Canadian Medical Records Privacy Law
Exam Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
Pdf
1. A physician practicing in a large urban hospital in Canada receives a
subpoena in connection with a civil lawsuit involving a former patient.
The physician is uncertain whether the subpoena alone authorizes
disclosure of the patient’s complete medical file, including psychiatric
notes and HIV-related laboratory results. Under Canadian medical
privacy principles and provincial health information statutes, which of
the following actions best reflects the physician’s legal and ethical
obligations before releasing the records?
A. Immediately disclose the entire file because a subpoena automatically
overrides all privacy protections
,B. Refuse to disclose any records under any circumstances because medical
confidentiality is absolute
C. Review the subpoena carefully, disclose only the information legally
required, and seek legal or privacy guidance where scope or privilege is
unclear
D. Send the records directly to opposing counsel without notifying the
hospital privacy office
Rationale: Canadian privacy law generally permits disclosure pursuant to
lawful court orders or subpoenas, but healthcare professionals must
ensure that only the minimum necessary information is released. Sensitive
information may require additional scrutiny, and providers should confirm
the legal validity and scope of the request before disclosure.
2. A nurse working in a rehabilitation facility accesses the electronic
medical record of her former spouse out of personal curiosity after
learning he was admitted following a workplace injury. She does not
alter the record or share the information with others. Which of the
following best describes the likely legal characterization of her conduct
under Canadian health information privacy legislation?
A. Acceptable conduct because no information was disclosed externally
B. Acceptable if she was employed by the same healthcare organization
C. A minor workplace issue but not a privacy breach
,D. Unauthorized access constituting a privacy violation even without
disclosure to third parties
Rationale: Canadian privacy laws governing personal health information
prohibit unauthorized access as well as unauthorized disclosure. Viewing
records without a legitimate clinical or operational purpose is commonly
treated as “snooping” and may lead to disciplinary action, regulatory
consequences, and penalties.
3. A patient requests a copy of her complete hospital chart, including
nursing notes, diagnostic imaging reports, and consultation letters.
The hospital health records department delays responding for several
months without explanation. Which statement most accurately
reflects the patient’s legal rights under Canadian health information
access laws?
A. Patients generally have no right to access hospital records created by
healthcare professionals
B. Patients generally have a statutory right to timely access their personal
health information subject to limited exceptions
C. Hospitals may indefinitely delay access requests whenever records are
archived
D. Only physicians may authorize release of records directly to patients
, Rationale: Provincial and territorial health information laws generally
provide patients with the right to access their own personal health
information within legislated timelines. Delays must usually be justified,
and limited exceptions apply only in specific circumstances such as risk of
serious harm.
4. A healthcare administrator sends a spreadsheet containing identifiable
patient billing data to the wrong email recipient due to an
autocomplete error. Under Canadian privacy law principles, what is
the most appropriate immediate organizational response?
A. Delete the sent email from the sender’s account and take no further
action
B. Wait to see whether the unintended recipient uses the information
improperly
C. Contain the breach, assess the risks, notify affected individuals where
required, and document the incident
D. Publicly disclose the breach on social media to demonstrate transparency
Rationale: Canadian breach-management obligations generally require
organizations to promptly contain breaches, evaluate risks, maintain
records, and notify affected individuals and regulators where statutory
thresholds are met. Proper documentation and mitigation are essential
compliance steps.
Exam Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2026 Q&A| Instant Download
1. A physician practicing in a large urban hospital in Canada receives a
subpoena in connection with a civil lawsuit involving a former patient.
The physician is uncertain whether the subpoena alone authorizes
disclosure of the patient’s complete medical file, including psychiatric
notes and HIV-related laboratory results. Under Canadian medical
privacy principles and provincial health information statutes, which of
the following actions best reflects the physician’s legal and ethical
obligations before releasing the records?
A. Immediately disclose the entire file because a subpoena automatically
overrides all privacy protections
,B. Refuse to disclose any records under any circumstances because medical
confidentiality is absolute
C. Review the subpoena carefully, disclose only the information legally
required, and seek legal or privacy guidance where scope or privilege is
unclear
D. Send the records directly to opposing counsel without notifying the
hospital privacy office
Rationale: Canadian privacy law generally permits disclosure pursuant to
lawful court orders or subpoenas, but healthcare professionals must
ensure that only the minimum necessary information is released. Sensitive
information may require additional scrutiny, and providers should confirm
the legal validity and scope of the request before disclosure.
2. A nurse working in a rehabilitation facility accesses the electronic
medical record of her former spouse out of personal curiosity after
learning he was admitted following a workplace injury. She does not
alter the record or share the information with others. Which of the
following best describes the likely legal characterization of her conduct
under Canadian health information privacy legislation?
A. Acceptable conduct because no information was disclosed externally
B. Acceptable if she was employed by the same healthcare organization
C. A minor workplace issue but not a privacy breach
,D. Unauthorized access constituting a privacy violation even without
disclosure to third parties
Rationale: Canadian privacy laws governing personal health information
prohibit unauthorized access as well as unauthorized disclosure. Viewing
records without a legitimate clinical or operational purpose is commonly
treated as “snooping” and may lead to disciplinary action, regulatory
consequences, and penalties.
3. A patient requests a copy of her complete hospital chart, including
nursing notes, diagnostic imaging reports, and consultation letters.
The hospital health records department delays responding for several
months without explanation. Which statement most accurately
reflects the patient’s legal rights under Canadian health information
access laws?
A. Patients generally have no right to access hospital records created by
healthcare professionals
B. Patients generally have a statutory right to timely access their personal
health information subject to limited exceptions
C. Hospitals may indefinitely delay access requests whenever records are
archived
D. Only physicians may authorize release of records directly to patients
, Rationale: Provincial and territorial health information laws generally
provide patients with the right to access their own personal health
information within legislated timelines. Delays must usually be justified,
and limited exceptions apply only in specific circumstances such as risk of
serious harm.
4. A healthcare administrator sends a spreadsheet containing identifiable
patient billing data to the wrong email recipient due to an
autocomplete error. Under Canadian privacy law principles, what is
the most appropriate immediate organizational response?
A. Delete the sent email from the sender’s account and take no further
action
B. Wait to see whether the unintended recipient uses the information
improperly
C. Contain the breach, assess the risks, notify affected individuals where
required, and document the incident
D. Publicly disclose the breach on social media to demonstrate transparency
Rationale: Canadian breach-management obligations generally require
organizations to promptly contain breaches, evaluate risks, maintain
records, and notify affected individuals and regulators where statutory
thresholds are met. Proper documentation and mitigation are essential
compliance steps.