Whether you are an insurance company, hospital or patient, a medical information privacy case in Canada last month illustrates how important is the quality of an organisation’s compliance infrastructure and its response to any breach of such sensitive personal information.

In the Ontario case, a hospital reported to the privacy commissioner three separate medical information privacy breaches under that province’s version of Bermuda’s Personal Information Protection Act 2016. Each involved unauthorised access to a patient’s personal medical information by employees of the hospital who had, in the words of the privacy commissioner, “snooped” those records for non-work-related purposes.

The number of such distinct wrongful access incidents suffered by the hospital aroused the privacy commissioner’s concern that such surreptitious snooping might be systemic across the hospital’s staff so she agreed to hear the complaint against the hospital.

By comparison, under Pipa, all such medical information is defined as sensitive personal information which must be used only for the consented purposes for which it was collected by the retaining organisation.

It must be securely kept to a standard of “safeguard” from unauthorised access that must take into account the likelihood and severity of the harm threatened by any such unauthorised access or misuse, the sensitivity of such personal information and the context in which it is held.

A possible contextual consideration for any hospital is the reasonable patient expectation of confidentiality for such sensitive medical information.

The Ontario privacy commissioner considered whether the hospital had taken reasonable steps to protect the health information, which must include the implementation of administrative and technical measures or safeguards — including policies, procedures, practices, audits, training and awareness programmes.

She also undertook a thorough review, if not audit, of all the hospital’s privacy compliance infrastructure.

Because the hospital in that case had responded diligently when those breaches arose, had taken disciplinary measures against the perpetrators, had increased its staff training on those issues, and had otherwise diligently complied with the security and other measures required by Ontario’s health information protection statute, the Ontario privacy commissioner was “… satisfied that the hospital has adequately addressed the privacy concerns raised by the three breaches … a [conduct] review [of the hospital] is not warranted”.

Although Bermuda and Ontario have different health information privacy laws, they are very similar in their treatment of personal medical information. Certainly, such employee snooping would likely be a violation of Pipa’s medical information privacy protections.

The decisions of the Ontario privacy commissioner are in no way binding in Bermuda, but the case may be instructive about how important preparatory compliance measures can be.

Whether sensitive medical information is in the hands of your healthcare providers, a hospital or your insurance company, the preparatory quality of the organisation’s compliance infrastructure and the diligent nature of its responses to a breach incident may well influence and inform a determination as to whether an organisation has contributed to, or even enabled, such breaches to occur.

First Published In The Royal Gazette, Legally Speaking, May 2023

Share
X.com LinkedIn Email Save as PDF
More Publications
Appleby-Website-Privacy-and-Data-Protection
28 Jul 2025

Insights from the BMA’s Second Consultation Paper on Digital Identity Service Providers

As jurisdictions around the world grapple with the complexities of authenticating digital identities...

Technology and Innovation
24 Jul 2025

Contracts to Manage AI Risk: Part Two (Bermuda)

In part one of this two-part series about artificial intelligence contracts, I discussed the ways th...

Technology and Innovation
22 Jul 2025

Contracts to Manage AI Risk (Bermuda)

This is the first of a two-part article on how artificial intelligence contracts can be used to mana...

Appleby-Website-Insurance-and-Reinsurance
15 Jul 2025

Captives are the grass roots of Bermuda risk

Bermuda has seen tremendous growth in the life reinsurance and insurance-linked securities markets i...

050-Insolvency-Restructuring-Grid-Image
10 Jul 2025

Bermuda: Restructuring & Insolvency

This country-specific Q&A provides an overview of Restructuring & Insolvency laws and regulations ap...

050-Insolvency-Restructuring-Grid-Image
3 Jul 2025

Insolvency law: secured creditors take note (Bermuda)

The recent judgment delivered by the Supreme Court of Bermuda in the matter of Harold J. Darrell hig...

Appleby-Website-Insurance-and-Reinsurance
2 Jul 2025

Bermuda: Education has helped investors get more comfortable as ILS continues to grow

It’s been an exceptionally busy and record first half of the year for the catastrophe bond sector,...

Appleby-Website-Privacy-and-Data-Protection
25 Jun 2025

Impact of Privacy Law on Bermuda Business

On 1st January 2025, Bermuda’s Personal Information Protection Act 2016 (PIPA) came into full forc...

Appleby-Website-Regulatory-Practice
25 Jun 2025

Simplified Due Diligence in Bermuda

Simplified Due Diligence (SDD) and Reduced Due Diligence (RDD) are critical features of a modern, ri...

Appleby-Website-Employment-and-Immigration
23 Jun 2025

Practical Tips for Conducting Workplace Investigations

Allegations of harassment, bullying or other misconduct in the workplace can create a legal mine fie...