Skip navigation

Good Practice: The Privacy Life Cycle of a Patient’s Physiotherapy Record

This article introduces the concept of a successor custodian. Physiotherapists need to know:

  • Regulated members of the College of Physiotherapist of Alberta are designated as custodians under the Act.
  • Unless you have a formal document (contract, job description) that designates you as an affiliate to a custodian, you are a custodian under the Act and are required to fulfill the duties and responsibilities of a custodian. 
  • Health information must be in the custody and control of a custodian.
  • If you cease to be a registrant of the College of Physiotherapist of Alberta (e.g. you retire, or cancel your registration during a planned leave), you are no longer a custodian. 
  • You must designate someone who is a custodian under the Act as your successor in the event of a planned cancellation of your registration OR an unplanned cancellation due to illness or death.

In order to understand the professional expectations and legislative requirements related to managing a patient’s record we are going to accompany a patient on their journey through a community physiotherapy clinic. We will start from the time they start filling out their intake form to the destruction of their record 10 years after their last appointment with you. The goal is to highlight performance expectations while providing situational examples of the most common issues seen from the College’s perspective. While we go through our patient’s privacy journey it would be helpful to review the College’s Privacy Guide to flush out some of the information included in this article.

The Intake

Joe recently had a bad fall at work and fractured his hip. He was in hospital for a few weeks after surgery and was finally discharged home and is now looking for a physiotherapist near where he lives. With the help of his daughter Clara, he has found your clinic that is just a couple blocks away from his house. You have an online booking process that requires an intake form to be completed prior to his appointment.

What information are you allowed to collect on the intake form?

Legislation requires you to only collect the minimum amount of information needed to provide physiotherapy services and complete necessary transactions. Therefore, you can collect their contact information, relevant health information, and potentially their financial information required for billing of services provided. If your patient wants to access their extended health benefits or it is a claim through the Workers Compensation Board or Motor Vehicle Insurance, it would be expected that they will provide the necessary information to do so. You can ask the patient for their credit card information, but they can refuse to provide it. A physiotherapist or clinic cannot deny service because the client did not agree to provide you with their credit card information via an online booking portal.

Do I need to provide a collection notice on the intake form?

Yes, each client should be aware of the legislated authority under which you are collecting, using, storing, and disclosing their health information. Clients should also be made aware of security measures in place to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction of their health information. 

Every physiotherapist should have a publicly available collection notice that is easily accessible by clients whether on their online intake form, website, via a recorded message, or available to the public at the clinic. Each physiotherapist custodian of health information should also have a privacy officer who is appointed by the custodian to develop and oversee privacy policies and procedures and ensure that a collection notice is in place and is available to both patients and employees. The privacy officer would also be responsible for training the custodian’s affiliates in the privacy policies and procedures, and they would be the main contact for anyone with questions regarding the protections of personal information. You can read more about role of the privacy officer in the College’s Privacy Guide. You can read more about the content to include in a collection statement in Health Information Act Policies and Procedures for Alberta Physiotherapist Custodians.

The Initial Assessment

Joe and Clara arrive at the clinic, and they are guided back into the curtained treatment area. A couple things occur that you need to manage.

  1. As you greet Joe and Clara, they let you know that Joe has had bouts of confusion since his injury and underwent a capacity assessment before his discharge from hospital. It was deemed due to his confusion post-surgery that his daughter will be acting as a co-decision maker. A co-decision maker assists with non-financial decision making such as health care or participation in social activities. Does this change anything for you moving forward from a privacy standpoint?

This may affect consent for treatment more than anything directly related to privacy. As a co-decision maker, Clara can attend medical appointments with her father to assist him in making informed choices about his care. You would need Clara present to discuss the physiotherapy plan of care and obtain consent. There is a distinction between Clara acting as co-decision maker and being a named guardian through Joe’s personal directive as THE decision maker. You can read more about capacity and decision making here.

It would be wise to confirm that the information collected in the intake form is accurate since you don’t know if Joe filled it out or if Clara helped him. If you are concerned about the accuracy and completeness of the information provided on the intake form or during the assessment, as a custodian under the Health Information Act (HIA) you can contact Joe’s physician or other custodians involved in his care to access the health information that the other custodian has in their control about Joe. As a custodian within the circle of care, you do not require consent to access information from other custodians, provided that you have a clear purpose for doing so and are limiting your access requests to that which is needed in order to provide Joe with physiotherapy services. Similarly, you can release information to other custodians for the purpose of providing treatment and care.

  1. Due to the nature of Joe’s confusion, they would rather a more private place to discuss his history as he gets a bit loud and agitated if he gets confused. What should you do?

A physiotherapist must protect their client’s privacy at all times. You should respect their wishes for privacy and if a private treatment room is available you should move to that area to continue your initial assessment. If one is not available, you need to offer options such as conducting the interview in an office, or rebooking their appointment to a time when a private treatment room may be available or when the clinic is less busy.

The Referral

Joe has developed urinary incontinence since his surgery and you would like to refer him to another clinic that is able to more effectively treat this condition.

  1. As already discussed, custodians can share information with other custodians under the HIA. You do not need to get consent to release Joe’s health information to the other custodian for the purpose of providing treatment and care.

The HIA is authority-based legislation. This means that custodians under the Act, and their affiliates, have legislated authority to collect, use, and disclose health information for purposes defined in the Act. One of those purposes is for the provision of treatment and care. As a custodian you have the authority to share information with another custodian who is also providing treatment and care to the client. It is advised that physiotherapists confirm the other party has accepted the referral before disclosing health information to the other provider, to avoid inappropriate disclosure of health information that is under their custody and control.

  1. The referral can be sent by paper, fax, or email. Each option should have their own security safeguards to reduce any risk of the information being compromised and it is up to you to decide which option you would choose.

The HIA requires that reasonable security measures be put in place to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal, or destruction of health information. As custodian of Joe’s information, you must have policies and appropriate safeguards in place to protect Joe’s information. Policies would outline the physical, technical, and electronic security mechanisms you have in place to protect information during collection, use, storage, and transmission. Your privacy policies should also be available in writing for you to provide Joe and Clara if they request it.

It is expected that when sharing Joe’s personal information that it would be done with the highest degree of security and anonymity possible. You may have a preferred method of transmitting health information, or your privacy officer could provide instructions as to which method to use.

Paper: You can hand deliver the referral or mail it. If you choose to hand deliver it, you should think about the risk of the information being stolen and what safeguards you must have in place. The information should be in an unmarked envelope and the person delivering it should keep the envelope safe and secure (i.e., not left on the seat of the car while they run errands) in transit. If you choose to mail it, the post office has several levels of security that you can use such as registered mail.

Fax: Yes, this is still utilized as a method of sending information. You would need to confirm that the fax number is correct prior to sending the information. You should try to mitigate the risk to patients by limiting the amount of health information contained to what is medically necessary.

Electronic Communication: Staff should be trained in the use of encryption methods for sending emails that contain health information and must confirm the email address of the intended recipient. You can access further information on electronic transmission of information from the Office of the Information and Privacy Commissioner (OIPC) here as well as this article by the College here.

The Privacy Breach

You do all your charting on a laptop which you left open after one of Joe’s treatments. The laptop was sitting in the treatment room that your next patient was guided to, giving them access to Joe’s chart notes and medical history. What are your next steps and who can you contact for assistance?

It is your responsibility to report the breach to your privacy officer. Section 60.1 of the HIA contains provisions related to a custodian’s duty to report any loss of, unauthorized access to, or disclosure of individually identifying health information when there is a risk of harm to the individual whose health information is the subject of the breach. Although the custodian is ultimately responsible for the reporting, custodians typically designate a privacy officer to be responsible for ensuring compliance with the Act, and that would include responsibility for assessing risk of harm and addressing privacy breaches. Section 8.1 of the Health Information Regulation provides a list of factors for determining if there is a risk of harm to an individual as a result of such a loss or unauthorized access or disclosure. 

The privacy officer will need to decide on whether or not this incident would meet the threshold for  reporting a privacy breach. If in doubt they can contact The Office of the Information and Privacy Commissioner (OIPC) and work with them to decide what is required. If Joe or his daughter had concerns with the safeguards that were in place or with any of the clinic’s handling of the breach, they should discuss these with the clinic’s privacy officer. The privacy officer’s contact information should be readily available to clients so they would know who to contact in the event of an issue or complaint.

The Discharge

Joe’s confusion has resolved. He has been back to his normal activities and is ready for discharge. He no longer has his daughter as his co-decision maker, but he has decided that he would like to move closer to his grandkids. What are your responsibilities regarding his physiotherapy record?

Records should be retained in a manner that enables any component of the record to be retrieved and copied upon request, regardless of the media (paper or electronic) used to create the record.

Paper charts: You can place Joe’s file as inactive or discharged and ensure it is housed in a manner that is safe and secure. For paper files, reasonable security measures would include having the record locked in a filing cabinet or secured storage room or facility with security alarms in place and limited keys to access the files based on clinic roles. You can also opt to hire an information manager to store paper files on your behalf. The downside of paper charts is that there is no back up in place so there is a risk of charts being lost completely due to fire/flood/etc.

Electronic charts: You have moved the electronic chart to inactive or discharged where it is placed on an encrypted hard drive stored in a safe and secure location. You are expected to have a back up to this stored at another safe and secure location in case the hard drive is lost or compromised. As technology advances over the time, you might need to change storage methods (CDs to USB to cloud based, etc.)

Cloud charts: Cloud based physiotherapy records have information stored on remote servers. You must check with your provider to ensure that there are provisions in place for long term access, for example, in the event they go bankrupt that you would still have access to your patient’s information.

The Clinic Closure

Five years have passed since Joe was discharged and the physiotherapist custodian wants to retire.

The physiotherapist must ensure that action is taken to prevent abandonment of the physiotherapy records. There are several options that a physiotherapist could consider when evaluating how to ensure the records are taken care of according to legislation.

The physiotherapist could continue to act as the custodian of the records and continue to house the charts or hire an Information Manager to do so, until the required retention period has passed. However, a physiotherapist is only a custodian of health information for so long as they are a registered physiotherapist. Once they cancel their registration, they are no longer a custodian under the HIA and must ensure that health information is transferred to a successor custodian. 

If the physiotherapist wishes to designate a successor custodian, they are expected to have a contractual agreement which addresses the requirements of the HIA, such as ongoing access, security, use and destruction of the health information for the duration of the retention period.

If Joe comes looking for a copy of his physiotherapy record, how is he going to find where it is stored?

There are several ways that the physiotherapist could make sure that past patients know where to find their physiotherapy record. The physiotherapist can send out secure communications to patients individually, notifying them of how they can access their information when needed. They may wish to maintain an email that is monitored regularly or provides an automated response as to who to contact should patients need to access records. Or the physiotherapist can post a larger notification in local newspapers or on social media channels which patients may be able to find months or years later.

The Destruction of Patient Records

Another five years have passed so it has officially been 10 years since Joe was discharged. Now that the 10-year retention period has passed what are the expectations for this record?

The physiotherapist must retain Joe’s clinical and financial records for ten (10) years after the last date of service. If Joe was a minor, then clinical and financial records must be retained for ten (10) years past the minor’s 18th birthday. Once the retention period is complete, the physiotherapist must also ensure that those records are disposed of in a manner that maintains privacy and confidentiality of health information.

Physiotherapy records should be destroyed by the custodian, the privacy officer they appointed, or the information manager (at the direction of the custodian). Paper files should be shredded to a degree that they are no longer able to be re-arranged and readable. Hard drives should be physically destroyed by using encryption software and then physically drilling holes through the drive. Agreements should be in place with any clinic EMR software companies that records will be appropriately removed from their servers. Keep records tracking which files were destroyed and when.

With Joe’s physiotherapy record successfully destroyed we have completed the life cycle of the patient record. From intake form to destruction, Joe’s record lifecycle highlights the regulatory and legislated expectations in relation to the protection of Joe’s information and the day to day processes each physiotherapist undertakes in order to abide by these expectations.

Page updated: 16/09/2026