DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ca: Security breach at provincial registry jeopardizes privacy rights of 25,000 personal support workers; ministry must act

Posted on December 9, 2013 by Dissent

Obviously there’s a political agenda here, but it’s curious I hadn’t heard about any breach until I read this press release. There is no notice on the Ontario PSW site concerning any breach:

Concerns and questions are mounting over the lack of provincial government action and oversight following a serious security breach at an employer-run online registry containing the names, employment and personal information of 25,000 personal support workers (PSWs). Two police forces and fraud investigators are now on the case.

All Ontario PSWs working in home care, long-term care and hospitals will soon be mandated to register with the [Ontario] Personal Support Worker Registry as a condition of employment.

Recently PSWs were alerted that their personal data on the Registry had been compromised by an “unauthorized user”. Since the security breach, PSWs have been targeted by telephone solicitations attempting to extract “registration” fees and payments for insurance coverage. There are no such fees associated with the PSW Registry, which has been online since June 2012.

The Canadian Union of Public Employees (CUPE) Ontario and CUPE’s Ontario Council of Hospital Unions (OCHU) opposed the ministry of health’s promotion of the Registry, as established, for several key reasons. CUPE’s concerns included the lack of government oversight and the seemingly inadequate policies and procedures for keeping PSWs’ information secure and confidential. CUPE, which represents over 20,000 PSWs province-wide also opposed the Registry being set up as a private, unaccountable, employer-managed organization.

Today CUPE called for:

  • The health minister to prevent the Registry from accepting new registrants until the ministry publicly certifies that the Registry has adequate policies, procedures, and staff training in place to ensure the privacy of registrants in the future.
  • The PSW Registry to cease accepting new registrants until there is a full independent investigation of the privacy policies and procedures in place at the Registry and the investigation findings made public.
  • An external, independent, and expert assessment of the breach and the Registry’s privacy policies, procedures, and staff training and that the findings be made public and sent to all existing registrants.

“Committed and caring PSWs should not be subjected to an insecure system, one that exposes them to the risk of having their personal information taken by an unauthorized user, demanding money from them. The actions taken by the Registry to protect PSWs are inadequate and the province must step-in. The minister has a responsibility to protect the privacy rights of these health care workers,” says Fred Hahn, president of CUPE Ontario.

The security breach “deepens our concerns about the need and merit of this Registry, considerably,” says Michael Hurley, president of OCHU. The health minister clearly knows that Ontario’s home care system leaves tens of thousands of PSWs with inconsistent, irregular and inadequate work hours. This privacy breach puts PSWs in an even more vulnerable situation.”

SOURCE: Cupe Communications

Category: Breach IncidentsGovernment SectorNon-U.S.

Post navigation

← San Francisco Doctor Accepts Bitcoin to Protect Patient Privacy
Lawmakers ask for deeper look into FDA security hack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Cyberattack pushes German napkin company into insolvency
  • WMATA Train Operators Arrested in Health Care Fraud Scheme
  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.