Investigation Report: PHIA Privacy Breach – Winnipeg Regional Health Authority
investigations & monitoring
health facility, body or trustee
Summary
Winnipeg Regional Health Authority. This case concerned a privacy breach involving the personal health information of 91 patients who received magnetic resonance imaging (MRI) scans within the Winnipeg Regional Health Authority (WRHA) between 2008 and 2016. The patients’ health information was disclosed in violation of PHIA to several media organizations. The ombudsman found that the WRHA responded appropriately to the privacy breach. The ombudsman was not able to determine the identity of the person(s) who made the unauthorized disclosures to media organizations and was not able to determine whether the breach originated within the WRHA. However, the review identified several measures that trustees should consider in an effort to minimize the risk of intentional or inadvertent privacy breaches in the case of bulk disclosures of personal health information.
CASE 2017-0143