DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

A breach, a complaint and how the NZ Privacy Commissioner helped

Posted on March 10, 2015 by Dissent

From the job-well-done dept.:

New Zealand’s Privacy Commissioner, John Edwards, writes:

Late last year, one of my senior investigating officers came to me with a file she’d been working on for quite a while. She was convinced the facts supported a finding of an “interference with privacy”, that is, a breach of the privacy principles, that had caused harm to the complainant. She’d tried to reach a settlement, but the parties were too far apart.

When we get to an end point like that, we have to decide whether or not to refer the matter to the Director of Human Rights Proceedings, an independent statutory officer who decides whether to litigate the matter in the Human Rights Review Tribunal. That can take a long time, and be quite stressful for the parties. It is also expensive.

What had happened was that a social worker out on her rounds had her car broken into. Her notebook was in the car. In the notebook were jotted details of some 90 clients she had seen in recent years. This is an important point – it was not just her current clients.

Her employer, a DHB, did the right thing, and got in touch with all the clients, to let them know what had happened. Some of them were understanding, some were a bit upset, but the one who complained to us was devastated. It had been some years since she had seen the social worker and she could not understand why she would still be carrying around her extremely sensitive personal information, which revealed details of mental ill health following the birth of a child.

And that, my friends, is a perfectly reasonable question. The social worker should not have been carrying around historical information not related to her current cases. And of course, whatever she carried around on a mobile device should have been properly secured. If that had happened in the U.K., it might have resulted in an undertaking. If it had happened here in the states, well, HHS might have done what John Edwards ultimately did. But read on….

Often, when a third party like a thief intervenes maliciously to release personal information, it would not be fair to hold the agency responsible. However in this case, we had to consider whether the agency had taken reasonable steps to ensure the information was protected from loss. While we acknowledged that there would be cases where it was necessary to take patient information ‘offsite’ when treating patients in the community, we were not satisfied it was reasonable to expose this type of historic information to the additional risks inherent in taking patient information out of the DHB.

As a last effort to resolve the complaint I arranged to meet with the chief executive of the DHB. We had a very productive conversation and were able to agree to terms on which the complaint would be settled without referral to the Director of Proceedings. It was helpful for me to learn that the DHB’s biggest concern was the perception that we were requiring a significant change of professional practice (namely that we were saying patient information should never be taken offsite). That would have had quite significant implications given the change in clinical service delivery to community care. This means that more health and support staff will be out and about, which means the ability of health care workers to access patient information when they are outside traditional facilities (think clinics and hospitals) will become increasingly important.

Part of the settlement was that my Office agreed to provide some guidance to help health workers and others who are increasingly mobile, to reduce the risks of things going wrong. We will be beginning that work soon, and will hope to canvas the views of a range of community workers to see how they practically manage their information securely without compromising their ability to deliver top quality care.

And here’s a final tip. One of the things that the complainant was very pleased about was that it had reached the highest level of the organisation. She felt that if it had come to the attention of the chief executive, she knew it had been taken seriously and that something would be done. Don’t underestimate the power of a personal approach from the top level in appropriate circumstances!

Guidance would be helpful, yes. But I fear that the Commissioner will discover that most community workers aren’t managing their information securely at all. To really understand data security among community workers, asking them what they do may not be as informative as unannounced audits. Even announcing that the office will be conducting random and unannounced audits of community workers’ data security might have a positive impact on getting community workers to better secure the information they carry with them – and to encourage them not to store information they do not need to store on mobile devices. It might also encourage DHB’s and agencies to invest in developing systems so that the information remains on the server and can be accessed, but not downloaded and stored, on mobile devices.


Related:

  • Canada says hacktivists breached water and energy facilities
  • UK: FCA fines former employee of Virgin Media O2 for data protection breach
  • The 4TB time bomb: when EY's cloud went public (and what it taught us)
  • China Amends Cybersecurity Law and Incident Reporting Regime to Address AI and Infrastructure Risks
  • Alan Turing institute launches new mission to protect UK from cyber-attacks
  • Some lower-tier ransomware gangs have formed a new RaaS alliance -- or have they? (1)
Category: Commentaries and AnalysesHealth DataNon-U.S.Theft

Post navigation

← Government to drop charges against National Weather Service employee accused of hacking
‘ISIS Hackers’ Almost Certainly Not ISIS Hackers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.