{"id":57339,"date":"2024-12-20T09:53:27","date_gmt":"2024-12-20T14:53:27","guid":{"rendered":"https:\/\/lescliniquesmaroisurologue.ca\/politique-de-protection-des-renseignements-personnels-site-web\/"},"modified":"2024-12-20T11:15:37","modified_gmt":"2024-12-20T16:15:37","slug":"politique-de-protection-des-renseignements-personnels-site-web","status":"publish","type":"page","link":"https:\/\/lescliniquesmaroisurologue.ca\/en\/politique-de-protection-des-renseignements-personnels-site-web\/","title":{"rendered":"Personal information protection policy"},"content":{"rendered":"<!--themify_builder_content-->\n<div id=\"themify_builder_content-57339\" data-postid=\"57339\" class=\"themify_builder_content themify_builder_content-57339 themify_builder tf_clear\">\n                    <div  data-lazy=\"1\" class=\"module_row themify_builder_row tb_uqyf738 tb_first tf_w\">\n                        <div class=\"row_inner col_align_top tb_col_count_1 tf_box tf_rel\">\n                        <div  data-lazy=\"1\" class=\"module_column tb-column col-full tb_dkfz738 first\">\n                    <!-- module text -->\n<div  class=\"module module-text tb_byv1739   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p>As part of its activities, Les Cliniques Marois collects, uses, archives and destroys personal information about patients who use its services.<\/p><p>Les Cliniques Marois are subject to the application of Law 25 on the protection of personal information in the private sector. To this end, Les Cliniques Marois are responsible for ensuring the protection of the personal information they hold and for complying with Quebec\u2019s Privacy Law 25.<\/p><p>This policy aims to ensure the protection of personal information and to demonstrate how Les Cliniques Marois manages it.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module divider -->\n<div  class=\"module tf_mw module-divider tb_fom5900 solid   \" style=\"border-width: 1px;border-color: #ffffff;margin-top: 15px;\" data-lazy=\"1\">\n    <\/div>\n<!-- \/module divider -->\n<!-- module fancy heading -->\n<div  class=\"module module-fancy-heading tb_vrvz925 \" data-lazy=\"1\">\n        <h2 class=\"fancy-heading\">\n    <span class=\"main-head tf_block\">\n                    THE DESIGNATED PRIVACY OFFICER            <\/span>\n\n    \n    <span class=\"sub-head tf_block tf_rel\">\n                                <\/span>\n    <\/h2>\n<\/div>\n<!-- \/module fancy heading -->\n<!-- module text -->\n<div  class=\"module module-text tb_1qxl947   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p>If you have any questions, comments or incidents concerning confidential data at Cliniques Marois, you can contact our privacy officer using one of the following methods:<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_2ovs799 box-content  \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p><strong>Name of the person in charge:<\/strong> Vanessa Faro-Dussault<\/p>\n<p><strong>Email address:<\/strong> Vanessa.Faro@lescliniquesmarois.com<\/p>\n<p><strong>Phone:<\/strong> 1-844-URO-ALLO Extension 412<\/p>\n<p><strong>Mailing address:<\/strong> 403-3135 Boul. Moise-Vincent, St-Hubert, Qu\u00e9bec, J3Z 0G7<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module divider -->\n<div  class=\"module tf_mw module-divider tb_76ti10 solid   \" style=\"border-width: 1px;border-color: #ffffff;margin-top: 15px;\" data-lazy=\"1\">\n    <\/div>\n<!-- \/module divider -->\n<!-- module fancy heading -->\n<div  class=\"module module-fancy-heading tb_q8hl95 \" data-lazy=\"1\">\n        <h2 class=\"fancy-heading\">\n    <span class=\"main-head tf_block\">\n                    DEFINITIONS            <\/span>\n\n    \n    <span class=\"sub-head tf_block tf_rel\">\n                                <\/span>\n    <\/h2>\n<\/div>\n<!-- \/module fancy heading -->\n<!-- module text -->\n<div  class=\"module module-text tb_07lp806   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p><strong>Personal information (PI)<\/strong> is personal information that concerns a natural person and that allows them to be identified, directly or indirectly. For example, here are PIs that Les Cliniques Marois administers daily:<\/p><ul><li>Full names and contact information;<\/li><li>Residential and electronic addresses;<\/li><li>Telephone numbers;<\/li><li>Parents\u2019 full names;<\/li><li>Demographic data (e.g. gender, date of birth, etc.);<\/li><li>Financial information.<\/li><\/ul><p><strong>Sensitive personal information (SPI)<\/strong> is data that, due to its nature, particularly medical, biometric or otherwise intimate, or due to the context of its use or communication, gives rise to a high degree of reasonable expectation of privacy. For example, here are some sensitive PI that Les Cliniques Marois manages on a daily basis:<\/p><ul><li>Medical records;<\/li><li>Health insurance number;<\/li><li>Health status;<\/li><li>Results of medical examinations;<\/li><li>List of medications;<\/li><li>Social insurance number (for employees only).<\/li><\/ul><p><strong>A privacy incident (PI)<\/strong> is: (i) access to personal information that is not authorized by law; (ii) use of personal information that is not authorized by law; (iii) disclosure of personal information that is not authorized by law; or (iv) loss of personal information or other breach of the protection of such information.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module divider -->\n<div  class=\"module tf_mw module-divider tb_t0x3665 solid   \" style=\"border-width: 1px;border-color: #ffffff;margin-top: 15px;\" data-lazy=\"1\">\n    <\/div>\n<!-- \/module divider -->\n<!-- module fancy heading -->\n<div  class=\"module module-fancy-heading tb_tgb0510 \" data-lazy=\"1\">\n        <h2 class=\"fancy-heading\">\n    <span class=\"main-head tf_block\">\n                    APPLICATION            <\/span>\n\n    \n    <span class=\"sub-head tf_block tf_rel\">\n                                <\/span>\n    <\/h2>\n<\/div>\n<!-- \/module fancy heading -->\n<!-- module text -->\n<div  class=\"module module-text tb_egzx606   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p>The policy covers all types of PI and sensitive PI that Les Cliniques Marois administers as part of professional activities with patients, employees and certain suppliers.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_5erp602   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>1. Consent to the collection of personal data:<\/h3><p>Les Cliniques Marois obtains consent to the collection of PI and sensitive PI before collection, explaining the puPIoses of this collection at the time of collection. In all cases, Les Cliniques Marois uses a consent form.<\/p><p>When Les Cliniques Marois collects PI and SPI on persons under 14 years of age, the holder of parental authority or guardian must consent to the collection.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_ho88705   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>2. Collection of personal data:<\/h3><p>As part of its activities, Les Cliniques Marois collects various types of PI and sensitive PI. Generally, the collection is done directly from the person who requests services or becomes an employee of Les Cliniques Marois. In certain cases, PI and sensitive PI may be received via third parties, when it concerns the results of additional examinations carried out externally or a patient under 14 years of age.<\/p><p>At the time of collection, Les Cliniques Marois informs the persons contacted of the following information:<\/p><ul><li>The purposes for which PI and sensitive PI are collected (e.g., opening a medical record);<\/li><li>The means by which PI and sensitive PI are collected (e.g., using electronic signature software).<\/li><\/ul><p>Details regarding <strong>the collection<\/strong> of personal data:<\/p><table class=\"policy-table\" cellspacing=\"0\"><tbody><tr><td class=\"table-col1\"><strong>Types of personal data<\/strong><\/td><td class=\"table-col2\">Personal information, sensitive personal information &amp; financial information.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Persons concerned<\/strong><\/td><td class=\"table-col2\">Patients, parents of children under 14, employees and certain suppliers.<\/td><\/tr><tr><td class=\"table-col1\"><strong>PuPIose of collection<\/strong><\/td><td class=\"table-col2\">Daily management of medical records, employee records &amp; accounting.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Staff involved<\/strong><\/td><td class=\"table-col2\">Administrative staff, nursing staff, doctors and service supervisors.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Computer technologies<\/strong><\/td><td class=\"table-col2\">Electronic medical records (EMR), electronic signature software, cloud telephony software, cloud payroll software, insurance &amp; RVER portals, POS platform, etc.<\/td><\/tr><\/tbody><\/table>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_7wul805   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>3. Use of PI and sensitive PI:<\/h3><p>Cliniques Marois limits the use of PI and sensitive PI to the purposes for which they were collected, as described at the time of collection.<\/p><p>Details regarding the <strong>use<\/strong> of personal data:<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_5y2v443   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <table class=\"policy-table\" cellspacing=\"0\"><tbody><tr><td class=\"table-col1\"><strong>Opening a patient file<\/strong> <br \/><em>(e.g. new patient)<\/em><\/td><td class=\"table-col2\">Performed by administrative staff on the DME.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Opening and managing employee files<\/strong> <br \/><em>(e.g.: new employee)<\/em><\/td><td class=\"table-col2\">Carried out by Human Resources (HR) and Accounting supervisors on secure digital platforms.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Patient file management<\/strong><br \/><em>(e.g.: file note entries, follow-ups, etc.)<\/em><\/td><td class=\"table-col2\">Performed by physicians or nurses on the secure EMR as part of appointments or receiving medical results.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Patient Transactions<\/strong><br \/><em>(e.g.: payments)<\/em><\/td><td class=\"table-col2\">Performed by administrative staff and accounting supervisor on the secure EMR and POS platform.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Communications of PI and sensitive PI to other healthcare professionals<\/strong><br \/><em>(e.g.: copy of medical record)<\/em><\/td><td class=\"table-col2\">Carried out by administrative or nursing staff, always with the patient&#8217;s consent.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Observation of third parties outside the Clinics<\/strong><br \/><em>(e.g. trainees or representatives)<\/em><\/td><td class=\"table-col2\">Possible with:<br \/>1) Patient consent<br \/>2) Duly completed and signed confidentiality form<\/td><\/tr><tr><td class=\"table-col1\"><strong>Production of reports<\/strong><br \/><em>(e.g.: monthly census of operative complications)<\/em><\/td><td class=\"table-col2\">Presented in an anonymous form.<\/td><\/tr><\/tbody><\/table>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_j5wx277   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p>All employees, service providers and subcontractors of Cliniques Marois who may have access to PI and sensitive PI have signed confidentiality agreements in favor of Cliniques Marois. They also undertake to comply with this policy and ensure that PI and sensitive PI are processed throughout their life cycle in the most secure manner possible.<\/p><p>If Cliniques Marois intends to use PI and sensitive PI for other purposes (e.g. clinical study or survey), the person concerned must give their consent.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_048i228   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>4. Archiving of PI and sensitive PI:<\/h3><p><em>Patients<\/em><br \/>Les Cliniques Marois retains the PI and sensitive PI that it holds on an individual for the period necessary to achieve the purposes for which it was requested. This period may vary depending on the person concerned and the reasons for which they were in contact with Les Cliniques Marois &#8211; all of which is archived on secure platforms.<\/p><p>The PI and sensitive PI that Les Cliniques Marois holds concerning patients is stored on a cloud-based software called \u201cElectronic Medical Record\u201d (EMR), whose data is encrypted. The EMR itself is hosted in the Telus Health (Canada) Ltd. data center located in Canada.<\/p><p>Voice communications between physicians, staff and patients take place on the cloud-based software and the recordings are hosted in the MCJ Conseil data center, also located in Canada.<\/p><p>Access management to the EMR and the telephone system is administered by management and supervised by the PI Privacy Officer.<\/p><p>Some patient PI may be stored on the POS platform used to collect payments; Les Cliniques Marois limit access to those who need it in the exercise of their functions (particularly accounting) and the password is changed several times a year.<\/p><p><em>Employees, subcontractors and consultants<\/em><br \/>The PI and sensitive PI of employees, subcontractors and consultants are stored on secure cloud servers.<\/p><p>Les Cliniques Marois limits access to PI and sensitive PI contained to those who need it in the performance of their duties. It creates as many accesses and sites as necessary to ensure that access to PI and sensitive PI is personalized and limited for different employees.<\/p><p>To this end, each user is granted access with a unique password and dual authentication. Any person who is no longer an employee, subcontractor or no longer needs to have access to PI and sensitive PI has their access revoked in a timely manner.<\/p><p>The management of these accesses is administered by management and supervised by the Personal Information Officer.<\/p><p>Details regarding the <strong>archiving<\/strong> of personal data:<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_cpez512   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <table class=\"policy-table\" cellspacing=\"0\"><tbody><tr><td class=\"table-col1\"><strong>Duration of archiving of PI and sensitive PI<\/strong><\/td><td class=\"table-col2\">For patients, 10 years after the medical record becomes inactive. For employees, 6 years after the record becomes inactive.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Staff involved in the archiving process<\/strong><\/td><td class=\"table-col2\">Management and some service supervisors.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Paper documents<\/strong><\/td><td class=\"table-col2\">Locked desks, cabinets and filing cabinets of some supervisors.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Computer technologies<\/strong><\/td><td class=\"table-col2\">DME &amp; various cloud software.<\/td><\/tr><\/tbody><\/table>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_44b0485   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <p><em>Cookies<\/em> <br \/>The use of <strong>cookies<\/strong> on our website is now the norm. Cookies only store information related to your movements on our site and do not have the capacity to retrieve other types of data from your hard drive. The information transmitted does not allow you to be personally identified and is only collected due to the technological requirements inherent in Internet browsing and is used for statistical purposes. <strong>You can set your browser to block cookies at any time.<\/strong> However, this action may deprive you of certain functions offered on our site.<\/p><p><em>Google Analytics<\/em> <br \/>This site uses Google Analytics, which is a web audience measurement tool. Google Analytics collects information about your browsing on the Cliniques Marois site, which is stored on servers located in the United States. Google may communicate this information to third parties in the event of a legal obligation or when these third parties process the data on its behalf.<\/p><p><strong>The information collected by the tool includes, for example:<\/strong><\/p><ul><li>The pages you visit;<\/li><li>The date, time, duration and frequency of your visits;<\/li><li>The links you click on;<\/li><li>The type of operating system on your computer and the language used;<\/li><li>The name of your Internet service provider and your geographic location (region);<\/li><li>Your IP address is also collected, but it is anonymized (truncated) to ensure the confidentiality of information about you. Anonymizing an IP address prevents an Internet user from being identified by it.<\/li><\/ul><p>Google uses the information collected only to produce statistics and reports on navigation on this site, which allows us to improve our online platforms. Google will not, under any circumstances, link the information collected on this site with any other data it stores.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_gnmu464   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>5. Destruction of PI and sensitive PI:<\/h3><p>Once the purposes for which the PI and sensitive PI were requested have been fulfilled, Les Cliniques Marois will ensure that the PI and sensitive PI are destroyed or that they are anonymized irreversibly and securely.<\/p><p>Details regarding the <strong>destruction<\/strong> of personal data:<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_1gbv685   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <table class=\"policy-table\" cellspacing=\"0\"><tbody><tr><td class=\"table-col1\"><strong>Personnel involved in the destruction process<\/strong><\/td><td class=\"table-col2\">Management and some department supervisors.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Paper documents<br \/><\/strong><em>(e.g. confidential postal mail)<\/em><\/td><td class=\"table-col2\">Digitization in a secure platform and systematic shredding.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Downloads or copies of documents<br \/><\/strong><em>(e.g. patient emails)<\/em><\/td><td class=\"table-col2\">Systematic downloading to a secure platform and regular emptying of trash bins.<\/td><\/tr><tr><td class=\"table-col1\"><strong>Cloud data<br \/><\/strong><em>(e.g. patient records over 10 years old)<\/em><\/td><td class=\"table-col2\">Permanent removal of sensitive PI and PI from the secure platform.<\/td><\/tr><\/tbody><\/table>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_xkzj510   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>6. Rights of access, rectification and withdrawal of consent:<\/h3><p>Individuals about whom Les Cliniques Marois holds PI and sensitive PI have the right, at any time, via the procedure described in section 7, to contact Les Cliniques Marois to:<\/p><ul><li>Know the PI and sensitive PI that Les Cliniques Marois holds about them;<\/li><li>Know the categories of individuals within Les Cliniques Marois who have access to the personal information held about them;<\/li><li>Request access to the PI and sensitive PI held about them;<\/li><li>Request a correction to the PI and sensitive PI if it is incomplete or inaccurate;<\/li><li>Request that Les Cliniques Marois stop using the PI and sensitive PI concerning them (implying a file closure);<\/li><li>Request that the PI and sensitive PI concerning them be anonymized (as part of a case study, for example).<\/li><\/ul><p>The Marois Clinics will respond to these requests within a maximum period of thirty (30) days unless Law 25 provides for an exception.<\/p>    <\/div>\n<\/div>\n<!-- \/module text --><!-- module text -->\n<div  class=\"module module-text tb_tn9v139   \" data-lazy=\"1\">\n        <div  class=\"tb_text_wrap\">\n        <h3>7. Process for handling requests relating to this policy:<\/h3><p>Any person who wishes to file a request or modification or complaint in connection with the governance of Cliniques Marois regarding the management of PI and sensitive PI, must do so in writing to the Personal Information Privacy Officer whose address is described in section 1 above.<\/p><p>The request must include the following elements, without which it will not be considered admissible:<\/p><ul><li>Name;<\/li><li>Address;<\/li><li>Telephone number;<\/li><li>Email;<\/li><li>Reasons for the request.<\/li><\/ul><p>The PI Privacy Officer will acknowledge receipt to the applicant as soon as possible.<\/p><p>Any request received will be treated confidentially.<\/p><p>Within thirty (30) days of receipt of the complete request, the PI and sensitive PI Privacy Officer must process it, then send a final, written and reasoned response.<\/p>    <\/div>\n<\/div>\n<!-- \/module text -->        <\/div>\n                        <\/div>\n        <\/div>\n        <\/div>\n<!--\/themify_builder_content-->","protected":false},"excerpt":{"rendered":"<p>As part of its activities, Les Cliniques Marois collects, uses, archives and destroys personal information about patients who use its services. Les Cliniques Marois are subject to the application of Law 25 on the protection of personal information in the private sector. To this end, Les Cliniques Marois are responsible for ensuring the protection of [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-singlepage.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-57339","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/pages\/57339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/comments?post=57339"}],"version-history":[{"count":0,"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/pages\/57339\/revisions"}],"wp:attachment":[{"href":"https:\/\/lescliniquesmaroisurologue.ca\/en\/wp-json\/wp\/v2\/media?parent=57339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}