Collection
Health Information and Privacy
Date
File Numbers
HR23-00157
Adjudicators
Alanna Maloney
Decision Type
Decision - PHIPA
Applicable Legislation
PHIPA - 3
A public hospital contacted the Information and Privacy Commissioner of Ontario to report a breach under the Personal Health Information Protection Act (the Act). The breach involved an unauthorized use of personal health information of patients by a physician. In response to the breach, the hospital updated its privacy training, confidentiality agreements and privacy policies. In this Decision, I find that the hospital was in breach of sections 10 (Information practices) and 12 (Security) of the Act. However, given the steps taken by the hospital to address the breach, I have also found that no formal review of this matter will be conducted under Part VI of the Act.