DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Major deficiencies in VCHA's Primary Access Regional Information System – report

Posted on March 5, 2010 by Dissent

The Office of the Information & Privacy Commissioner of British Columbia has released its review of the electronic health information system set up by the Vancouver Coastal Health Authority known as the Primary Access Regional Information System (PARIS).

From the Executive Summary:

The electronic health record system at Vancouver Coastal Health Authority (“VCH”) known as the Primary Access Regional Information System (“PARIS”) was introduced in 2001 for its community-based programs. It is accessed by staff and contractors involved in the delivery of a wide range of health services outside of acute care hospitals. These health services include such things as a newborn hotline, home support for seniors, detox services, and communicable disease control. The personal information contained in PARIS is highly sensitive. It includes diagnoses as well as the case notes of physicians, nurses and counsellors about the treatment they provide to their clients.

As a result of our review of the compliance of the system with the standards required by the Freedom of Information and Protection of Privacy Act (“FIPPA”), we found that the privacy protection of personal information in PARIS is inadequate. Major deficiencies in implementation of the PARIS software from a privacy perspective are the following:

  • an access model that is team-based rather than role-based resulting in too many users having access to too much personal information,
  • several data flows of personal information outside of the health authority that are not authorized under FIPPA,
  • the security protection for the system when we investigated it was not reasonable given the sensitivity of the personal information and did not meet the FIPPA standard1, and
  • records are stored indefinitely – neither archived nor destroyed when they are no longer needed to provide care.

These deficiencies are serious and are a matter of significant concern. It must be noted, however, that these deficiencies are not a result of the software product itself. Rather, they are due to the lack of a proper privacy lens being applied when it was operationalized in community programs at VCH.

VCH has recently put a good privacy management framework in place and is nurturing a corporate culture of privacy. However, this increased capacity and awareness with respect to privacy issues has not yet resulted in an adequate degree of privacy protection for the personal information contained in PARIS. The Information Privacy Office at VCH needs to have greater influence over the system administration of PARIS.

PARIS is a good example of an electronic database that should be designated as a health information bank under the E-Health (Personal Health Information Access and Protection of Privacy) Act. Designation would remedy the lack of authority under FIPPA for certain data flows into and out of PARIS. Designation by means of a legal instrument would also inform the public as to how personal information is being collected, used, and disclosed within the health care system, thereby improving transparency and accountability regarding its privacy protection.

Because of the current privacy management framework at VCH, it is anticipated that VCH will be able to respond to our recommendations in a timely fashion. To date, new privacy and security policies have been triggered by this review and role-based access model pilots have been initiated.

We intend to review implementation of all the recommendations contained in this report after one year.

Read the full report here.


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
Category: Uncategorized

Post navigation

← Kaiser official defends security practices for veterans health data
UT Southwestern employee accused of selling patient information →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.