Saturday, February 7, 2026
ADVT 
National

Privacy commissioner rules Medicentres failed to protect info on stolen laptop

Darpan News Desk Canadian Press, 29 Aug, 2014 11:43 AM
    Alberta's privacy commissioner says a chain of medical clinics failed to protect patients' health information on a laptop that was stolen — and took too long to publicly report the theft.
     
    The commissioner's office released its report Friday into the breach, along with several recommendations for Medicentres Inc., including one that the company update its notification policy.
     
    An information technology consultant who had taken his laptop from work lost it at a public venue on Sept. 26, 2013. Nine days later, when the laptop couldn't be found, the company reported the theft to police and the privacy office.
     
    The company didn't tell the government or the patients and their doctors until January.
     
    The laptop contained key information from about 621,000 patients, who had been seen by doctors at the company's Alberta clinics dating back to May 2011. The computer was password-protected but not encrypted.
     
    Encryption is a "no-brainer" that the privacy office has been recommending to health providers for years, said Brian Hamilton, the office's director of compliance and special investigations.
     
    In addition, he said, Medicentres failed to properly inform the consultant of its security policies and didn't conduct regular checks on his work.
     
    "This really speaks to governance and delegation of authority and being aware of what your service providers are doing," Hamilton said.
     
    The report further criticized the four months Medicentres took to inform the patients and their doctors.
     
    Disclosure wasn't mandatory by law at the time. But the privacy office had guidelines stating anyone involved in a breach should "immediately" respond and notify affected individuals. The report said staff repeatedly told Medicentres that it should notify people, but the company "spent considerable time considering and rejecting various methods of notification."
     
    Hamilton said Medicentres technically adopted the privacy office's guideline, but without a time factor, and should revise its approach to "make sure its responses are more timely."
     
    Health Minister Fred Horne said he was outraged by the delay when he learned about it. He was also angry that the privacy commissioner wasn't required to inform him about the breach.
     
    Since then, changes have been made to the province's Health Information Act that require mandatory notification of people affected by privacy breaches. Violations carry a minimum $2,000 fine for an individual and $200,000 for a corporation.
     
    Horne said details, such as how many days should be allowed for notification, are still being discussed but should be finalized in the fall.
     
    "This should never happen again," he said Friday.
     
    Dr. Arif Bhimji, chief medical officer for Medicentres, said the company needed time to pull together a team to respond to the phone calls it would receive from people about the laptop breach.
     
    Four months was "not unreasonable," he said.
     
    "I think moving forward we would try to do things sooner, but I'm assuming that we will never have this situation again."
     
    Many of the report's recommendations have already been made and others are being "worked on," Bhimji said.
     
    Medicentres has also stopped hiring consultants, he added, and will only do so again if they work strictly out of company offices with company equipment.
     
    Medicentres was recently in court asking for a stay on the release of the privacy commissioner's report and a publication ban on its contents. The judge dismissed the application.
     
    Bhimji said the company wanted more time to respond to a draft version.
     
    Court of Queen's Bench Justice Robert Graesser wrote in his decision that the company's main concern seemed to be "the potential impact the final report may have on the intended class proceedings it faces."
     
    A multimillion-dollar, class-action lawsuit against Medicentres was filed in June on behalf of patients who had their personal data stored on the laptop.
     
    Medicentres and the privacy office agree that, so far, none of the patients has fallen victim to an identity crime.

    MORE National ARTICLES

    'Apologies Are Not Enough:' Alberta Tightens Rules On Use Of Government Planes

    'Apologies Are Not Enough:' Alberta Tightens Rules On Use Of Government Planes
    EDMONTON - Alberta says it is tightening rules for government aircraft following a harsh report that outlined inappropriate use of the planes by former premier Alison Redford.

    'Apologies Are Not Enough:' Alberta Tightens Rules On Use Of Government Planes

    B.C. Appeal Court Judge Who Wrote Ruling Dismissing Pickton Appeal Dies

    B.C. Appeal Court Judge Who Wrote Ruling Dismissing Pickton Appeal Dies
    VANCOUVER - A B.C. Appeal Court judge who died while sitting as Canada's longest-serving federally appointed judge is being remembered for his empathy on the job.

    B.C. Appeal Court Judge Who Wrote Ruling Dismissing Pickton Appeal Dies

    Lisa Raitt Stands By Railway Safety Self-Regulation, Despite Lac-Megantic Report

    Lisa Raitt Stands By Railway Safety Self-Regulation, Despite Lac-Megantic Report
    OTTAWA - The Harper government's faith in a deregulated railway safety system remains unshaken and won't be abandoned in the wake of the Lac-Megantic tragedy, Transport Minister Lisa Raitt insisted Tuesday, even as the country's top transportation investigator questioned the current amount of oversight.

    Lisa Raitt Stands By Railway Safety Self-Regulation, Despite Lac-Megantic Report

    Lac-Megantic: Safety Board Says Rail Company Had Weak Safety Culture

    Lac-Megantic: Safety Board Says Rail Company Had Weak Safety Culture
    LAC-MEGANTIC,, - Many factors contributed to the Lac-Megantic train derailment in 2013, including lax safety measures at the company that owned the runaway train, the Transportation Safety Board of Canada said Tuesday.

    Lac-Megantic: Safety Board Says Rail Company Had Weak Safety Culture

    B.C. mine breach leads nuclear safety commission to seek safety checks

    B.C. mine breach leads nuclear safety commission to seek safety checks
    VANCOUVER - A toxic spill from a British Columbia mine has prompted the country's nuclear watchdog to request a series of checks at seven uranium facilities.

    B.C. mine breach leads nuclear safety commission to seek safety checks

    Super tankers in B.C.'s Douglas Channel 'not responsible': Mulcair

    Super tankers in B.C.'s Douglas Channel 'not responsible': Mulcair
    Federal Opposition and New Democratic Party Leader Tom Mulcair has had his first look at Douglas Channel on B.C.'s central coast and is convinced it's a bad idea to use the narrow channel as a highway for super tankers.

    Super tankers in B.C.'s Douglas Channel 'not responsible': Mulcair