The Electronic Health Record Sharing System Ordinance came into effect on 2 December 2015. The Ordinance provides the legal framework for public and private hospitals and other healthcare providers to collect, share and keep patient’s electronic health record (eHR) through the Electronic Health Record Sharing System (the eHRS System) upon obtaining the informed consent of the patient and proper registration. The eHRS System is expected to launch in the first quarter of 2016.
The key features of the Ordinance include:
- The EHRS System will be operated, maintained and regulated by the Commissioner for the Electronic Health Record (the eHR Commissioner). In order to participate in the eHRS System, patients and healthcare providers may, on a voluntary basis, apply for registration with the eHR Commissioner.
- Healthcare provider is defined as any person providing an activity performed by a healthcare professional to an individual for assessment, maintenance, diagnosis or treatment of illness or disability. Examples of a healthcare professional include a registered medical practitioner, dentist, pharmacist, nurse, physiotherapist, chiropractor and Chinese medicine practitioner.
- A patient must be aged 16 or above in order to register with the eHRS System and provide consent to share any eHR. For any patient under 16 (or is aged 16 or above but incapable of giving consent), the patient’s parent (or guardian) may act on the patient’s behalf for the purposes of registration and giving of consent.
- When applying for registration with the eHRS System, a patient is required to give consent to the eHR Commissioner to share the patient’s eHR in the System with any registered healthcare provider for both healthcare and referral purposes (Joining Consent). However, upon the patient’s registration, the System will not automatically allow sharing of any patient’s eHR by a healthcare provider unless the patient has given a separate consent to such healthcare provider to provide the patient’s eHR to and obtain it from the eHRS System (Sharing Consent).
- It should be noted that the patient is deemed to have given a Sharing Consent to the Department of Health and the Hospital Authority when providing the Joining Consent upon registration.
- A patient may at any time withdraw its registration with the eHRS System or revoke a Sharing Consent given to any healthcare provider (except for any Sharing Consent given to the Department of Health and the Hospital Authority).
- Only sharable data in any eHR can be shared in the eHRS System. Sharable data includes both health data and personal particulars of the patient. Whilst there are no specific categories of sharable data provided in the Ordinance, the eHR Commissioner’s website set out examples including name, date of birth, ID number, adverse reactions, diagnosis, birth and immunisation records, laboratory and radiology results, and referral between healthcare providers.
- The eHR Commissioner has the power to (i) issue code of practice on compliance with the Ordinance; and (ii) in the event that a healthcare provider contravenes any provision of the Ordinance or code of practice, suspend or revoke the registration of a healthcare provider, or require the production of records and documents by a healthcare provider.
- A healthcare provider provided with a Sharing Consent is required to take reasonable steps to restrict access to a patient’s eHR to healthcare professionals performing services for the patient and to restrict such access to relevant health data of the patient.