objectives Establish a robust access audit program that complies with the Panorama Access Audit requirements and includes the data in Panorama that is included in their local systems (e.g. Mustimuhw) Identify best practices for conducting user access audits in local systems (e.g. Mustimuhw) Address the different service models: Nurse works on their own or in a small community setting Nurse works as part of a medium to large health program delivery team Multiple sites within FNHSO Define roles, responsibilities, processes, timelines, including escalation and disciplinary processes Build capacity to support sustainability 4 FNHSO P&S Framework Forum
5
5 Staged Approach to Establish Access Audit Program Period 1 Validate & Refine Stage 1: Initial Audit Process Stage 0: Define Audit Program: Stages, RnR, etc. Validate & Refine Stage 2: Data Quality Audits Period 2Period 3 Validate & Refine Stage 3: Pattern-based Audits Validate & Refine Stage 4: Comprehensive Audit Program Period 4 5 FNHSO P&S Framework Forum
6
6 Period 1 2. Define Procedures / Forms Stage 1Activities 1. Define Stage Objectives & Process 3. Validate Process / Procedures Period 2Period 3 4. Refine Policy / Process / Procedures Based on Lessons Learned 5. Refine Approach For Remaining Stages Based on Lessons Learned Period 4 6 Period 5 FNHSO P&S Framework Forum
7
Define Stage 1 Objectives √ Objectives established : Develop capacity to: Respond to user access complaints (reactive audit) Inactivate user accounts that are not being used Identify users that have accessed their own record or records of a family member with the same last name when not providing services Monitor access to special clients 7 FNHSO P&S Framework Forum
8
8 Define Stage 1 Process Flow 8 Process defined √Respond to access complaints (reactive audit) √Inactivate user accounts that are not being used √Identify users that have accessed their own record or records of a family member with the same last name when not providing services Process topics for today: Monitor access to special clients FNHSO P&S Framework Forum
9
We are looking for an approach to fulfill proactive audit requirements in a sustainable manner Panorama is used for Immunizations and TB as of March 14. STI/HIV access planned for this summer (date TBC) Number of users with access to Panorama varies by FNHSO; typically FNHSO has more Mustimuhw users than Panorama users In Panorama, every user has access to all clients in the system to support the client’s ability to receive service at any health centre in either BC or Yukon In Mustimuhw, users can be restricted to only those clients that the user provides care; however in some FNHSOs nurses and clerical staff have access to all clients FNHSO P&S Framework Forum Context: Proactive Auditing
10
Based on the discussion in the meeting, it was decided to take a different approach to address the proactive auditing requirements Approach: Health Director/Data Steward/Privacy Officer in consultation with Panorama/Mustimuhw champions & Nursing Manager/Supervisor collaboratively decide the approach for proactive audits that best suits their organization, size of user community, and audit capacity Proactive audits would be based on one or more of the following: Audit specific users to ensure they were accessing the system appropriately Audit specific clients to ensure that access to these clients was appropriate Audit groups of users to ensure they were accessing the system appropriately(e.g. 25% of users every quarter) FNHSO P&S Framework Forum Proactive Audit Recommendation
11
Proactive Audit Process Investigation Process: Execute Panorama report showing user activity against a specific client, or specific clients a user accessed Review access to identify possible inappropriate activity If warranted, review activity with user, user’s manager/supervisor If access is confirmed to be inappropriate, determine disciplinary actions (e.g. Privacy refresher, review the Confidentiality and Acceptable Use Agreement) If warranted Initiate Breach Management process or complete disciplinary actions FNHSO P&S Framework Forum
12
12 Period 1 2. Define Procedures / Forms Define Stage 1 Procedures & Forms 1. Define Stage Objectives & Process 3. Validate Process / Procedures Period 2Period 3 4. Refine Policy / Process / Procedures Based on Lessons Learned 5. Refine Approach For Remaining Stages Based on Lessons Learned Period 4 12 Period 5 FNHSO P&S Framework Forum
13
What Forms are Required? Stage 1 AuditsForms (others)?Comments 1.Respond to access complaints (reactive audit) Complaint formLeverage Info Request form – Mildred may have a form we can leverage as well Manager review formProvides steps to address both appropriate and inappropriate access Complainant Response Letter Identifies outcome of the review and appeal process Complaint Tracking requirements Identifies the logging requirements, supporting materials that are kept in a restricted area, etc. ReportingIncludes requirements for: FNHSO Annual Reporting OIPC Reporting FNHSO P&S Framework Forum
14
Roundtable Review Any changes to Panorama users (add/remove) ? Questions or concerns? Agenda items for next meeting? Deferred to a later meeting: Mildred: are you available to provide a review of Mustimuhw access audit process? FNHSO P&S Framework Forum
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.