OnSPARK Privacy Policy

1. Introduction and Purpose 

OnSPARK (Ontario Supporting Partnerships to Advance Care and Knowledge in Long-Term Care) is committed to protecting the privacy, confidentiality, and security of information entrusted to the platform. 

OnSPARK operates through two distinct environments: 

  1. A “Secure Server” that is operated by McMaster University and is physically located in the McMaster Children’s Hospital that provides the secure receipt, storage, processing, and analysis of raw and identifiable health and other confidential data for approved purposes.  It holds personal health information (PHI), and other confidential and non-confidential data.  

  2. A secure cloud system with user-specific passwords that includes a web accessible “Portal”. The portal provides authorized users with access to processed, de-identified, aggregated, and/or home- or unit-level information and insights.  The portal does not house PHI.   

These environments have different purposes, data, access controls, and governance requirements. This Privacy Policy applies to OnSPARK as a whole, while the sections below describe the privacy practices specific to each environment. 

The institutional disclosure and use of data contributed by participating long-term care (LTC) homes is governed by applicable Data Sharing Agreements (DSAs) and OnSPARK governance policies. Individual access to and use of the Portal is additionally governed by the OnSPARK Portal Terms of Use. 

OnSPARK operates in accordance with the Personal Health Information Protection Act, 2004 (PHIPA) and other applicable privacy and information-security requirements. 

2. Privacy Principles Applying Across OnSPARK 

The following principles apply to both the Secure Server and the Portal: 

Data Minimization 

OnSPARK collects, uses, and makes available only the information necessary for an authorized purpose. 

Purpose Limitation 

Information is used only for purposes authorized under applicable agreements, governance requirements, and applicable law. 

Access Control 

Access is limited according to a person's role, responsibilities, and authorized purpose. Access is not granted by default. 

Confidentiality 

Individuals with access to OnSPARK information are expected to protect its confidentiality and use it only as authorized. 

End to End Encryption  

Information is protected using encryption during transmission and while stored within OnSPARK environments. Encryption safeguards are applied throughout the data lifecycle, with protections appropriate to the sensitivity of the information and the environment in which it is managed. 

Data Stewardship 

Participating Long-Term Care homes retain their rights and responsibilities in relation to data they contribute, consistent with applicable DSAs and governance requirements. 

Security 

Administrative, technical, and physical safeguards are used to protect information against unauthorized access, use, disclosure, alteration, loss, or destruction. 

Accountability 

OnSPARK maintains governance, oversight, monitoring, and review processes to support responsible handling of information. 

3. Information Managed by OnSPARK

The information handled by OnSPARK varies depending on the environment in which it is processed. 

Information may include: 

  • Health and clinical information relating to residents of participating LTC homes; 

  • Facility and operational information; 

  • Staffing and workforce information; 

  • Quality and performance indicators; 

  • Research and analytical information; and 

  • Information required to administer user accounts and maintain the security and operation of OnSPARK systems. 

The type and level of information accessible to an individual depends on the environment, their role, their authorized purpose, and applicable agreements and approvals. 

4. Data Sharing and Disclosure 

Disclosure and use of information are limited to purposes authorized under applicable DSAs, project approvals, OnSPARK governance requirements, and applicable law. 

Depending on the environment and approved purpose, information may be made available to: 

  • Participating LTC Homes; 

  • Authorized researchers; 

  • McMaster University personnel with an approved role; 

  • St. Joseph's Health System personnel with an approved role; 

  • The Ontario Ministry of Long-Term Care; 

  • Ontario Health; and 

  • Other parties specifically authorized with an approved purpose through applicable agreements and governance requirements. 

Information will not be disclosed to unauthorized third parties, including for marketing or for commercial purposes. Unauthorized parties, including third-party companies, insurance providers, and private-sector organizations, are not permitted to access OnSPARK data. 

5. Research and Quality Improvement 

OnSPARK supports both research and quality improvement (QI) activities. 

Research means research as defined under Section 44 of PHIPA. 

Quality improvement (QI) means activities that fall under Section 37 of PHIPA, excluding Section 37(1)(j). 

The OnSPARK Portal is a QI initiative and is designed to support quality improvement activities using processed and aggregated information. It does not provide access to the raw or identifiable information held within the Secure Server. 

The Secure Server supports the management and use of information for approved OnSPARK activities, which may include both research and QI. 

6. Data Retention and Removal 

Information is retained only for as long as required for its authorized purpose and in accordance with applicable agreements, project requirements, and OnSPARK policies. Participating homes may have rights and responsibilities regarding the information they contribute, including rights relating to withdrawal or removal, as established in the DSA and Data Removal Policy.  

7. Security Incidents 

OnSPARK maintains processes for identifying, investigating, managing, and reporting privacy and security incidents. Where a privacy breach or other security incident occurs, OnSPARK will take appropriate steps to contain and investigate the incident, assess the potential impact, and make any notifications required by applicable law, agreements, policies, or governance requirements. 

Incident management may involve the affected LTC Home, McMaster University's Privacy Office, information-security personnel, and appropriate OnSPARK governance bodies. 

8. Oversight and Accountability 

OnSPARK operates under a governance framework that includes representatives from participating LTC Homes, McMaster University, St. Joseph's Health System, and other appropriate experts. 

McMaster University's privacy and information-security functions provide institutional oversight and support, including privacy impact assessments and threat and risk assessments where applicable. 

OnSPARK's governance framework, policies, agreements, and security controls are reviewed periodically and updated as necessary. 

The following outlines the two distinct environments: 

9. Secure Server

9.1 Purpose

The Secure Server that is operated by McMaster University and is physically located in the McMaster Children’s Hospital, located in Ontario, Canada. It provides the secure receipt, storage, processing, and analysis of raw and identifiable health and other confidential data for approved purposes.  It holds personal health information (PHI), and other confidential and non-confidential data. The Secure Server supports approved activities including research, quality improvement, data processing, linkage, analysis, and other activities authorized through applicable agreements and OnSPARK governance processes. 

9.2 Information Collected

OnSPARK collects and processes health and administrative data from participating LTC homes to support quality improvement, research, and policy development. 

 Information may include: 

  • De-identified resident health and clinical information (including month and year of birth), clinical assessments, diagnoses, treatment history, medication prescriptions, administration records, immunization status, hospitalizations, emergency transfers, and care outcomes; 

  • Facility-level data, such as disease surveillance, infection control measures, quality indicators, and operational performance metrics; 

  • Staffing and workforce information; 

  • Longitudinal and linked datasets; and 

  • Other confidential information authorized under the applicable DSA or project approvals. 

Access to this information is restricted to specifically authorized individuals and is governed by applicable data sharing agreements, project approvals, privacy requirements, and OnSPARK policies. 

9.3 De-identification and Processing

Data received by OnSPARK may initially contain identifiers required for authorized data processing. These identifiers are protected through encryption and other controlled transformation processes before the data are made available for research or analytical use. 

Where data are de-identified for analysis or Portal use, the de-identification process is completed through controlled processes before the resulting information is made available through the Portal. The Secure Server may therefore contain information that is not present in the Portal, including source data containing identifiers and information required for authorized processing, linkage, and data management. 

9.4 Secure Server Access and Use

Access to information on the Secure Server is granted only where there is an authorized purpose and the required approvals are in place.  

Permitted uses include: 

  • Improving resident care and quality outcomes  

  • Supporting approved comparative effectiveness studies and clinical trials research in LTC. 

  • Providing evidence-based insights for policymakers 

  • Assisting LTC sector in staffing optimization and resource allocation. 

Prohibited uses include: 

  • Marketing or commercial exploitation of resident data. 

  • Data linkage without explicit ethics board approval. 

  • Re-identification of de-identified data. 

Information on the Secure Server is not available to Portal users simply because they have a Portal account. 

9.5 Secure Server Security

The Secure Server is hosted within McMaster University’s on-premises environment on Tier 4 server infrastructure, designed to provide high levels of availability, redundancy, and physical infrastructure resilience. The Secure Server is protected through administrative, technical, and physical safeguards appropriate to the sensitivity of the information it stores and processes.  

Security measures include: 

  • End-to-end encryption for all data in transit and at rest. 

  • Secure data hosting at McMaster University, ensuring compliance with institutional and provincial security policies. 

  • Role-based access control (RBAC) to ensure that only approved users with necessary permissions can access specific datasets. 

  • Institutional physical security controls, including controlled facility and/or badge access 

  • Regular Privacy Impact Assessments (PIAs) conducted by the McMaster University Privacy Office. 

  • Threat and Risk Assessments (TRA) performed by McMaster’s Information Security Office. 

10. Portal 

10.1 Purpose 

The Portal is a separate, secure, cloud-hosted application that functions as a reporting tool and provides authorized users with access to information and insights derived from OnSPARK data. 

The Portal is intended to support activities such as: 

  • Quality improvement; 

  • Operational decision-making; 

  • Care planning; 

  • Workforce planning; 

  • Performance monitoring; and 

  • Benchmarking   

  • Sector learning. 

The Portal is not a clinical record system and does not provide access to the Secure Server or the raw or identifiable information stored within it. 

10.2 Information Available Through the Portal 

The Portal is designed to provide processed information rather than raw source records. The Portal presents information that has been processed, de-identified, aggregated, and/or otherwise prepared for Portal use. This may include home-level and unit-level indicators, rates, averages, trends, and other approved insights. 

The Portal does not provide users with access to: 

  • Individual resident health records; 

  • Individual health events or free-text clinical notes; 

  • Raw identifiable clinical records; 

  • Staff-level personal records; or 

  • Other raw PHI held within the Secure Server. 

The Portal stores limited personal information about authorized users, such as names and work email addresses, for account administration, authentication, access control, and security purposes. 

10.3 Portal Access and Use 

Portal access is role-based and permissioned. 

A user's access is determined by their role, organizational affiliation, authorized purpose, and applicable governance requirements. A Portal account does not provide access to the Secure Server or to information beyond the user's assigned permissions. 

Other authorized users can be approved by OnSPARK governance and access policies.    

10.4 Portal Data Residency and Third-Party Services 

The Portal's database, file storage, application software, and authentication services operate in a Canadian AWS region (ca-central-1) using a Canada-only configuration. 

Limited technical information associated with Portal operation may be processed by third-party services outside Canada. This may include error and usage monitoring information used to maintain and improve the Portal.  

OnSPARK's Portal configuration is designed so that LTC data does not leave Canada. 

10.5 Portal Security 

The Portal is a separate cloud-hosted environment. Portal infrastructure is hosted in Amazon Web Services (AWS) in the Canada (ca-central-1) region. Physical security of the underlying cloud infrastructure is managed by AWS as part of its cloud infrastructure security. All encryption work is handled by AWS's secure services. Canadian data residency is maintained through the use of our ca-central-1 (Montreal, Canada) AWS infrastructure. AWS KMS also meets FIPS 140-3 Level 3, a strict government security standard. 

The Portal uses safeguards appropriate to the information it processes, including: 

  • Encryption in transit and at rest; 

  • Role-based access controls; 

  • Individually identifiable accounts; 

  • Authentication and session controls; 

  • Access provisioning and deactivation procedures; 

  • Database and network isolation; 

  • Security monitoring and logging; 

  • Vulnerability and security testing; and 

  • Regular privacy and security assessments. 

Portal access and activity may be logged and monitored for security, administration, compliance, and investigation of suspected unauthorized activity. 

 10.6 Portal Users 

Individuals accessing the Portal must comply with the OnSPARK Portal Terms of Use, which establish requirements for individual account security, confidentiality, permitted use, prohibited activities, downloading and sharing information, and other conditions of Portal access. 

The Portal Terms of Use do not provide access to or govern use of the Secure Server. 

10.7. Cookies, Technical Information, and Portal Analytics 

The Portal may use cookies and technical analytics tools to support authentication, security, system performance, and usability. 

Technical information may include information such as IP address, browser and device information, pages accessed, and usage activity. 

Where third-party monitoring or analytics services are used, they are configured to limit the collection of personal and health information. Portal usage information is not intentionally combined with resident health information. 

Users may be able to limit or disable certain cookies through their browser settings; doing so may affect Portal functionality. 

11. Changes to This Privacy Policy 

OnSPARK may update this Privacy Policy to reflect changes to its privacy practices, technology, governance framework, applicable law, or the services it provides. The current version of this Privacy Policy will be made available through the OnSPARK website. 

Where appropriate, participating organizations and affected users will be notified of material changes. 

12. Contact Us 

For questions about this Privacy Policy, OnSPARK's privacy practices, or the handling of information within OnSPARK, contact: onspark@mcmaster.ca