Tag: Case of Note

Showing 1 - 10 of 13 results

Toronto Public Library cyberattack: A wake-up call for stronger security

Case of Note: File MR23-00112 Background In November 2023, the Toronto Public Library (TPL) reported a cybersecurity breach to the Office of the Information and Privacy Commissioner of Ontario (IPC). The breach, which related to a ransomware attack, was first detected in October 2023 when TPL

Resource

- Published on Mar 14, 2025

Ensuring secure disposal of health records: Out of sight is not out of mind!

Case of Note: PHIPA Decision 266 Background A complaint was brought to the Information and Privacy Commissioner of Ontario (IPC) alleging that a health clinic had failed to securely dispose of records of personal health information (PHI). To support the allegations, photographs of patient records

Resource

- Published on Feb 10, 2025

Lost and found: Preserving abandoned health records

Case of Note: PHIPA Decision 221 (interim) and PHIPA Decision 230 (final) Background The Information and Privacy Commissioner of Ontario (IPC) was contacted about a case of potentially abandoned medical records at a storage facility. The report came from a property management company that was acting
Topics

Resource

- Published on Jan 7, 2025

Toronto Public Library Cyberattack: Importance of reasonable security measures and notifying affected individuals under MFIPPA

A cyberattack on the Toronto Public Library exposed vulnerabilities in its systems that contained a significant number of individuals’ personal information. Read the closing letter to learn about how the case was settled at the Early Resolution Stage.

Resource

- Published on Dec 19, 2024

Preventing health privacy breaches: Why training, policies, and confidentiality agreements matter

Case of Note: PHIPA Decision 260 Background A public hospital was alerted to suspicious activity on a patient chart, and initiated an investigation, which included a targeted audit. The audit revealed that nearly 4,000 patient charts had been accessed by a physician without authorization, from a

Resource

- Published on Nov 18, 2024

Reported Breach HR23-00282

A prescribed person under the Personal Health Information Protection Act reported a breach to the IPC regarding a cyberattack that involved the unauthorized copying of approximately 3.4 million individuals’ personal health information from the prescribed person’s secure file transfer server. The

Resource

- Published on Aug 14, 2024

Cyberattack response: Duty to notify individuals under PHIPA and CYFSA

Background The following decisions involved different cyberattacks against four different organizations. Three involved health information custodians (HICs) subject to the Personal Health Information Protection Act (PHIPA), and the fourth involved a Children’s Aid Society subject to Part X of the

Resource

- Published on Aug 2, 2024

Cyberattack response: Duty to notify individuals under PHIPA and CYFSA

Background The following decisions involved different cyberattacks against four different organizations. Three involved health information custodians (HICs) subject to the Personal Health Information Protection Act (PHIPA), and the fourth involved a Children’s Aid Society subject to Part X of the

Published on Aug 2, 2024

Ensuring health data privacy: Insights from the UTOPIAN case

Case of Note: PHIPA Decision 243 Introduction Health information research plays a vital role in improving medical treatments and the quality of care. To conduct health research, researchers require access to personal health information, the collection and use of which is regulated under health

Resource

- Published on Jul 29, 2024

Ensuring health data privacy: Insights from the UTOPIAN case

Case of Note: PHIPA Decision 243 Introduction Health information research plays a vital role in improving medical treatments and the quality of care. To conduct health research, researchers require access to personal health information, the collection and use of which is regulated under health

Published on Jul 29, 2024