Skip to main content
Update Required: We noticed you are using an older version of Internet Explorer. To ensure full functionality of this site, please contact your system administrator to upgrade to the newest version of Internet Explorer or try accessing the site in Chrome.
HIROC
  • Home
  • Services
    • Risk Management
      Learn how our risk management solutions help you increase safety
    • Insurance
      Learn about our coverage offerings and how the HIROC advantage can work for you
    • Claims
      Learn about the claims process and the support HIROC provides
  • Resources
  • News & Events
    • Annual Conference
      Learn how the HIROC Annual Conference brings Subscribers, partners, and healthcare professionals together to drive patient safety forward
    • News
      News from HIROC and our subscribers about what’s trending in healthcare
    • Podcasts
      Podcasts from HIROC about healthcare
      • Healthcare Change Makers Podcast
      • Share Scale Repeat Podcast
    • Webinars and Events
      View our schedule of upcoming webinars and access the archives
  • About Us
    • Board of Directors
      Learn about our Board – made up of HIROC subscribers – and access the current list of Directors
    • Leadership Team
      A message from HIROC's CEO, Catherine Gaulton
    • Careers
      Want to join a team of innovators and leaders? Check out our current opportunities
    • Our Story, Our Art of Safety Strategy
      How HIROC and its Subscribers are working to create the safest healthcare system
    • Risk Management Residency Program (RMRP)
      Learn about the RMRP
    • Safety Grants Program
      Learn about the HIROC Foundation and the Safety Grants Program
  • Contact Us
Log in Register
HIROC
Log in Register
  1. Home
  2. Resources
  3. Breach of Personal Health Information

Related Resources

Risk Watch (October '25)

Download PDF

Care

Risk Case Studies

The Unsterile Needle

Download PDF

Human Resources

Risk Profiles

Human Resources – Workplace Violence/Disruptive Behaviour

Download PDF

Breach of Personal Health Information

Category
Regulatory
Topic
Privacy
Type
Risk Case Studies
  • Download PDF
  • LinkedIn

Key Words

Privacy Breach, Information Technology, Personal Health Information, Community Health Centre

Abstract

A program director inappropriately accessed person health information. The director’s employer - a community health centre - lacked a robust process to train staff with respect to privacy of personal of health information and failed to conduct health record access audits.

Case Summary

During the course of a 20-year employment term at a community health centre, a senior program director repeatedly accessed the personal health information of numerous family members and social acquaintances. The organization was informed of the breaches following a complaint by a member of the involved employee’s immediate family

Medical legal findings

Expert review of the case was critical of the involved community health centre, indicating that the involved employee appeared to have no understanding of client confidentiality. Further, it was noted that a review of the employee’s employment record provided no evidence to indicate that the employee had received appropriate training with regard to the organization’s policies and procedures related to client confidentiality. Expert review questioned the community health centre’s internal audit processes, given the organization’s apparent failure to identify the privacy breaches prior to the receipt of the complaint.

Reflections

Reflecting on your practice as well as your facility’s policies, procedures and processes:

  1. With respect to staff training and orientation, discuss whether small community organizations and clinics should be held to the same privacy standards as large hospitals. Would lack of resources be sufficient justification for not implementing necessary controls to minimize and identify privacy breaches?
  2. Discuss your organization’s privacy policy. Does it clearly define the possible consequences of breaching a patient’s personal health information? Does it include a standardized privacy breach response protocol? Discuss the role of policies and procedures in legal and regulatory body investigations.
  3. Does your organization have a standardized privacy breach response protocol? Is the protocol effective? Is its effectiveness reviewed following each privacy breach?
  4. Discuss the role of audit logs for internal quality control purposes as well as following a suspected privacy breach. How long are audit logs retained?
  5. Discuss your organization’s threshold for patient and external notification following a privacy breach, specifically who is to be notified and within what timeframes?
Risk

 

Date last reviewed: October 2017
This is a resource for quality assurance and risk management purposes only, and is not intended to provide or replace legal or medical advice or reflect standards of care and/or standards of practice of a regulatory body. The information contained in this resource was deemed accurate at the time of publication, however, practices may change without notice.

Related Resources

Risk Watch (October '25)

Download PDF

Care

Risk Case Studies

The Unsterile Needle

Download PDF

Human Resources

Risk Profiles

Human Resources – Workplace Violence/Disruptive Behaviour

Download PDF

Partnering to create the safest healthcare system

HIROC is not just a not-for-profit, we are a reciprocal. This means we are governed by our Subscribers – a group of over 800 diverse healthcare organizations across Canada. Together we share learnings and find ways to adapt to the changing nature of the industry.
Learn More
HIROC staff members
HIROC
Join our newsletter to stay up to date with the latest news.
By subscribing you agree with our Privacy Policy and provide consent to receive updates from HIROC.

About Us

  • Careers
  • Contact Us
  • Our Story, Our Art of Safety Strategy
  • Risk Management Residency Program (RMRP)
  • Safety Grants Program

Quicklinks

  • Claims
  • Insurance
  • Risk Management

Important information

  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions
  • AODA

©2026 HIROC All rights reserved.

  • Linkedin
  • Instagram
  • Youtube