The Information and Privacy Commissioner of Ontario (“IPC”) has recently issued its second administrative monetary penalty (“AMP”) since the expansion of its enforcement powers for violations of Ontario’s health privacy legislation, Personal Health Information Protection Act, 2004 (“PHIPA”), in PHIPA Decision 334.[1]
As in the case of the first AMP issued by the IPC in PHIPA Decision 298, the IPC’s latest penalty has been issued against an individual who worked at hospital and was caught snooping numerous patient records without authorization.
Background
The matter arose from events at the Children’s Hospital of Eastern Ontario (“CHEO”), where a nurse employed by the hospital appeared to know details about care provided to her stepchild, despite not being the child’s legal guardian. CHEO conducted an investigation into recent accesses to the child’s personal health information that was stored in the hospital’s electronic medical record system (“EMR”) and determined that a patient services clerk that worked with the nurse had accessed the child’s personal health information without authorization.
Following this determination, CHEO conducted additional audits of the clerk’s activity in the hospital EMR. Through this investigation, CHEO concluded that the clerk’s unauthorized activity in the EMR was much broader than the initial incident and that the clerk had been snooping in a significant number of patient records.
CHEO ultimately determined, and informed the IPC, that between March 1, 2024, and September 23, 2024, the clerk abused the permissions granted to her and accessed the personal health information of 436 patients without authorization, including her own records, those of her family members and other adult and pediatric patient records.
Given the seriousness of the allegations, the IPC commenced a formal review of the incident to consider CHEO’s privacy practices at the time of the incident as well as the clerk’s conduct and to determine whether the imposition of an AMP was warranted in the circumstances.