PHIPA Resolutions

HR-10-18

Records of personal health information were found scattered on the streets of Ottawa after being improperly disposed of. Section 12(1) (protection against theft, loss, unauthorized use or disclosure, unauthorized copying, modification or...

Read more

HI07-20

Dispute between a family physician and a medical management company over records of personal health information where the family physician is no longer practising at the location managed by the company. Resolved through informal resoluti...

Read more

HR07-36

A laptop that may have contained the personal health information of up to 590 individuals was stolen from a staff member’s vehicle. The laptop was not encrypted. The matter was resolved by way of informal resolution. Various security m...

Read more

HI07-11

A photocopy of a record of personal health information of an individual was inadvertently sent to the wrong person by a medical file management company. The matter was resolved by way of informal resolution. The photocopy of personal hea...

Read more

HR07-22

Staff member at a hospital disclosed a patient’s personal health information to the patient’s family member. Matter was resolved by way of informal resolution. The hospital has undertaken to review its policies and procedures relatin...

Read more

HI07-3

The Privacy Manager of a hospital contacted the IPC to advise that she found a bag of garbage in front of the hospital that contained personal health information. The garbage originated from a physician’s office, located across the str...

Read more

HR06-62

s. 12 (2) – Notice of loss, etc. Data was incorrectly entered into a provincial database, resulting in data from patients from the Hospital being electronically accessible by staff members at a second facility.

Read more

HR06-51

Possible access to the personal health information of 128 individuals by unauthorized persons due to theft of hard copies of personal health information from a staff member’s vehicle. The material was returned to the staff member a few...

Read more

HR06-36

Access to the personal health information of seven individuals by an unauthorized person, due to an error. Resolved through informal resolution. The custodian retrieved the personal health information and reviewed and revised its policie...

Read more

HR06-53

Access to the personal health information of 17 individuals by unauthorized staff members at a hospital. Resolved through informal resolution. The custodian conducted a review of its policies and procedures that relate to the privacy of ...

Read more

HR-060033-1

Personal health information of three individuals was accessed by an unauthorized person. Resolved through informal resolution. The health information custodian retrieved the personal health information and confirmed that it was not copie...

Read more

HR050028-1

A newspaper article revealed that personal health information had been discarded with household garbage from a local clinic. Complaint resolved by way of informal resolution. Health information custodian agreed to change its policies and...

Read more

HI-060020-1

Newspaper article that contained personal health information of patients in an Emergency Department. Complaint resolved by way of informal resolution. Health information custodian agreed to update their policies and procedures to ensure ...

Read more

HR-060012-1

Personal health information of up to 2, 700 individuals, contained on CDs, stolen from a bone densitometry laboratory. Resolved through informal resolution. The health information custodian created a policy regarding the security of the ...

Read more

HI-060024-1

A not-for-profit organization was unable to locate a diskette containing the personal health information of donors following one of their clinics. Section 12(2) notification requirement met by letter to the affected individuals. Complain...

Read more

HI-050052-1, HI-050053-1, HI-050054-1

A member of the public reported that he had been receiving misdirected faxes from three Community Care Access Centres at his private fax. Section 12(2) notification requirement met by contacting the affected individuals by telephone. Com...

Read more

HI-060009-1

The patient records of a family practitioner were found scattered around the parking lot of a local grocery store. Section 12(2) notification requirement met by letter sent to the affected individuals. Complaint resolved by way of inform...

Read more

HI06-45 Investigative Report

Investigation Report – PHIPA Report HI06-45 released today. August 28, 2006. ((Executive Summary) (PHIPA Report HI06-45)

Read more

Executive Summary of HI-06-45

Investigation Report – PHIPA Report HI06-45 released today. August 28, 2006.

Read more

HI-050049-1

A break-in at the home of a psychologist resulted in the theft of a laptop computer containing the personal health information of four patients. Section 12(2) notification requirement met by verbal notification of the patients’ parents...

Read more

HI-05-0040-1

A report from a member of the public regarding the collection of health card numbers by a local food bank. Complaint resolved by way of informal resolution. Health information custodian agreed to update their policies and procedures to e...

Read more

HI-050046-1

A member of the public advised that upon purchasing the contents of a storage locker, they found 48 boxes of records containing personal health information related to a home-health professionals agency. Complaint resolved by way of infor...

Read more

HI-05-0047-1 A Physiotherapy and Rehabilitation Centre

A break-in at a physiotherapy and rehabilitation centre resulted in the theft of two laptop computers. Section 12(2) notification requirement was met through posting a notice at the centre. Complaint resolved by way of informal resolutio...

Read more

HI-050050-1

A technological glitch causes two patients’ videoconferences to be linked into one another. Section 12(2) notification requirement met by verbal notification of the affected individuals. Complaint resolved by way of informal resolu...

Read more

HI-050055-1

A laptop belonging to an employee of a school board that contains the personal health information of 37 students is stolen. Section 12(2) notification requirement met by sending notification letters to students’ parents. Complaint reso...

Read more

HI-050044-1

A school board employee’s laptop which contained the personal health information for 51 students was reported stolen. Section 12(2) notification requirement was met by notification of the students’ parents. Complaint resolved by ...

Read more

HI-050045-1

A break-in at a branch office of a not-for-profit organization resulted in the theft of two desktop computers and a server. Section 12(2) notification requirement met by way of a notice to be included in the newsletter sent to patients a...

Read more

HI-050036-1 – A Medical Clinic in a Rural Setting

A medical clinic provided a patient with a receipt containing the personal health information of another individual. Complaint resolved by way of informal resolution. Health information custodian agreed to update their policies and proce...

Read more

HI-050029-1 A Provincial Government Program

Files containing the personal health information of 27 patients were reported as missing following the move of a provincial government program’s office. Complaint resolved by way of informal resolution. Health information custodian...

Read more

HI-050022-1 – A Community Care Access Centre

Loss of personal health information due to theft of a laptop computer from a staff member’s vehicle. Resolved through informal resolution. The health information custodian reminded its staff that laptops should be locked in the trunk o...

Read more

HI-050039-1 – A Designated Rehabilitation Assessment Centre

Loss of personal health information due to theft of a non-password protected laptop computer from a staff member’s home. Resolved through informal resolution. The health information custodian revised its practices so that the laptop wo...

Read more

HI-050026-1 – A City’s Public Health Department

Loss of personal health information due to theft of a non-password protected USB storage device. Resolved through informal resolution. The health information custodian reminded staff that personal health information should be stored on t...

Read more

HI-050027-1

Records of personal health information relating to four individuals found by a member of the public on the street near a public hospital. Resolved through informal resolution. The records were retrieved and assurances were given that no ...

Read more

HI-050025-1 – A City Hospital

Records containing personal health information of one individual were accessed by an unauthorized person as the records were erroneously left on public transit. Resolved through informal resolution. The health information custodian inves...

Read more

HI-050024-1 – The Ministry of Health and Long-Term Care

Personal health information of one individual accessed by an unauthorized person because the individual’s provincial health card re-registration notice was sent in error to another individual. Resolved through informal resolution. ...

Read more

HI-050021-1 – An Audiology Clinic

Loss of personal health information due to theft of computer. Resolved through informal resolution. The health information custodian worked with the building’s owner to improve security measures. The health information custodian fulfil...

Read more

HI-050016-1 – A City Hospital

Loss of personal health information due to theft of a computer. Resolved through informal resolution. The health information custodian revised its policies and practices regarding security, de-identification of data, privacy of personal ...

Read more

HI-050019-1 – A Municipality’s Public Health Unit

Loss of personal health information due to theft of two records from a staff member’s vehicle. Resolved through informal resolution. The health information custodian revised its privacy protocol to ensure that records of personal healt...

Read more

HI-050018-1 – A Regional Health Sciences Centre

Personal health information of one individual accessed by an unauthorized person. Resolved through informal resolution. The health information custodian purchased privacy screens for computer monitors and the employee involved in the inc...

Read more

HI-050042-1 – A Hospital Emergency Department

A hospital reported that twelve partial emergency department records had gone missing from their emergency department. Section 12(2) notification requirement met by telephone calls and written letters to the affected individuals. Complai...

Read more

HI-050017-1 – A Health Unit

Loss of personal health information following immunization clinics at three schools. Resolved through informal resolution. The health information custodian revised its policies relating to document management in the context of immunizati...

Read more

HI-050015-1 – A Nursing Services Company

Loss of personal health information due to theft of a computer. Resolved through informal resolution. The health information custodian revised its policies and practices regarding security, de-identification of data, privacy of personal ...

Read more

HI-050014-1 – A Physician

Garbage bag containing personal health information found by a homeowner on his property. Resolved through informal resolution. After the health information custodian was identified, she retrieved the contents of the garbage bag. The pers...

Read more

HI-050037-1 – A Hospital in a Suburban Setting

A hospital staff member’s Assignment and Work Sheet is found in a parking lot of a grocery store. Section 12(2) notification requirement met by telephone calls and follow up letters sent to the affected individuals. Complaint resol...

Read more

HI-050034-1 – A Community Care Access Centre in an Urban Setting

A Community Care Access Centre misdirected a fax to the Administration/Business Centre of a local department store. Section 12(2) notification requirement met by way of telephone calls and letters. Complaint resolved by way of informal r...

Read more

HI-050031-1 – A Hospital in an Urban Setting

A hospital reported the theft of three laptop computers from one of its offices. Complaint resolved by way of informal resolution. Health information custodian agreed to update their security practices in order to ensure compliance with ...

Read more

HI-050012-1 – A Community Care Access Centre

Loss of personal health information due to theft of 24 laptop computers. The personal health information on the laptops was encrypted. Resolved through informal resolution. The health information custodian increased security measures in ...

Read more

HI-050030-1 – Misdirected faxes to a private business

Faxes containing personal health information were misdirected to a private business. Section 12(2) notification requirement met through the notification of the individuals by the intended recipients of the faxes. Complaint resolved by wa...

Read more

HI-050009-1 – A Hospital in a Rural Centre

Portions of a patient’s original health record were given to the patient in error. Resolved through informal resolution. The health information custodian retrieved the original records from the patient. As a result of the incident,...

Read more

HI-050013-1 – A Hospital in an Urban Centre

Employee engaged in unauthorized access to personal health information of one individual. Resolved through informal resolution. The health information custodian immediately removed the employee’s access rights to personal health inform...

Read more

HI-050011-1 – A Community Care Access Centre

Loss of portable digital assistant (PDA) that contained personal health information. Resolved through informal resolution. The health information custodian disabled the PDA and amended its practices regarding identifiable personal health...

Read more

HI-050010-1 – A Public Laboratory

Laboratory requisitions containing personal health information and laboratory specimens were lost while being transported. Resolved through informal resolution. The health information custodian and the courier company reviewed and revise...

Read more

HI-050007-1 – A Private Laboratory

Loss of personal health information due to theft of a computer. Resolved through informal resolution. The personal health information on the computer was not backed up and, therefore, identification of affected individuals was not possib...

Read more

HI-050004-1 – A Public Laboratory

Loss of personal health information due to theft of laboratory reports from a commercial courier van. Resolved through informal resolution. The health information custodian worked with the courier company to change its practices to minim...

Read more

HI-050003-1 – A Community Care Access Centre

Loss of personal health information of one individual due to theft of laptop from an employee’s vehicle. Resolved through informal resolution. The health information custodian developed a privacy policy in response to the incident....

Read more

HI-050001-1 – A City Hospital

Misdirected faxes resulting in unauthorized access to personal health information. Resolved through informal resolution. The health information custodian retrieved the faxes and received confirmation that no copies had been made. The hea...

Read more

HI-050002-1 – A Hospital in a Rural Centre

Misdirected fax resulted in unauthorized access to the personal health information of one individual. Resolved through informal resolution. The health information custodian retrieved the personal health information and received confirmat...

Read more

HI-040003-1 – A Provincial Government Program

Personal health information of one individual sent in error to the wrong person. Resolved through informal resolution. The health information custodian retrieved the personal health information, and undertook a review of its policies and...

Read more

HI-040001-1 – A Hospital in a Rural Centre

Loss of personal health information due to missing computers. Resolved through informal resolution. The health information custodian revised it policies such that personal health information is no longer saved on local hard drives. Secti...

Read more

HI-040002-1 – A Community Care Access Centre

Loss of agent’s appointment book that did not contain personal health information, because it was not identifiable. Resolved through informal resolution. Despite the extremely small chance that any personal health information was i...

Read more

HI-050006-1

Employee posted personal health information on a website A nurse had a personal website that contained photographs of fellow employees and five patients at the hospital where she worked. The matter was resolved through informal resoluti...

Read more

HI-050005-1

Diagnostic reports gone missing Hard copies of diagnostic reports were not filed in the patients’ health records and were likely disposed of by one of the health information custodian’s employees. Resolved through informal resolutio...

Read more