DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NZ: Case note 269784: Employee repeatedly accessed health records without proper reason

Posted on March 29, 2016 by Dissent

There has been a new finding in an investigation by the Privacy Commissioner of New Zealand that is especially worth noting for it’s “small breach, big impact” value. Because the health agency is not named, it’s not clear to me whether this incident had been reported in the media and on this site previously:

The complainant, who had been employed by a large health agency, was notified by the agency that a former colleague of hers had been dismissed for accessing her health records without proper reason. The complainant and her former colleague had worked in administrative roles, but had access to health records and medical information.

The records ‘browsed’ by the complainant’s former work-mate included extremely sensitive emergency department and mental health information about the complainant. The complainant’s records were accessed on numerous occasions between 2012 and 2013. This showed a pattern of behaviour and gave meaning and context to some comments her former colleagues had made about her health while they worked together.

After finding out about this the complainant asked for an audit of access to her records so she could be sure no other staff she had worked with had inappropriately accessed her health information.

The access audit revealed a further instance of browsing of the complainant’s health information by another former colleague over the same time period. This was especially distressing for the complainant because it renewed the complainant’s concerns that her colleagues had treated her unfairly and had been sharing her sensitive health information with each other.

Rule 5 – Security safeguards

Rule 5 of the Health Information Privacy Code 1994 requires an agency to ensure reasonable security safeguards exist to prevent loss, unauthorised access or disclosure of the health information it holds.

Assessing what is reasonable depends on the sensitivity or confidentiality of the information involved and the ease with which safeguards could be put in place to protect the information. The agency’s current policies and practices, including any staff training, are also relevant.

Under rule 5, an agency has an ongoing responsibility to develop and maintain appropriate security safeguards for their information. System audits, staff training, policies and technology upgrades are some of the tools an agency can employ to help maintain a good privacy culture and ensure trust and confidence in the security and privacy of health information.

Inappropriate access to information by employees, called ‘employee browsing’, is a problem for many large agencies. It is important agencies take a proactive approach to information security and make continuing efforts to put in place and improve their security processes.

Although the health agency took a proactive, sympathetic and responsible approach to the interference with the complainant’s privacy, it had limited processes in place to catch inappropriate access to their files. The extent of the browsing and length of time before detection also indicated the safeguards in place were not adequate. The browsing took place over several months and was not an isolated incident. The fact that people she worked with were responsible heightened the complainant’s feelings of violation and humiliation.

Harm

In this case, the harm suffered by the complainant was ongoing and substantial. She experienced high levels of anxiety, nightmares, and was fearful of further browsing of her health information. The complainant also felt any future possible employment at the agency was impossible as not only did she feel her reputation had been damaged, she no longer trusted the agency.

Settlement

Both the complainant and the health agency agreed to participate in a mediation facilitated by our Office. The mediation was successful and the health agency, following on from earlier apologies, provided a formal apology and agreed to provide financial compensation to the complainant for the harm caused by the interference with her privacy. The health agency had initiated an independent review of its health record audit process to reduce the risk of this happening again in the future and is implementing those changes.

Category: Health DataInsiderNon-U.S.

Post navigation

← Vulnerabilities in a Third-Party Healthcare Payment Processor
WA: Olympia man suspected of stealing hard drives from federal offices →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.