This article was published in April 2022 and reflects information current at the time of publication.
Are there specific privacy and confidentiality considerations an Occupational Health Nurse (OHN) should contemplate before disclosing COVID-19 vaccination statuses?
Health care professionals and OHNs particularly, are already familiar with the professional and ethical obligations that require them to maintain patient confidentiality. An individual’s health information is subject to governing privacy law, whether it is intended to protect personal health information (PHI) specifically or a broader range of identifying personal information (PI). As a general rule, a patient’s vaccination status should be kept confidential. There may, however, be exceptions to the duty to maintain confidentiality, for instance where child protection legislation, public health and communicable disease legislation (such as during the COVID-19 pandemic), or other mandatory-reporting legislation requires it.1
It also remains the OHN’s responsibility, along with the organizations who employ them or retain their services, to safeguard the privacy and confidentiality of the employee’s vaccination status documentation, as this is considered either personal health information or at a minimum, in some jurisdictions, protected personal information. Some of the ways to protect this information may include:
- Collecting only the necessary information, to the extent possible. For instance, some organizations have found it sufficient to collect only the employee’s name and date of vaccination for each dose.2
- Keeping employee vaccination information separate from personnel files.
- Limiting access to vaccination information only to those with a “need to know”.
In all jurisdictions, legislation mandates that PHI or vaccination information is kept secure and used only for the purpose for which it was collected.3
Can an employer access specific information pertaining to an employee’s vaccination status?
In most provinces and territories, an employer may collect, use or disclose PHI with the employee’s consent for reasonable purposes. If requiring COVID-19 vaccination as a condition of work, an employer would typically gather specific information regarding vaccination status, which qualifies as the collection of PHI or PI, depending on the jurisdiction and the workplace.
Depending on the applicable legislation, an OHN may be obliged, upon the request of the employer, to release certain limited health information such as, for example, to advise the employer whether the employee is fit, unfit, or fit with limitations, to perform a particular activity. This could for instance apply to working in an office. Depending on the governing legislation and the type of workplace, the vaccination status could be shared with employer representatives with a “need to know”, provided certain conditions are met.
Many professions have imposed vaccination requirements to mitigate the risks of COVID-19, which would generally qualify as a reasonable purpose. For example, the Government of Canada required vaccination in their federal workforce and federally regulated transportation sector during the pandemic.4
When an employer asks for personal health information about an employee beyond what is required to determine their ability to work, a conflict may arise between the obligation to maintain confidentiality and the duty of loyalty to the employer. If this conflict arises, the legal and professional duty to maintain employee confidentiality and to safeguard the personal health information typically prevails. Some Canadian jurisdictions have legislation preventing an employer from gaining access to an employee’s health information, in the absence of the employee’s written consent.5
What protective safeguards should an OHN use when explaining the necessary disclosure to an employee or employer?
An OHN may be faced with employees who do not agree with their decision to disclose their vaccination status to their employer.
Employers have a duty to provide a safe workplace for all employees, which may include collecting the vaccination status of their employees. OHNs can reassure employees that employers do not have the right to disclose personal health information unless absolutely necessary, and that they collect the least amount of information that is necessary for the policy to be effective. Typically, an OHN can tell their employer if employees have or have not complied with the vaccination policy, without showing the employer the employee’s personal health information (proof of vaccination or accommodation).
Conversely, if faced with a request for access to more employee PHI than what the OHN deems to be necessary, it may be appropriate for the nurse to gently remind the employer of the importance of proper disclosure, and the risks associated with a disclosure that does not respect privacy laws and public health guidelines. In fact, there are a number of possible consequences to the employer in the case of an improper release of personal information or personal health information:
- An employee may commence legal proceedings for negligence, breach of confidentiality or privacy, or defamation.
- A health regulator may institute disciplinary proceedings against regulated health professionals.
- The provincial or territorial privacy commissioner may investigate a complaint.
It would be prudent to become familiar with the applicable legislation and sources of legal, professional and ethical obligations to maintain the confidentiality of PHI and PI at all times. Being equipped with this information could help the OHN be seen as a valuable resource when advising with respect to the extent of PHI disclosure.
The foregoing is an outline of the general principles. Understanding that circumstances can vary significantly with each case, we encourage CNPS beneficiaries to contact CNPS legal counsel for personalized advice if they have any related questions arising in the context of the provision of professional nursing services.
COVID-19 Considerations for Occupational Health Nurses: Vaccination Policy
I have been asked to draft a COVID-19 vaccination policy, where do I start?
Should an OHN be involved in developing a vaccination policy for staff in their workplace, there are certain components that should be included in the policy. Due to the significant privacy risks involved, when creating such a policy, an OHN will want to exercise prudence and care when collecting, sharing, storing or disposing of any information about an employee’s vaccination status. If possible or available, an OHN should consider using the support of their privacy officer and/or legal counsel in preparing the policy. The federal, provincial and territorial privacy commissioners have also released statements regarding the privacy implications of vaccine passports that could be applied to vaccine policies. They explain that the necessity, effectiveness, and proportionality of the vaccine passports have to be established for each specific context6:
- Necessity: the policy must be necessary and evidence-based to achieve the public health purpose, and there is no less privacy-intrusive measure available or as effective;
- Effectiveness: the policy should achieve its specific purpose from the outset until it is no longer required, or it is not considered “effective”;
- Proportionality: the privacy risks must be proportionate to the public health purposes the policy will address.7
When drafting the relevant policy, the OHN may wish to consider the following components:
- The purpose of the policy: this might include setting out the risks of COVID-19 and why vaccination is currently one of the best ways to prevent transmission. The purpose should explain why the policy is necessary, likely to be effective, and proportionate.
- To whom policy will apply, for instance: all employees, volunteers, students, only employees who work onsite, customers, etc.8
- A description of the information that employees will have to provide: As employers are required to collect the least information possible, information collected is typically limited to whether the employee has received a vaccine (including the number of doses), the dates of vaccination, and the type of vaccine.
- A description of the means by which an employee can comply with the policy:
- It may include providing their proof of full vaccination, as outlined by their respective provincial or territorial guideline, or a written medical exemption provided by an approved practitioner.
- It may also include a declaration that an individual requires an accommodation under the human rights code of their jurisdiction, if they are unable to obtain a COVID-19 vaccine.
- It may include providing the results of a rapid antigen test, if applicable in the circumstances.
- Any alternatives for unvaccinated workers, including working from home, continuous use of personal protective employment such as masks, routine testing, etc.
Consequences for non-compliance, i.e. what steps employers will have to take if an employee does not comply with the policy,
How privacy will be protected, and how the information will be stored, secured, and destroyed if necessary. Further, ensure that the least information necessary will be stored and shared in order to protect the privacy of an employee’s PHI.
There may be circumstances in which a court or tribunal would find the collection of PHI more reasonable than others, depending on the nature of the workplace. Factors that could be considered in determining whether a vaccination policy is reasonable include but are not limited to:
- The degree of risk of COVID-19 transmission in the workplace;
- Whether workers are in contact with vulnerable populations (such as elderly or immunocompromised individuals, or children that cannot be vaccinated); and
- The availability and effectiveness of less intrusive measures (such as whether workers can stay two meters apart, whether masks have to be removed in order to perform the job, whether employees are working from home, etc.)
CNPS beneficiaries can contact CNPS at 1-800-267-3390 with specific questions related to their practice to speak with a member of CNPS legal counsel. All calls are confidential.
- Ibid; In terms of communicable disease disclosure, the Ontario legislation explains that physicians and practitioners (including members of the College of Nurses of Ontario), “who, while providing professional services to a person who is not a patient in or an out-patient of a hospital, forms the opinion that the person has or may have a disease of public health significance shall, as soon as possible after forming the opinion, report thereon to the medical officer of health of the health unit in which the professional services are provided.” The communicable diseases may vary depending on the jurisdiction, but typically include the like of coronavirus, hepatitis, rabies, or measles (Health Protection and Promotion Act, R.S.O. 1990, c. H.7, section 25.).
- Eastern Ontario Health Unit, Recommendations for Workplace COVID-19 Vaccination Policies: Information for Employers
- For example, the Personal Health Information Protection Act of Ontario states that “a health information custodian may use personal health information about an individual, (a) for the purpose for which the information was collected or created and for all the functions reasonably necessary for carrying out that purpose, but not if the information was collected with the consent of the individual or under clause 36 (1) (b) and the individual expressly instructs otherwise“;
- Government of Canada, COVID-19 vaccination requirement for federal public servants, 2022.
- Office of the Privacy Commissioner of Canada, Privacy and COVID-19 Vaccine Passports: Joint Statement by Federal, Provincial and Territorial Privacy Commissioners, May 19, 2021
- This is an important distinction as this determination will impact which privacy, employment, or other legislation applies to the policy. (Ibid)
THIS PUBLICATION IS FOR INFORMATION PURPOSES ONLY. NOTHING IN THIS PUBLICATION SHOULD BE CONSTRUED AS LEGAL ADVICE FROM ANY LAWYER, CONTRIBUTOR OR THE CNPS. READERS SHOULD CONSULT LEGAL COUNSEL FOR SPECIFIC ADVICE.