Personal Health Information Regulation
This regulation sets privacy, security, audit, training, disclosure, research, and breach-notification rules for trustees handling personal health information.
- Jurisdiction
- Canada — Manitoba
- Instrument
- Regulation
- Version
- Undated source snapshot
- Language
- en
- Official source
- View official record ↗
Statute overview
About this statute
This page preserves the statute’s identified version, provision structure, official source link, and stored legal text for reading and research.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Personal Health Information Regulation
Showing 1 of 1
- § Verify source ↗
Personal Health Information Regulation
This regulation sets privacy, security, audit, training, disclosure, research, and breach-notification rules for trustees handling personal health information.
Personal Health Information Regulation, M.R. 245/97 The Personal Health Information Act , C.C.S.M. c. P33.5 Regulation 245/97 Registered December 11, 1997 bilingual version (HTML) Table of Contents Section 1 Definitions 1.1 Specified public bodies 1.2 Designation of health professionals 1.3 Designation of health care facilities 1.4 Notice of right to access information 2 Written security policy and procedures 3 Access restrictions and other precautions 4 Additional safeguards for electronic health information systems 5 Authorized access for employees and agents 6 Orientation and training for employees 7 Pledge of confidentiality for employees 8 Audit 8.1 Disclosure for charitable fundraising 8.2 Health research privacy committee 8.3 Members of the health research privacy committee 8.4 Research agreements 8.5 Agreement re health research 8.6 Meaning of "common-law partner" 8.7 Risk of significant harm — factors 8.8 Form and manner of direct notice to individuals 8.9 When indirect notification may be given 9 Coming into force Schedules A Designated Health Care Facilities B Demographic and Eligibility Information Definitions 1 In this regulation, "Act" means The Personal Health Information Act ; («  Loi  ») "agent" , in relation to a trustee, includes, (a) if the trustee is a corporation, an officer or director of the corporation, and (b) a student or volunteer; (« mandataire ») "record of user activity" means a record about access to personal health information maintained on an electronic information system, which identifies the following: (a) individuals whose personal health information has been accessed, (b) persons who accessed personal health information, (c) when personal health information was accessed, (d) the electronic information system or component of the system in which personal health information was accessed, (e) whether personal health information that has been accessed is subsequently disclosed under section 22 of the Act; (« document concernant l'activité des utilisateurs ») "removable electronic storage media" includes diskettes, magnetic tape, CD ROMs, disk drives and laser disks; (« supports électroniques amovibles ») "Research Manitoba" means Research Manitoba, as continued under The Research Manitoba Act ; (« Société Recherche Manitoba ») "use" , in relation to personal health information, includes processing, reproduction, transmission and transportation of information. (« utilisation ») M.R. 64/2003 ; 142/2005 ; 146/2021 Specified public bodies 1.1 The following are specified public bodies for the purpose of clauses 22(2)⁠(h) and (2.1)⁠(d) of the Act: (a) every regional health authority established or continued under The Regional Health Authorities Act ; (b) Shared Health Inc. M.R. 64/2003 ; 70/2004 ; 38/2010 ; 89/2018 Designation of health professionals 1.2 The following classes of persons are designated as health professionals for the purpose of the Act: (a) persons registered or eligible for registration under The Manitoba Institute of Registered Social Workers Incorporation Act ; (b) persons registered or eligible for registration under The Manitoba Speech and Hearing Association Act ; (c) persons registered or eligible for registration with the Massage Therapy Association of Manitoba Inc.; (c.1) persons licensed to operate a business as a massage therapist under the City of Thompson Business Licensing By-Law No. 1677-2002 or any other municipal by-law of similar intent; (d) persons certified or eligible for certification as orthotists by the Canadian Board of Certification of Prosthetists and Orthotists; (e) persons certified or eligible for certification as prosthetists by the Canadian Board of Certification of Prosthetists and Orthotists. M.R. 64/2003 ; 38/2010 Designation of health care facilities 1.3 The facilities set out in Schedule A are designated as health care facilities for the purpose of the Act. M.R. 64/2003 ; 142/2005 Notice of right to access information 1.4(1) For the purpose of section 9.1 of the Act, a trustee must use a sign, poster, brochure or other similar type of notice to inform individuals. 1.4(2) The notice must (a) set out the information clearly in a manner that the individual can reasonably be expected to understand; (b) state that the individual has a right to examine and receive a copy of his or her personal health information; and (c) state that the individual has a right to authorize another person to examine and receive a copy of the information. 1.4(3) The notice may also contain other information about the trustee's practices and procedures relating to personal health information, including information about the trustee's collection practices required by section 15 of the Act. 1.4(4) The notice must be prominently displayed in as many locations and in such numbers as the trustee reasonably considers adequate to ensure that the information is likely to come to the individuals' attention. M.R. 38/2010 Written security policy and procedures 2 A trustee shall establish and comply with a written policy and procedures containing the following: (a) provisions for the security of personal health information during its collection, use, disclosure, storage, and destruction, including measures (i) to ensure the security of the personal health information when a record of the information is removed from a secure designated area, and (ii) to ensure the security of personal health information in electronic form when the computer hardware or removable electronic storage media on which it has been recorded is being disposed of or used for another purpose; (b) provisions for the recording of security breaches; (c) corrective procedures to address security breaches. Access restrictions and other precautions 3 A trustee shall (a) ensure that personal health information is maintained in a designated area or areas and is subject to appropriate security safeguards; (b) limit physical access to designated areas containing personal health information to authorized persons; (c) take reasonable precautions to protect personal health information from fire, theft, vandalism, deterioration, accidental destruction or loss and other hazards; and (d) ensure that removable media used to record personal health information is stored securely when not in use. Additional safeguards for electronic health information systems 4(1) In accordance with guidelines set by the minister, a trustee shall create and maintain, or have created and maintained, a record of user activity for any electronic information system it uses to maintain personal health information. 4(2) A record of user activity may be generated manually or electronically. 4(3) In the following circumstances, a record of user activity is not required under this section: (a) if personal health information is demographic or eligibility information listed in Schedule B, or is information that qualifies or further describes information listed in Schedule B; (b) if personal health information is disclosed under the authority of clause 22(2)⁠(h) of the Act (disclosure to a computerized health information network) in a routine and documented transmission from one electronic information system to another; (c) if personal health information is accessed or disclosed while a trustee is generating, distributing or receiving a statistical report, as long as the trustee (i) maintains a record of the persons authorized to generate, distribute and receive such reports, and (ii) regularly reviews the authorizations. 4(4) A trustee shall audit records of user activity to detect security breaches, in accordance with guidelines set by the minister. 4(5) A trustee shall maintain a record of user activity for at least three years. 4(6) A trustee shall ensure that at least one audit of a record of user activity is conducted before the record is destroyed. M.R. 90/2001 ; 142/2005 Authorized access for employees and agents 5 A trustee shall, for each of its employees and agents, determine the personal health information that he or she is authorized to access. Orientation and training for employees 6 A trustee shall provide orientation and ongoing training for its employees and agents about the trustee's policy and procedures referred to in section 2. Pledge of confidentiality for employees 7 A trustee shall ensure that each employee and agent signs a pledge of confidentiality that includes an acknowledgment that he or she is bound by the policy and procedures referred to in section 2 and is aware of the consequences of breaching them. Audit 8(1) A trustee shall conduct an audit of its security safeguards at least every two years. 8(2) If an audit identifies deficiencies in the trustee's security safeguards, the trustee shall take steps to correct the deficiencies as soon as practicable. Disclosure for charitable fundraising 8.1(1) The following are designated for the purpose of section 23.2 of the Act (charitable fundraising): (a) Society for Manitobans with Disabilities Inc.; (b) Pan Am Clinic. 8.1(2) A trustee must not disclose personal health information under subsection 23.2(2) of the Act in any of the following circumstances: (a) the individual has requested that the trustee limit disclosure of his or her personal health information; (b) the individual has died while in the trustee's care; (c) the individual is a child; (d) the trustee is a hospital and the reason for the patient's admission would reasonably be considered to be sensitive personal health information. 8.1(3) A charitable fundraising foundation that receives personal health information from a trustee under section 23.2 of the Act must not use an individual's information for fundraising if the foundation's records indicate that the individual has previously requested that he or she does not wish to receive communication from the foundation. 8.1(4) A charitable fundraising foundation must (a) clearly inform an individual to whom it sends a solicitation under section 23.2 of the Act that the individual may refuse any further solicitation; and (b) provide a telephone number that the individual may call to communicate a refusal. M.R. 38/2010 ; 282/2014 Health research privacy committee 8.2(1) A research applicant seeking approval for a health research project under section 24 of the Act must provide the health research privacy committee with the following information: (a) the purpose of the health research; (b) the name of the principal researcher or researchers responsible for the project, including any collaborating researchers if the project is multi-centre in scope; (c) the duration of the project, the date of commencement and the projected date it will conclude; (d) a detailed description of the personal health information required for the research; (e) a description of any possible linkage or merging of the personal health information with other information and the rationale for that linkage or merger; (f) whether the research project will require direct contact with individuals; (g) a description of the methods to be employed to maintain security of the personal health information, including disposal of the information; (h) the names of persons who will receive the project results, including any proposed submissions for publication; (i) identification of the sources and duration of funding for the research project; (j) [repealed] M.R. 146/2001 ; (k) any additional information the committee considers necessary. 8.2(1.1) On receiving the information required under subsection (1), the health research privacy committee must ensure that the information is forwarded to Research Manitoba, for consideration by CHIPER. 8.2(2) After receiving satisfactory confirmation that the proposed research project has been approved by CHIPER, the health research privacy committee may grant or refuse to grant an approval of the project, and must advise the research applicant in writing of its decision. 8.2(2.1) The health research privacy committee may sit in panels of three members, and when considering a proposed research project, (a) a panel has all the jurisdiction of the committee; and (b) a decision of a majority of the members of a panel is the decision of the committee. 8.2(3) The committee may determine its own practice and procedure. 8.2(4) [Repealed] M.R. 146/2021 8.2(5) The committee shall provide the minister with an annual report of its activities. 8.2(6) In this section, "CHIPER" means the Committee for Harmonized Health Impact, Privacy, and Ethics Review (CHIPER), as established by Research Manitoba. (« Comité pour l'analyse harmonisée ») M.R. 64/2003 ; 38/2010 ; 146/2021 Members of the health research privacy committee 8.3(1) The health research privacy committee is to consist of not less than eight and not more than 12 members. 8.3(2) The minister must appoint at least one person from nominations received from each of the following: (a) the College of Physicians and Surgeons of Manitoba; (b) the College of Registered Nurses of Manitoba; (c) the College of Pharmacists of Manitoba; (d) the Manitoba and Nunavut Chapter of the Canadian Health Information Management Association; (e) The University of Manitoba; (f) Research Manitoba. 8.3(2.1) In addition, the minister must appoint at least one person from nominations received from Shared Health Inc., CancerCare Manitoba and any regional health authority. 8.3(3) In appointing the balance of the members of the committee, the minister must consult with persons and organizations that the minister considers relevant and must have regard for the need to ensure that the committee as a whole represents a sufficient range of expertise and experience for it to carry out its role and responsibilities effectively. 8.3(3.1) A committee member may be appointed for a period of no more than six years, and continues to hold office until the member is re-appointed, the appointment is revoked or a successor is appointed. 8.3(4) The committee shall elect a chairperson from among its members. M.R. 64/2003 ; 38/2010 ; 146/2021 Research agreements 8.4 An agreement between a trustee and a researcher under subsection 24(4) of the Act must be in writing and must adequately identify the research project for which approval is given. M.R. 64/2003 ; 38/2010 Agreement re health research 8.5(1) For the purpose of section 24.1 of the Act, the following are prescribed health research organizations: (a) Manitoba Centre for Health Policy at the University of Manitoba; (b) Canadian Institute for Health Information. 8.5(2) For the purpose of 24.1(4) of the Act, an agreement between a trustee and a prescribed health research organization must (a) specify the purposes for which the health research organization may use the personal health information; (b) prohibit disclosure of personal health information except with the trustee's prior written consent; (c) require the health research organization to implement and maintain adequate safeguards for the protection, retention and destruction of personal health information satisfactory to the trustee; (d) allow the trustee to monitor compliance with the terms of the agreement; and (e) include remedies to address any failure by the health research organization to comply with the terms of the agreement. 8.5(3) A prescribed health research organization may collect and use a person's PHIN for a purpose mentioned in subsection 24.1(2) of the Act, subject to and in accordance with the requirements of the agreement entered into under subsection 24.1(4) of the Act. M.R. 38/2010 ; 61/2025 Meaning of "common-law partner" 8.6 For the purpose of clause 60(2)⁠(a) of the Act, "common-law partner" means a person who, not being married to the other person, is cohabitating with him or her in a conjugal relationship of some permanence. M.R. 38/2010 Risk of significant harm — factors 8.7 For the purpose of subsection 19.0.1(2) of the Act (notifying individual of privacy breach), for determining if a privacy breach could reasonably be expected to create a real risk of significant harm to an individual, the relevant factors to be considered are (a) the sensitivity of the personal health information involved; (b) the probability that the personal health information could be used to cause significant harm to the individual, having regard for (i) the event that caused the privacy breach to occur, including whether there is evidence of any malicious intent, such as the breach being the result of theft or gaining unauthorized access to a computer system, (ii) the number of persons who actually or potentially accessed the personal health information, (iii) if the identity of the persons who actually or potentially accessed the personal health information is known or unknown, (iv) any known relationship between any of the persons who actually or potentially accessed the personal health information and the individual to whom the information relates, and the nature of the relationship, (v) if the trustee is reasonably satisfied that any person who actually or potentially accessed the personal health information has destroyed any unauthorized copies of it and has committed to not use or disclose it, (vi) the length of time since the privacy breach first occurred and the duration of the period in which the personal health information was available to be accessed, used, disclosed, destroyed or altered in contravention of the Act, (vii) the amount of personal health information involved, (viii) if the personal health information has been recovered, (ix) if the personal health information was adequately encrypted, anonymized or otherwise not easily accessible, and (x) if harm has materialized; and (c) any other factors that are reasonably relevant in the circumstances. M.R. 146/2021 Form and manner of direct notice to individuals 8.8(1) When notice of a privacy breach is to be given to an individual as required under section 19.0.1 of the Act, the notice must be given in writing and must include (a) a description of the circumstances of the privacy breach; (b) the date or period of time that the privacy breach occurred, or is believed to have occurred; (c) the name of the trustee who had custody or control of the personal health information at the time of the privacy breach; (d) a description of the personal health information that was the subject of the privacy breach; (e) a description of the steps that the trustee has taken or is intending to take, as of the date of the notice, (i) to reduce the risk of harm to the individual as a result of the privacy breach, and (ii) to reduce the risk of a similar privacy breach in the future; (f) a description of the steps that the individual can take to reduce the risk of harm that can result from the privacy breach or to mitigate that harm; (g) a statement that the Ombudsman has been or will be given notice of the privacy breach, as required under subsection 19.0.1(4) of the Act; (h) the name and contact information of an officer or employee of the trustee who is able to answer questions about the privacy breach; and (i) any other information that the trustee considers relevant. 8.8(2) If the trustee reasonably believes that the delay necessary to provide written notice to an individual is likely to significantly increase a real risk of significant harm to the individual, the trustee may give the notice orally, provided (a) at the time the oral notice is given, the trustee records the information that was given and the date on which it was provided; or (b) the trustee gives notice in writing in accordance with subsection (1) within a reasonable time after the oral notice is provided. M.R. 146/2021 When indirect notification may be given 8.9(1) Under clause 19.0.1(3)⁠(c) of the Act, notification of a privacy breach may be given indirectly to one or more individuals in the following circumstances: (a) if the trustee reasonably believes that the privacy breach may result in a risk to public health or safety; (b) if the identity or current contact information of the individual or individuals is not known; (c) if the trustee reasonably believes giving notice to an individual in accordance with section 8.8 (i) is impractical or unduly expensive because of the large number of individuals that may have been affected by the privacy breach, or (ii) could threaten or harm the individual's mental or physical health. 8.9(2) Notification under this section must be given (a) by public communication or similar measure that (i) can be reasonably expected to reach the affected individual or individuals, and (ii) does not include any information that could reasonably identify the affected individual or individuals; or (b) if notice of the privacy breach can be reasonably expected to threaten or harm the recipient's mental or physical health, in writing to an individual who provides care to the recipient or to an individual with whom the recipient is known to have a close personal relationship. M.R. 146/2021 Coming into force 9(1) This regulation comes into force on December 11, 1997. Time to comply: one year 9(2) Notwithstanding subsection (1), a trustee shall comply with this regulation, except section 4, as soon as reasonably possible but not later than December 11, 1998. 9(3) [Repealed] M.R. 90/2001 M.R. 90/2001 SCHEDULE A (Section 1.3) DESIGNATED HEALTH CARE FACILITIES Aboriginal Health and Wellness Centre of Winnipeg, Inc. Beaver Air Services L.P. Behavioural Health Foundation Inc. Brandon Cardiac Reh-Fit — YMCA CFB Shilo Emergency Services Canadian Blood Services (The) Centre de Santé Chemawawin First Nation Ambulance Service Clinique Youville Clinic Inc. Community Therapy Services Inc. Eden Residential Care Services Inc. Emerson Volunteer Ambulance Service Fisher Ambulance Service Ltd. Gilbert Plains Ambulance Service Hope Centre Health Care Incorporated Jocelyn House Inc. Keewatin Air Klinic, Inc. Laurel Centre Inc. MFL Occupational Health and Safety Centre Inc. Main Street Project Inc. Manitoba Cardiac Institute (Reh-Fit) Inc. Melita Ambulance Service Mount Carmel Clinic Native Addictions Council of Manitoba Neepawa & District Ambulance Service Ltd. Nine Circles Community Health Centre Norway House Cree Nation EMS Nor'West Co-op Health & Social Services Centre Inc. Perimeter AeroMed Pimichikimac Air Ltd. Pine Falls Ambulance Service Portage Emergency Medical Care Services Riverton Ambulance Service Rosaire House — The Pas St. Amant Centre Inc. Ste. Rose and District Ambulance Service Salvation Army Inc. — Anchorage Program Salvation Army Inc. — Brandon Crisis Stabilization/Mobile Crisis Unit Salvation Army Inc. — Interlake Crisis Stabilization/Mobile Crisis Unit Saul Sair Health Centre — Siloam Mission SkyCare Air Ambulance Society for Manitobans with Disabilities Inc. Swan Valley Ambulance Service Tamarack Rehab Inc. The Sanatorium Board of Manitoba (Pelican Lake Centre) Winnipegosis Ambulance Service Women's Health Clinic Inc. M.R. 64/2003 ; 142/2005 ; 38/2010 SCHEDULE B (Clause 4(3)⁠(a)) DEMOGRAPHIC AND ELIGIBILITY INFORMATION Name Signature Address Telecommunications information Sex Date of birth Date of death Family associations Eligibility for health care coverage Jurisdiction of residence Manitoba Health family registration number Personal Health Identification Number(PHIN) A unique identifier equivalent to the PHIN assigned by another jurisdiction that pays for health care A unique identifier — not including a social insurance number or, except as provided in this Schedule, any other pre-existing identifier — assigned to an individual by a trustee for its own purposes, when accessed by any trustee A non-Canadian unique health identification number M.R. 142/2005 ; 99/2012
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Personal Health Information Regulation
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.