DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ca: Breach of Privacy at Eastern Health (updated)

Posted on July 26, 2012 by Dissent

VOCM reports:

There has been a significant breach of privacy at Eastern Health involving about 122 patients. The authority says their records were inappropriately accessed by an employee, who has since been terminated.

CEO Vickie Kaminski says there is zero tolerance of wilfil breaches of patient privacy. All employees sign a confidentiality pledge, and are provided with access to personal health information to perform their duties. She says Eastern Health has identified all the patients who have been impacted by the deliberate breach, and has established a process for contacting the patients directly to advise of the breach. The Office of the Information and Privacy Commissioner has also been advised.

Kaminski publicly apologizes to all patients whose privacy has been breached, and assures that the majority of employees take privacy and confidentiality very seriously.

A statement posted to Eastern Health’s web site today reads:

Eastern Health advised today that it is in the process of contacting approximately 122 of its patients whose medical records were inappropriately accessed by an employee of the health authority. The employee has been terminated.

“At Eastern Health, we take our responsibility as custodians of personal health information very seriously,” said Vickie Kaminski, President and CEO of Eastern Health. “As such, when we identify a deliberate breach of patient privacy, we take action to discipline the offending employee. While the severity of the discipline is determined by the seriousness of the breach, there is zero tolerance for willful breaches of patient privacy.”

Eastern Health employees have signed a confidentiality pledge, or an oath of confidentiality, and are provided with access to personal health information to perform their job duties. Eastern Health also undertakes random audits of its employees’ access to patient records, and performs additional audits should a patient file a complaint, or if patients have become broadly known in the community as being patients of Eastern Health. In addition, Eastern Health has provided privacy education and awareness activities, including facilitating an annual Privacy Awareness Week, and routinely sends reminders to its employees of their obligation to help ensure that they protect the privacy of patients, clients and residents. Privacy at Eastern Health will also be further enhanced through new electronic auditing software that is in the process of being installed, which will automate the auditing process, and make it faster and easier to identify inappropriate access to personal health information.

Eastern Health has identified all the patients who have been impacted by the deliberate breach, and has established a process for contacting the patients directly to advise of the breach. The Office of the Information and Privacy Commissioner has also been advised of the breach.

“On behalf of Eastern Health, I want to publicly apologize to all of the patients whose privacy has been breached,” said Ms. Kaminski. “It is quite disheartening when these breaches occur. However, it is my belief that the majority of employees take privacy and confidentiality very seriously.”

Eastern Health is committed to continue protecting the privacy and confidentiality of the health information of its patients, clients and residents, and holds its responsibility as a custodian of personal health information in the highest regard.

So after all that, there’s no statement as to the motivation behind the deliberate breach. Were these patients known to the employee? Were there other motives? Were any of the data manually copied?  Eastern Health did not respond to an email inquiry I sent them yesterday seeking information on this.

Update: Eastern Health has not responded to my inquiry, but another media source reports that the files were those of people the nurse knew.


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
  • "Pompompurin" taken into custody after violating conditions of pre-sentencing release on bond (1)
Category: Uncategorized

Post navigation

← Hackers steal AAPT customer data to protest web spying proposal
UK: Man claims hard drive bought at car boot sale contained personal data from West Cheshire College →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.