Personal health information and your privacy

Published: 18 May 2023
Type: Insight

When Bermuda’s privacy laws come into full force, perhaps this year, one of the most sensitive areas of privacy protection will concern the medical and health records that so many organisations collect and use.


Whether you are an insurance company, hospital or patient, a medical information privacy case in Canada last month illustrates how important is the quality of an organisation’s compliance infrastructure and its response to any breach of such sensitive personal information.

In the Ontario case, a hospital reported to the privacy commissioner three separate medical information privacy breaches under that province’s version of Bermuda’s Personal Information Protection Act 2016. Each involved unauthorised access to a patient’s personal medical information by employees of the hospital who had, in the words of the privacy commissioner, “snooped” those records for non-work-related purposes.

The number of such distinct wrongful access incidents suffered by the hospital aroused the privacy commissioner’s concern that such surreptitious snooping might be systemic across the hospital’s staff so she agreed to hear the complaint against the hospital.

By comparison, under Pipa, all such medical information is defined as sensitive personal information which must be used only for the consented purposes for which it was collected by the retaining organisation.

It must be securely kept to a standard of “safeguard” from unauthorised access that must take into account the likelihood and severity of the harm threatened by any such unauthorised access or misuse, the sensitivity of such personal information and the context in which it is held.

A possible contextual consideration for any hospital is the reasonable patient expectation of confidentiality for such sensitive medical information.

The Ontario privacy commissioner considered whether the hospital had taken reasonable steps to protect the health information, which must include the implementation of administrative and technical measures or safeguards — including policies, procedures, practices, audits, training and awareness programmes.

She also undertook a thorough review, if not audit, of all the hospital’s privacy compliance infrastructure.

Because the hospital in that case had responded diligently when those breaches arose, had taken disciplinary measures against the perpetrators, had increased its staff training on those issues, and had otherwise diligently complied with the security and other measures required by Ontario’s health information protection statute, the Ontario privacy commissioner was “… satisfied that the hospital has adequately addressed the privacy concerns raised by the three breaches … a [conduct] review [of the hospital] is not warranted”.

Although Bermuda and Ontario have different health information privacy laws, they are very similar in their treatment of personal medical information. Certainly, such employee snooping would likely be a violation of Pipa’s medical information privacy protections.

The decisions of the Ontario privacy commissioner are in no way binding in Bermuda, but the case may be instructive about how important preparatory compliance measures can be.

Whether sensitive medical information is in the hands of your healthcare providers, a hospital or your insurance company, the preparatory quality of the organisation’s compliance infrastructure and the diligent nature of its responses to a breach incident may well influence and inform a determination as to whether an organisation has contributed to, or even enabled, such breaches to occur.

First Published In The Royal Gazette, Legally Speaking, May 2023

Share
More publications
Appleby-Website-Privacy-and-Data-Protection
13 Feb 2026

Employee access limits under Pipa

The Personal Information Protection Act 2016 has been in effect for more than a year now, and employers in Bermuda are now fielding requests from their employees to access and review their employment records — all of them.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
29 Jan 2026

Navigating estate administration in Bermuda

When a loved one dies, families are often left to navigate not only grief but also a complex legal and administrative process known as estate administration.

Appleby-Website-Insurance-and-Reinsurance
23 Jan 2026

Bermuda: Chambers Insurance & Reinsurance Guide 2026

The guide provides the latest information on sources of insurance and reinsurance law, overseas-based insurers or reinsurers, making an insurance contract, intermediary involvement, alternative risk transfer (ART) transactions, warranties, conditions precedent, insurance disputes and insurtech.

Fund Finance
22 Jan 2026

Fund Finance Laws and Regulations 2026 – Bermuda

The Bermuda fund industry sees investment predominantly from North America and Europe, and therefore trends in the Bermuda fund finance market track the major onshore markets. Although there is no overall data reporting service for the local fund finance market, anecdotal reports from many of the major facility lenders, as well as Appleby practitioners, anticipate that there will continue to be a high demand for capital call or subscription line facilities. That is not to say, of course, that other structures such as NAV facilities will not be utilised.

Appleby-Website-Corporate-Practice
16 Jan 2026

Extracting capital from a Bermuda company

It is widely accepted that one of the main purposes of a business is to create value for its shareholders, who contribute significant capital into entities, hoping that value will be returned to them.

Appleby_preview_Bermuda_1
9 Jan 2026

Bermuda Prohibits Bearer Shares and Nominee Directors

On 21 November 2025, Bermuda passed the Companies (Prohibition of Bearer Shares and Nominee Directors) Amendment Act 2025 (Act). The Act, which came into full force on 10 December 2025, amends both the Companies Act 1981 (Companies Act) and Limited Liability Company Act 2016 (Limited Liability Company Act) in respect of bearer shares, nominee directors, alternate directors and beneficial ownership record keeping for companies and limited liability companies (LLCs) discontinuing to another jurisdiction.

Appleby-Website-Insurance-and-Reinsurance
5 Jan 2026

Cat Bond Issuance Well-Placed to Reach $20bn Again In ‘26, Fueled by Momentum & Proven Success

Annual catastrophe bond issuance hit record heights for the third consecutive year in 2025, and as Brad Adderley, Managing Partner at law firm Appleby’s Bermuda office highlights, given the significant activity and momentum observed in the market, it would not be unexpected for the market to achieve $20 billion once more in 2026

Appleby-Website-Insurance-and-Reinsurance
22 Dec 2025

Collateralised insurers benefit from flexible forms of capital

Bermuda’s well established corporate regulatory regime offers a variety of corporate vehicles that can be used to support insurance-linked securities.

Technology and Innovation
2 Dec 2025

Do cryptocurrencies count as money?

When Satoshi Nakamoto first proposed bitcoin in 2008, he described it as a “peer-to-peer electronic cash system”.

050-Insolvency-Restructuring-Grid-Image
27 Nov 2025

Bermuda: Americas Restructuring Review 2026

This article discusses the defining features of Bermuda’s insolvency landscape and the primary insolvency and rescue procedures available under Bermuda law, including compulsory liquidations, provisional liquidations and schemes of arrangements.