DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ca: First report issued on breach of new health info act

Posted on May 5, 2012 by Dissent

CBC News reports:

Newfoundland and Labrador’s privacy commissioner says a registered massage therapist breached the Personal Health Information Act by failing to properly safeguard a patient’s file.

Commissioner Ed Ring says the therapist lost a file containing the personal health information of the complainant, a patient.

The commissioner recommended that the massage therapist, and other people who have access to health information, should take steps to learn the act and ensure they are following it.

Read more from CBC, but I doubt anyone really needs to read the act to know that you’re not supposed to lose patient files.

You can read the commissioner’s report here. In this case, the Custodian of the file did not have policies in place, and then, to make matters worse (from my perspective), ignored contacts from the Commissioner’s office:

On July 25, 2011 this Office wrote to the Custodian and formally advised her of the complaint. An investigator from this Office spoke with the Custodian briefly by telephone and explained the investigative process. On August 25, 2011, another letter was sent to the Custodian requesting information with respect to the Custodian’s information handling and storage practices and any policies and procedures relating to information management. Unfortunately, there was no response to the second letter, despite several unsuccessful attempts to contact the Custodian by telephone and letters sent (by courier) in November 2011 and January 2012. Finally, in early February 2012, this Office prepared and served a Summons to Witness on the Custodian and on February 13, 2012, the Custodian attended at our Office and provided the information necessary for us to proceed with our investigation and Review.

Under the circumstances, I think the Commissioner was being kind in not naming the therapist, but the word does need to get out that therapists need to comply with PHIA and that they need to cooperate with any investigations.


Related:

  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Ransomware blog claims New Horizons Medical has been attacked
  • Little Rock Psychologist Indicted by Federal Grand Jury for Defrauding Medicare and Arkansas Blue Cross Blue Shield
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • Large medical lab in South Africa suffers multiple data breaches
  • From bad to worse: Doctor Alliance hacked again by same threat actor (2)
Category: Health Data

Post navigation

← Security breach: Twice victimized
TeamPoison still active, attacks governments and corporations →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-teen hackers warn parents are clueless as children steal ‘millions’
  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)
  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
  • Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies
  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Update on Dos-OP’s report on Nova RaaS
  • KR: Privacy Commissioner’s Office Urges the Public to Beware of Fraudsters Exploiting the Tai Po Fire Disaster

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.