Northwest Territories · Health Information Act

Run the NWT Health Information Act, including its PIA duty

For custodians under the HIA — the territorial health and social services system, health authorities, and practitioners — AccessPoint manages access and correction, mandatory breach notification, and the statutory privacy impact assessments the Act requires before a new system goes live.

Northwest Territories — HIA at a glance

Access deadline
30 days, with an extension in the circumstances the Act allows
Correction
Correction, or a statement of disagreement where refused
Breach duty
Mandatory — notice to the individual and to the Commissioner
PIA duty
Statutory, before a new or substantially modified health information system
Oversight
NWT Information and Privacy Commissioner
Languages
English, French

Built for Northwest Territories — HIA

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Access to one's own record

Take a patient's access request from intake to release on the 30-day clock, with the Act's grounds for refusal applied and cited on each withheld passage.

Correction requests

Run correction end to end — the decision, the correction or the refusal with reasons, and the individual's statement of disagreement kept with the record.

Mandatory breach notification

The NWT does not leave breach notice to discretion. Log the breach, assess it, and work a live checklist covering both the affected individual and the Commissioner.

The statutory PIA

The Act requires a privacy impact assessment before a new or substantially modified health information system goes live. Run it as a real assessment — questionnaire, risks, mitigations, sign-off — not a document someone remembers to write.

Custodian duties

Collection, use, and disclosure recorded with their purpose and authority, so a disclosure made years ago can still be explained.

In your own tenant

Health information stays inside your own Microsoft 365 and Azure tenant — no third-party cloud, no vendor access, and no data leaving Canada.

A PIA the statute actually demands

Most privacy laws recommend a PIA. The NWT Health Information Act requires one before the system goes live.

Across most of Canada, the privacy impact assessment is policy — expected by a treasury board, encouraged by a commissioner, occasionally skipped when a project runs late. The Northwest Territories put it in the statute: a custodian must assess a new or substantially modified health information system before implementing it. That changes what the assessment has to be. A slide deck written after go-live does not satisfy a legal precondition; a dated, versioned, signed-off assessment with its risks tracked to closure does. AccessPoint runs the HIA PIA as a first-class case — questionnaire, sections assigned to the people who can actually answer them, an embedded risk register, and a summary a Commissioner can read — so the duty is discharged on the record rather than asserted after the fact.

Before go-live A dated assessment that precedes implementation, as written.
Risks to closure Mitigations owned and tracked, not listed and forgotten.
Mandatory breach notice Individual and Commissioner, on one live checklist.

Configured out of the box

Installing the ca-nt-hia jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The NWT Health Information Act as the legal-authority spine
  • The 30-day access clock with the Act's extension grounds and the territorial holiday calendar
  • The Act's grounds for refusing access, colour-coded for redaction and citable line by line
  • Correction requests, refusals with reasons, and statement-of-disagreement handling
  • Mandatory breach notification workflows for both the individual and the Commissioner
  • The statutory PIA questionnaire for new and substantially modified health information systems
  • Custodian collection, use, and disclosure rules with purpose and authority recorded
  • Bilingual correspondence templates carrying the statutory wording

Northwest Territories — HIA Questions

What makes the NWT Health Information Act different?

Two duties stand out. Breach notification is mandatory rather than discretionary — both the affected individual and the Commissioner must be notified where the Act requires it. And a privacy impact assessment is a statutory precondition to implementing a new or substantially modified health information system, not merely good practice. AccessPoint ships both as real workflows.

How does the statutory PIA work in AccessPoint?

As a full assessment case: a questionnaire scoped to the system under review, sections assigned to the people who can answer them, an embedded risk register where each risk carries a mitigation and an owner, and a versioned, dated summary with sign-off. Because it is dated and versioned, the assessment demonstrably precedes implementation — which is what the Act asks.

Do you also run the territory's ATIPP Act?

Yes — as a separate pack. NWT's ATIPP Act governs access to records held by public bodies and carries a 20-business-day clock with order-making oversight; the HIA governs health information held by custodians. An organization subject to both runs each on its own rules on one platform.

Where does health information reside?

Entirely within your own Microsoft 365 and Azure tenant. Records, requests, assessments, and audit history never leave your control — no third-party cloud, no vendor access, and no cross-border data transfers.

Run the NWT Health Information Act in Your Own Tenant

Try AccessPoint free for 30 days, configured for Northwest Territories custodians. No credit card required.

Start Free Trial