OTNhub eVisit Privacy and Security Recommendations

Below are some best practices regarding privacy and security when using your mobile device with eVisit. Personal Information (PI) and Personal Health Information (PHI) are important and must be protected, both to comply with legislation and to ensure patient safety, trust, and a good clinical experience.

Administrative Safeguards

Follow all policies and procedures in place at your organization to ensure the collection, use, disclosure, retention and destruction of PHI is done in accordance with Ontario’s Personal Health Information Protection Act (PHIPA) and any other applicable law or regulation.

Follow any policies and procedures in place at your own organization to ensure the physical, technical, and administrative security of sensitive assets (for example, computers, documents, and the like).

Report any privacy or information-security related incidents (for example, theft of mobile device) to your Privacy or Information Security officer, respectively. Any breaches with the potential to affect other organizations should also be reported to Ontario Health by calling 1-866-250-1554 or servicedesk@ontariohealth.ca).

If you accidentally dial another system and someone is present:

  • Identify yourself and explain that you have connected in error
  • Hang up and contact your privacy officer and Ontario Health’s privacy team (Telephone: 1-866-250-1554 or or email: servicedesk@ontariohealth.ca).

If a site accidentally dials your system, contact your privacy officer and Ontario Health’s privacy team (1-866-250-1554 or email: servicedesk@ontariohealth.ca).

Physical Safeguards

Lock your meeting room before starting the conference and after you have confirmed that all invitees have joined to prevent unauthorized access to personal information (PI) and personal health information (PHI) in transit.

Locate device(s) in a secure location to minimize the risks of modification, loss, access, theft, view and disclosure by unauthorized individuals. If you are using a mobile device (for example, a laptop or smartphone), do not leave it unattended.

Ensure that records containing confidential information (for example, PHI) are viewed in a private setting. Avoid performing sensitive tasks in public areas, such as airports, coffee shops, or business lounges, where there is an opportunity for unauthorized individuals to observe the confidential information.

Technical Safeguards

Enable your computer to automatically lock itself if it is idle for a period of time (for example, every 30 min).

Only use equipment that has been approved by your organization.

Encrypt any device containing confidential information. Do not export confidential information onto unencrypted portable storage such as USB flash keys, recordable CDs/DVDs, or external hard drives.

Do not use the “Remember Me” function on a login page. (Clear your username and password when you sign out.)

Requirements for Mobile Devices

Ontario Health takes protection of PHI very seriously. Although Ontario Health has implemented several security safeguards to protect the confidentiality, integrity, and availability of data, protection of PHI is ultimately a joint responsibility between Ontario Health and the users of its services. the Ontario Health Security team has created a Tip Sheet: Securing Your Data on Your Mobile Device.

More Like This

Last Updated: June 04, 2026