Privileges without privacy conditions are incomplete privileges
Health privacy incidents often involve people who are not “employees” in the simple sense. They are professional staff: physicians and others credentialed to practise in the hospital, bound by bylaws and appointment processes more than by a standard employment agreement. If your privacy program is built only for payroll staff, you are governing half the risk surface.
PHIPA Decision 298 puts this in writing. Alongside the first administrative monetary penalties — and the IPC’s public discussion of the case — the Commissioner recommended that hospitals update professional staff bylaws to include more direct, explicit references to privacy obligations and to the requirement that professional staff comply with hospital privacy policies. The IPC also recommended that professional staff receive copies of those privacy policies before they apply for appointment and each year before reappointment.
That is practical governance. It ties access to PHI to a recurring professional gate.
Why bylaws beat one-off training emails
Training is necessary and insufficient. Professional staff are busy, mobile across sites, and sometimes psychologically closer to independent contractors than to employees. Bylaws and credentialing processes carry a different weight:
- They are part of the legal and professional relationship with the hospital.
- They can condition appointment and reappointment.
- They can support privilege restriction when privacy duties are breached.
- They create a paper trail of notice that is hard to dismiss as “I never saw the intranet post.”
In the Decision 298 pattern, hospital privileges enabled access to a shared EHR that then fed private clinic solicitation. The technical permission came from the privileged role. Governance has to sit at that same junction.
What I want to see in a bylaw and credentialing redesign
1. Explicit privacy duty clauses Not a vague “comply with hospital policies,” though you need that too. Spell out purpose limitation: access only for authorized care, hospital functions, and other PHIPA-permitted purposes — not for independent commercial solicitation or personal curiosity.
2. Policy delivery before appointment and reappointment The IPC’s recommendation is operationally clear. Build it into the credentialing checklist:
- Current privacy policy package provided and acknowledged.
- Confidentiality agreement executed.
- Training completion verified or scheduled with a hard deadline.
- Disclosure of private practice activities that could create conflict with hospital PHI use.
3. Cross-site and shared-EHR language Many physicians practise in ecosystems of shared records. Bylaws should anticipate that access may technically reach patients the physician is not treating — and state that technical reach is not ethical or legal permission.
4. Investigation and privilege consequences Link serious privacy breaches to interim privilege suspension pathways already familiar from other professional conduct issues. Privacy should not be the slow cousin of impairment or fraud processes.
5. Alignment with medical leadership MAC, credentials committee, chief of staff, privacy office, and legal need one playbook. If privacy investigates in a silo while credentials waits for a perfect final report, patients stay exposed.
Reappointment as an annual control test
I treat reappointment like an access recertification campaign:
- Pull a sample of high-access professional staff and verify acknowledgments are real.
- Confirm departed or inactive staff lose EHR access on a defined timeline.
- Ask department chiefs to flag dual-practice risk areas (cosmetics, elective procedures, parallel clinics).
- Report completion metrics to the quality or risk committee, not only to privacy.
- Sample whether acknowledgments match the current policy version, not a five-year-old PDF.
If reappointment is a rubber stamp, privacy language in the bylaws will be decorative.
Connecting back to AMPs and accountability
Ontario’s AMP era — starting with Decision 298 and reinforced by later cases such as the second AMP in Decision 334 — rewards organizations that can show structure. Bylaws will not immunize a hospital against every agent’s misconduct. They will help show the custodian set clear expectations for privileged professionals and had a governance route to enforce them. That is part of demonstrable accountability under the AMP guidance framework.
If you are in a multi-hospital shared EHR, coordinate. A physician can be clean at one site and risky at another if appointment packages and audit practices diverge. Regional privacy and credentials leaders should compare language on commercial secondary use, audit cooperation duties, and interim suspension triggers. Inconsistency is where clever misuse hides.
A practical rewrite sprint
When I help hospitals update bylaws, we do four meetings:
- Privacy + legal draft plain-language privacy duty clauses.
- Credentials committee stress-tests operational feasibility.
- Medical leadership pressure-tests enforcement realism.
- Board or MAC approval with a communication plan for existing staff.
Do not bury the change in a 200-page package with no cover note. Physicians deserve a one-page summary: what changed, why Decision 298 matters, and what reappointment will now require.
Actionable takeaway
Credentialing is privacy infrastructure. Decision 298’s bylaw recommendations are a checklist item with teeth: put privacy into professional staff rules, deliver policies at appointment and reappointment, and make privileges conditional on respecting PHI purpose limits. Start from the decision text and the IPC summary. Hospitals that leave privacy in the employee handbook alone should not be surprised when the next incident involves someone who never thought the handbook applied to them. Fix the bylaws while you still have time to do it as governance, not as remediation under investigation. When did your organization last revise professional staff bylaws with privacy counsel and the credentials committee in the same room?