Ontario’s Information and Privacy Commissioner (IPC) is ordering Lakeridge Health to take steps to amend its privacy-related policies and procedures after an investigation into several “snooping” incidents where patients’ personal health information was accessed by hospital workers without authorization.

The investigation was focused on different incidents that included a doctor, a unit clerk, a clinical extern, a diagnostic imaging technician and two registered practical nurses (RPNs). The report says the hospital agents all accessed the information without the proper authority to do so, which violated the Personal Health Information Protection Act.

Although the hospital did investigate the incidents, the privacy commissioner found they did not remove any of the workers’ access to the electronic health record when the investigation began. In some cases, the workers continued to access health information unauthorized.

This is not the first time something like this has has happened. The report says the IPC previously investigated similar incidents in the past and already ordered the hospital to take action to prevent it from happening again. Despite that decision, the unauthorized access continued and spurred the commissioner to do a systemic review of the ongoing issues at the hospital network.

The investigation found Lakeridge Health did not take “reasonable steps” to make sure that patients’ personal health information was protected and in three cases, the affected individuals were not notified about the breach at the reasonable opportunity to do so.

Lakeridge Health released a statement about the findings and says they’re conducting a thorough review of the decision. They are also committed to strengthening their privacy program and continuing to enhance how personal health information is safeguarded.

The hospital network added they’ve already made some big improvements to their privacy policies and practices since the incidents spanning from 2022-2024. The statement pointed out Lakeridge Health became the first health care system in Canada to earn both the Information Security Management System and Privacy Information Management System certifications.

Their full statement is below:

At Lakeridge Health, protecting the privacy of our patients, residents, clients, families, and team members is a top priority. We are conducting a thorough review of the IPC’s decision related to events that occurred between 2022-2024 and remain committed to strengthening our privacy program and continuing to enhance how we safeguard personal health information.

We have made significant improvements in our privacy policies and practices since the time when these events occurred. These improvements and our continued commitment to privacy is reflected in Lakeridge Health becoming the first health care system in Canada to earn both Information Security Management System (ISO/IEC 27001:2022) and Privacy Information Management System (ISO/IEC 27701:2019) certifications. These internationally recognized standards demonstrate the strength of our information security and privacy controls, as well as our ongoing oversight of how patient information is managed.

You can read the full report from the IPC here.

File photo