Best practices for smartphone and smart-device clinical photo taking and sharing
- Health information and e-health
- Ethics and medical professionalism
- Policy Type
- Policy document
- Clinical photography is a valuable tool for physicians. Smartphones, as well as other devices supporting network connectivity, offer a convenient, efficient method to take and share images. However, due to the private nature of the information contained in clinical photographs there are concerns as to the appropriate storage, dissemination, and documentation of clinical images. Confidentiality of image data must be considered and the dissemination of these images onto servers must respect the privacy and rights of the patient. Importantly, patient information should be considered as any information deriving from a patient, and the concepts outlined therefore apply to any media that can be collected on, or transmitted with, a smart-device. Clinical photography can aid in documenting form and function, in tracking conditions and wound healing, in planning surgical operations, and in clinical decision-making. Additionally, clinical photographs can provide physicians with a valuable tool for patient communication and education. Due to the convenience of this type of technology it is not appropriate to expect physicians to forego their use in providing their patients with the best care available. The technology and software required for secure transfer, communication, and storage of clinical media is presently available, but many devices have non-secure storage/dissemination options enabled and lack user-control for permanently deleting digital files. In addition, data uploaded onto server systems commonly cross legal jurisdictions. Many physicians are not comfortable with the practice, citing security, privacy, and confidentiality concerns as well as uncertainty in regards to regional regulations governing this practice.1 Due to concern for patient privacy and confidentiality it is therefore incredibly important to limit the unsecure or undocumented acquisition or dissemination of clinical photographs. To assess the current state of this topic, Heyns et al. have reviewed the accessibility and completeness of provincial and territorial medical regulatory college guidelines.2 Categories identified as vital and explored in this review included: Consent; Storage; Retention; Audit; Transmission; and Breach. While each regulatory body has addressed limited aspects of the overall issue, the authors found a general lack of available information and call for a unified document outlining pertinent instructions for conducting clinical photography using a smartphone and the electronic transmission of patient information.2 The discussion of this topic will need to be ongoing and it is important that physicians are aware of applicable regulations, both at the federal and provincial levels, and how these regulations may impact the use of personal devices. The best practices supported here aim to provide physicians and healthcare providers with an understanding of the scope and gravity of the current environment, as well as the information needed to ensure patient privacy and confidentiality is assessed and protected while physicians utilize accessible clinical photography to advance patient care. Importantly, this document only focusses on medical use (clinical, academic, and educational) of clinical photography and, while discussing many core concepts of patient privacy and confidentiality of information, should not be perceived as a complete or binding framework. Additionally, it is recommended that physicians understand the core competencies of clinical photography, which are not described here. The Canadian Medical Association (CMA) suggests that the following recommendations be implemented, as thoroughly as possible, to best align with the CMA policy on the Principles for the Protection of Patient Privacy (CMA Policy PD2018-02). These key recommendations represent a non-exhaustive set of best practices - physicians should seek additional information as needed to gain a thorough understanding and to stay current in this rapidly changing field. KEY RECOMMENDATIONS 1. CONSENT * Informed consent must be obtained, preferably prior, to photography with a mobile device. This applies for each and any such encounter and the purpose made clear (i.e. clinical, research, education, publication, etc.). Patients should also be made aware that they may request a copy of a picture or for a picture to be deleted. * A patient's consent to use electronic transmission does not relieve a physician of their duty to protect the confidentiality of patient information. Also, a patient's consent cannot override other jurisdictionally mandated security requirements. * All patient consents (including verbal) should be documented. The acquisition and recording of patient consent for medical photography/dissemination may be held to a high standard of accountability due to the patient privacy and confidentiality issues inherent in the use of this technology. Written and signed consent is encouraged. * Consent should be considered as necessary for any and all photography involving a patient, whether or not that patient can be directly recognized, due to the possibility of linked information and the potential for breach of privacy. The definition of non-identifiable photos must be carefully considered. Current technologies such as face recognition and pattern matching (e.g. skin markers, physical structure, etc.), especially in combination with identifying information, have the potential to create a privacy breach. * Unsecure text and email messaging requires explicit patient consent and should not be used unless the current gold standards of security are not accessible. For a patient-initiated unsecure transmission, consent should be clarified and not assumed. 2. TRANSMISSION * Transmission of photos and patient information should be encrypted as per current-day gold standards (presently, end-to-end encryption (E2EE)) and use only secure servers that are subject to Canadian laws. Explicit, informed consent is required otherwise due to privacy concerns or standards for servers in other jurisdictions. Generally, free internet-based communication services and public internet access are unsecure technologies and often operate on servers outside of Canadian jurisdiction. * Efforts should be made to use the most secure transmission method possible. For data security purposes, identifying information should never be included in the image, any frame of a video, the file name, or linked messages. * The sender should always ensure that each recipient is intended and appropriate and, if possible, receipt of transmission should be confirmed by the recipient. 3. STORAGE * Storing images and data on a smart-device should be limited as much as possible for data protection purposes. * Clinical photos, as well as messages or other patient-related information, should be completely segregated from the device's personal storage. This can be accomplished by using an app that creates a secure, password-protected folder on the device. * All information stored (on internal memory or cloud) must be strongly encrypted and password protected. The security measures must be more substantial than the general password unlock feature on mobile devices. * Efforts should be made to dissociate identifying information from images when images are exported from a secure server. Media should not be uploaded to platforms without an option for securely deleting information without consent from the patient, and only if there are no better options. Automatic back-up of photos to unsecure cloud servers should be deactivated. Further, other back-up or syncing options that could lead to unsecure server involvement should be ascertained and the risks mitigated. 4. Cloud storage should be on a Canadian and SOCII certified server. Explicit, informed consent is required otherwise due to privacy concerns for servers in other jurisdictions. 5. AUDIT & RETENTION * It is important to create an audit trail for the purposes of transparency and medical best practice. Key information includes patient and health information, consent type and details, pertinent information regarding the photography (date, circumstance, photographer), and any other important facts such as access granted/deletion requests. * Access to the stored information must be by the authorized physician or health care provider and for the intended purpose, as per the consent given. Records should be stored such that it is possible to print/transfer as necessary. * Original photos should be retained and not overwritten. * All photos and associated messages may be considered part of the patient's clinical records and should be maintained for at least 10 years or 10 years after the age of majority, whichever is longer. When possible, patient information (including photos and message histories between health professionals) should be retained and amalgamated with a patient's medical record. Provincial regulations regarding retention of clinical records may vary and other regulations may apply to other entities - e.g. 90 years from date of birth applies to records at the federal level. * It may not be allowable to erase a picture if it is integral to a clinical decision or provincial, federal, or other applicable regulations require their retention. 6. BREACH * Any breach should be taken seriously and should be reviewed. All reasonable efforts must be made to prevent a breach before one occurs. A breach occurs when personal information, communication, or photos of patients are stolen, lost, or mistakenly disclosed. This includes loss or theft of one's mobile device, texting to the wrong number or emailing/messaging to the wrong person(s), or accidentally showing a clinical photo that exists in the phone's personal photo album. * It should be noted that non-identifying information, when combined with other available information (e.g. a text message with identifiers or another image with identifiers), can lead to highly accurate re-identification. * At present, apps downloaded to a smart-device for personal use may be capable of collecting and sharing information - the rapidly changing nature of this technology and the inherent privacy concerns requires regular attention. Use of specialized apps designed for health-information sharing that help safeguard patient information in this context is worth careful consideration. * Having remote wipe (i.e. device reformatting) capabilities is an asset and can help contain a breach. However, inappropriate access may take place before reformatting occurs. * If a smartphone is strongly encrypted and has no clinical photos stored locally then its loss may not be considered a breach. * In the event of a breach any patient potentially involved must be notified as soon as possible. The CMPA, the organization/hospital, and the Provincial licensing College should also be contacted immediately. Provincial regulations regarding notification of breach may vary. Approved by the CMA Board of Directors March 2018 References i Heyns M†, Steve A‡, Dumestre DO‡, Fraulin FO‡, Yeung JK‡ † University of Calgary, Canada ‡ Section of Plastic Surgery, Department of Surgery, University of Calgary, Canada 1 Chan N, Charette J, Dumestre DO, Fraulin FO. Should 'smart phones' be used for patient photography? Plast Surg (Oakv). 2016;24(1):32-4. 2 Unpublished - Heyns M, Steve A, Dumestre DO, Fraulin FO, Yeung J. Canadian Guidelines on Smartphone Clinical Photography.
Maintaining Ontario’s leadership on prohibiting the use of sick notes for short medical leaves
- Physician practice/ compensation/ forms
- Health systems, system funding and performance
- Policy Type
- Parliamentary submission
- The Canadian Medical Association (CMA) submits this brief to the Standing Committee on Finance and Economic Affairs for consideration as part of its study on Bill 47, Making Ontario Open for Business Act, 2018. The CMA unites physicians on national, pan-Canadian health and medical matters. As the national advocacy organization representing physicians and the medical profession, the CMA engages with provincial/territorial governments on pan-Canadian health and health care priorities. As outlined in this submission, the CMA supports the position of the Ontario Medical Association (OMA) in recommending that Schedule 1 of Bill 47 be amended to strike down the proposed new Section 50(6) of the Employment Standards Act, 2000. This section proposes to reinstate an employer’s ability to require an employee to provide a sick note for short leaves of absence because of personal illness, injury or medical emergency. Ontario is currently a national leader on sick notes In 2018, Ontario became the first jurisdiction in Canada to withdraw the ability of employers to require employees to provide sick notes for short medical leaves because of illnesses such as a cold or flu. This legislative change aligned with the CMA’s policy position1 and was strongly supported by the medical and health policy community. An emerging pan-Canadian concern about the use of sick notes As health systems across Canada continue to grapple with the need to be more efficient, the use of sick notes for short leaves as a human resources tool to manage employee absenteeism has drawn increasing criticism in recent years. In addition to Ontario’s leadership, here are a few recent cases that demonstrate the emerging concern about the use of sick notes for short leaves:
- In 2016, proposed legislation to end the practice was tabled in the Manitoba legislature.2
- The Newfoundland and Labrador Medical Association and Doctors Nova Scotia have been vocal opponents of sick notes for short leaves, characterizing them as a strain on the health care system.3,4
- The University of Alberta and Queen’s University have both formally adopted “no sick note” policies for exams.5,6
- The report of Ontario’s Changing Workplaces Review summarized stakeholder comments about sick notes, describing them as “costly, very often result from a telephone consultation and repeat what the physician is told by the patient, and which are of very little value to the employer.”7 Ontario’s action in 2018 to remove the ability of employers to require sick notes, in response to the real challenges posed by this practice, was meaningful and demonstrated leadership in the national context. The requirement to obtain sick notes negatively affects patients and the public By walking back this advancement, Ontario risks reintroducing a needless inefficiency and strain on the health system, health care providers, their patients and families. For patients, having to produce a sick note for an 4 employer following a short illness-related leave could represent an unfair economic impact. Individuals who do not receive paid sick days may face the added burden of covering the cost of obtaining a sick note as well as related transportation fees in addition to losing their daily wage. This scenario illustrates an unfair socioeconomic impact of the proposal to reinstate employers’ ability to require sick notes. In representing the voice of Canada’s doctors, the CMA would be remiss not to mention the need for individuals who are ill to stay home, rest and recover. In addition to adding a physical strain on patients who are ill, the requirement for employees who are ill to get a sick note, may also contribute to the spread of viruses and infection. Allowing employers to require sick notes may also contribute to the spread of illness as employees may choose to forego the personal financial impact, and difficulty to secure an appointment, and simply go to work sick. Reinstating sick notes contradicts the government’s commitment to end hallway medicine It is important to consider these potential negative consequences in the context of the government’s commitment to “end hallway medicine.” If the proposal to reintroduce the ability of employers to require sick notes for short medical leaves is adopted, the government will be introducing an impediment to meeting its core health care commitment. Reinstating sick notes would increase the administrative burden on physicians Finally, as the national organization representing the medical profession in Canada, the CMA is concerned about how this proposal, if implemented, may negatively affect physician health and wellness. The CMA recently released a new baseline survey, CMA National Physician Health Survey: A National Snapshot, that reveals physician health is a growing concern.8 While the survey found that 82% of physicians and residents reported high resilience, a concerning one in four respondents reported experiencing high levels of burnout. How are these findings relevant to the proposed new Section 50(6) of the Employment Standards Act, 2000? Paperwork and administrative burden are routinely found to rank as a key contributor to physician burnout.9 While a certain level of paperwork and administrative responsibility is to be expected, health system and policy decision-makers must avoid introducing an unnecessary burden in our health care system. Conclusion: Remove Section 50(6) from Schedule 1 of Bill 47 The CMA appreciates the opportunity to provide this submission for consideration by the committee in its study of Bill 47. The committee has an important opportunity to respond to the real challenges associated with sick notes for short medical leaves by ensuring that Section 50(6) in Schedule 1 is not implemented as part of Bill 47. 5 1 Canadian Medical Association (CMA). Third-Party Forms (Update 2017). Ottawa: The Association; 2017. Available: http://policybase.cma.ca/dbtw-wpd/Policypdf/PD17-02.pdf (accessed 2019 Nov 13). 2 Bill 202. The Employment Standards Code Amendment Act (Sick Notes). Winnipeg: Queen’s Printer for the Province of Manitoba; 2016. Available: https://web2.gov.mb.ca/bills/40-5/pdf/b202.pdf (accessed 2019 Nov 13). 3 CBC News. Sick notes required by employers a strain on system, says NLMA. 2018 May 30. Available: www.cbc.ca/news/canada/newfoundland-labrador/employer-required-sick-notes-unnecessary-says-nlma-1.4682899 4 CBC News. No more sick notes from workers, pleads Doctors Nova Scotia. 2014 Jan 10. Available: www.cbc.ca/news/canada/nova-scotia/no-more-sick-notes-from-workers-pleads-doctors-nova-scotia-1.2491526 (accessed 2019 Nov 13). 5 University of Alberta University Health Centre. Exam deferrals. Edmonton: University of Alberta; 2018. Available: www.ualberta.ca/services/health-centre/exam-deferrals (accessed 2019 Nov 13). 6 Queen’s University Student Wellness Services. Sick notes. Kingston: Queen’s University; 2018. Available: www.queensu.ca/studentwellness/health-services/services-offered/sick-notes (accessed 2019 Nov 13). 7 Ministry of Labour. The Changing Workplaces Review: An Agenda for Workplace Rights. Final Report. Toronto: Ministry of Labour; 2017 May. Available: https://files.ontario.ca/books/mol_changing_workplace_report_eng_2_0.pdf (accessed 2019 Nov 13). 8 Canadian Medical Association (CMA). One in four Canadian physicians report burnout [media release]. Ottawa: The Association; 2018 Oct 10. Available: www.cma.ca/En/Pages/One-in-four-Canadian-physicians-report-burnout-.aspx (accessed 2019 Nov 13). 9 Leslie C. The burden of paperwork. Med Post 2018 Apr.