DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ca: Security breach at provincial registry jeopardizes privacy rights of 25,000 personal support workers; ministry must act

Posted on December 9, 2013 by Dissent

Obviously there’s a political agenda here, but it’s curious I hadn’t heard about any breach until I read this press release. There is no notice on the Ontario PSW site concerning any breach:

Concerns and questions are mounting over the lack of provincial government action and oversight following a serious security breach at an employer-run online registry containing the names, employment and personal information of 25,000 personal support workers (PSWs). Two police forces and fraud investigators are now on the case.

All Ontario PSWs working in home care, long-term care and hospitals will soon be mandated to register with the [Ontario] Personal Support Worker Registry as a condition of employment.

Recently PSWs were alerted that their personal data on the Registry had been compromised by an “unauthorized user”. Since the security breach, PSWs have been targeted by telephone solicitations attempting to extract “registration” fees and payments for insurance coverage. There are no such fees associated with the PSW Registry, which has been online since June 2012.

The Canadian Union of Public Employees (CUPE) Ontario and CUPE’s Ontario Council of Hospital Unions (OCHU) opposed the ministry of health’s promotion of the Registry, as established, for several key reasons. CUPE’s concerns included the lack of government oversight and the seemingly inadequate policies and procedures for keeping PSWs’ information secure and confidential. CUPE, which represents over 20,000 PSWs province-wide also opposed the Registry being set up as a private, unaccountable, employer-managed organization.

Today CUPE called for:

  • The health minister to prevent the Registry from accepting new registrants until the ministry publicly certifies that the Registry has adequate policies, procedures, and staff training in place to ensure the privacy of registrants in the future.
  • The PSW Registry to cease accepting new registrants until there is a full independent investigation of the privacy policies and procedures in place at the Registry and the investigation findings made public.
  • An external, independent, and expert assessment of the breach and the Registry’s privacy policies, procedures, and staff training and that the findings be made public and sent to all existing registrants.

“Committed and caring PSWs should not be subjected to an insecure system, one that exposes them to the risk of having their personal information taken by an unauthorized user, demanding money from them. The actions taken by the Registry to protect PSWs are inadequate and the province must step-in. The minister has a responsibility to protect the privacy rights of these health care workers,” says Fred Hahn, president of CUPE Ontario.

The security breach “deepens our concerns about the need and merit of this Registry, considerably,” says Michael Hurley, president of OCHU. The health minister clearly knows that Ontario’s home care system leaves tens of thousands of PSWs with inconsistent, irregular and inadequate work hours. This privacy breach puts PSWs in an even more vulnerable situation.”

SOURCE: Cupe Communications

No related posts.

Category: Breach IncidentsGovernment SectorNon-U.S.

Post navigation

← San Francisco Doctor Accepts Bitcoin to Protect Patient Privacy
Lawmakers ask for deeper look into FDA security hack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Mississippi Law Firm Sues Cyber Insurer Over Coverage for Scam
  • Ukrainian Hackers Wipe 47TB of Data from Top Russian Military Drone Supplier
  • Computer Whiz Gets Suspended Sentence over 2019 Revenue Agency Data Breach
  • Ministry of Defence data breach timeline
  • Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
  • Ransomware in Italy, strike at the Diskstation gang: hacker group leader arrested in Milan
  • A year after cyber attack, Columbus could invest $23M in cybersecurity upgrades
  • Gravity Forms Breach Hits 1M WordPress Sites
  • Stormous claims to have protected health info on 600,000 patients of North Country Healthcare. The patient data appears fake. (2)
  • Back from the Brink: District Court Clears Air Regarding Individualized Damages Assessment in Data Breach Cases

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The EU’s Plan To Ban Private Messaging Could Have a Global Impact (Plus: What To Do About It)
  • A Balancing Act: Privacy Issues And Responding to A Federal Subpoena Investigating Transgender Care
  • Here’s What a Reproductive Police State Looks Like
  • Meta investors, Zuckerberg to square off at $8 billion trial over alleged privacy violations
  • Australian law is now clearer about clinicians’ discretion to tell our patients’ relatives about their genetic risk
  • The ICO’s AI and biometrics strategy
  • Trump Border Czar Boasts ICE Can ‘Briefly Detain’ People Based On ‘Physical Appearance’

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.