OTNhub Ncompass: Privacy and Security Recommendations
Personal Health Information (PHI) is sensitive and must be protected to comply with legislation and to ensure positive clinical experiences, patient safety and trust. Below are some privacy and security best practices for scheduling virtual care events in Ncompass.
Administrative Safeguards
Follow any policies and procedures in place at your organization to ensure that PHI is collected, used, disclosed, retained and destroyed in compliance with the Personal Health Information Protection Act, 2004 (PHIPA) and any other applicable law or regulation.
Follow any policies and procedures in place at your organization to ensure the physical, technical, and administrative security of sensitive assets (for example, computers, documents, and the like).
Beware of email phishing scams. Any emails requesting personal information should be deleted, unless they are expected and coming from a verified source. Do not open any attachments from sources that you do not trust.
Report any privacy or information security incidents to your organization’s Privacy and Information Security Officers (or equivalent roles).
Any privacy and/or security incidents related to OTNhub services must be reported to Ontario Health’s privacy team (1-866-250-1554 or email servicedesk@ontariohealth.ca)
If you accidentally dial another system and someone is present:
- identify yourself and explain that you have connected in error
- hang up and contact your organization’s Privacy Officer (or equivalent role) and Ontario Health’s privacy team (1-866-250-1554 or email: servicedesk@ontariohealth.ca)
- if a site accidentally dials your system, contact your organization’s Privacy Officer (or equivalent role) and Ontario Health’s privacy team (1-866-250-1554 or email: servicedesk@ontariohealth.ca)
Physical Safeguards
- Locate devices in a secure location to minimize the risks of modification, loss, access/viewing, theft, and disclosure by unauthorized individuals. If you are using a mobile device (for example, laptop, smartphone), do not leave it unattended.
- Ensure that records containing confidential information (for example, PHI) are viewed in a private setting. Avoid performing sensitive tasks in public areas such as airports, coffee shops or business lounges, where there is an opportunity for unauthorized individuals to observe confidential information.
- Lock the meeting or office room being used for a virtual visit before starting to prevent interruptions and unauthorized access to PI and PHI.
Technical Safeguards
- Enable your device to automatically lock itself after a period of inactivity (for example, every 15 minutes or less).
- Keep your device up to date with the latest security updates and ensure that your anti-virus software is turned on.
- Only use equipment and apps that have been approved by your organization.
- Keep your firewall turned on.
- Encrypt any device containing confidential information. Do not export confidential information onto unencrypted portable storage such as USB flash keys, recordable CDs/DVDs or external hard drives.
- Ensure your device is password protected and follow these best practices around password use.
Privacy Tips for Scheduling
Ncompass users should follow the practices below to ensure compliance with PHIPA and its Regulation:
- Do not include any identifiable patient information in any event data fields when scheduling a virtual care event.
- Notify participating sites that you intend to register them prior to scheduling an event.
- Always confirm the system details before adding a participant site.
- When making a manual point-to-point call, the consultant site should always call the patient site unless arranged otherwise.
- If you inadvertently connect with the wrong site and/or system, contact Ontario Health’s privacy team (1-866-250-1554 or email: servicedesk@ontariohealth.ca)
- Do not share your Ncompass username and password with anyone. Protect your computer monitor from causal observation by others in your workspace when logged into Ncompass.
- Limit access to and use of PHI to that which you require to complete scheduling tasks.
- Do not take screen shots of patient PHI.
- If hard copies are required for any reason, ensure the documents are securely stored and then shredded securely once they are no longer required.
- Be sure to follow the agreed-upon process for notifying other sites of event changes and confirm that notifications have been received prior to editing an event.
If you have any questions regarding privacy and security issues, you can submit an inquiry on our webpage Privacy: Contact Us.
More Like This
Last Updated: June 04, 2026