OTNhub Virtual Emergency Services: Privacy and Security Safeguards

These safeguards outline the key practices for protecting patient confidentiality while using OTNhub’s Virtual Emergency Services.  

Key Practices for Protecting Patient Confidentiality

Physical Privacy Safeguards

  • Position patients in areas away from unauthorized observers and with minimal traffic.
  • Angle monitors to reduce on-screen visibility to passersby.
  • Avoid placing cameras near windows or doors.
  • Post visible signage indicating when a session is in progress.
  • Keep audio volume low to prevent others from overhearing.
  • Do not leave laptops or devices unattended; secure them with locks or store them out of sight.
  • Ensure viewing of images and personal health information (PHI) happens in private settings.
  • Shred all sensitive hardcopy documents after use.

Technological Safeguards

  • Use strong passwords (minimum eight characters with mixed case, numbers, special characters).
  • Change passwords every six months and never share them.
  • Avoid using public computers for confidential information.
  • Do not use the same password across applications.
  • Lock computers when unattended (use CTRL+ALT+DEL).
  • Keep devices powered on for updates, not in “Sleep” or “Hibernate.”
  • Connect devices to an uninterruptible power supply (UPS).
  • Export PHI only to encrypted storage; delete when no longer needed.
  • Use FIPS 140-2 certified protocols for transmitting data.
  • De-identify patient images for educational use and always obtain patient consent.
  • Never provide passwords via email or store them insecurely.

Administrative Controls

  • Follow organizational policies for the handling of PHI or personal information (PI), including collection, use, retention, and destruction.
  • Report lost or stolen hardware and suspected breaches immediately as per policy.
  • Maintain “Clean Desk” practices and secure charts and forms outside normal work areas.
  • Ensure all virtual care sessions are live feeds and not recorded, informing the patient accordingly.

General Considerations

  • Adhere to PHIPA, IPC Orders, and other applicable privacy laws and regulations.
  • If you suspect that patient information was inappropriately accessed or disclosed, contact your privacy officer and Ontario Health’s privacy team (1-866-250-1554 or email: servicedesk@ontariohealth.ca)

More Like This

Last Updated: June 04, 2026