Saskatchewan·New
Saskatchewan's privateness commissioner recovered that the Sask. Health Authority acted appropriately to place a caregiver who was snooping into aesculapian records, but didn't bash capable to pass the victims oregon support against aboriginal breaches.
Commissioner gave SHA until the extremity of April to update policies
Chris Edwards · CBC News
· Posted: Apr 14, 2025 7:36 PM EDT | Last Updated: 3 minutes ago
Saskatchewan's privateness commissioner has released a study connected a registered caregiver who snooped connected diligent records astatine a infirmary successful Yorkton.
The incidents took spot astatine the Yorkton Regional Health Centre betwixt November 2023 and May 2024. While moving astatine the hospital, the caregiver inappropriately viewed the aesculapian records of 70 patients, accessing the strategy implicit 200 times, according to the study by Ronald Kruzeniski.
After an probe by the Saskatchewan Health Authority (SHA), the caregiver was terminated successful October 2024.
Kruzeniski's report, released March 31, stated that portion the SHA investigated the breach appropriately, it failed connected respective counts to incorporate the privateness breaches and notify the patients involved. It besides criticized the SHA for not sharing capable accusation proactively implicit the people of the investigation.
"After a reappraisal of the SHA's interior probe report, it was evident that it lacked capable item for my bureau to afloat analyse the matter," the commissioner said, earlier a bid of back-and-forth communications betwixt the SHA and the commissioner's bureau successful January.
Kruzeniski besides noted the SHA did not instantly supply audit logs and notes from meetings with the caregiver that helium requested for his investigation, starring to delays.
"Instead of providing each of the accusation requested, the SHA asked for the rationale oregon intent of requiring the audit log and interrogation notes," the committee said successful the report.
He said that contacting the caregiver was astatine archetypal met with akin resistance.
Over the people of the investigation, the commissioner determined that the caregiver continued to person entree to diligent aesculapian records portion they were being investigated, inappropriately accessing them an further 27 times aft the interior probe began.
Kruzeniski notes that portion the SHA did interaction the patients who had been impacted, it didn't adequately pass them of the harms that whitethorn travel to them arsenic a effect of the breach. That prevented the victims from taking further actions to support themselves from individuality theft.
Moreover, the commissioner said, the SHA didn't archer the victims who snooped connected their aesculapian records, oregon that the idiosyncratic had been terminated arsenic a result.
While the SHA found the snooper done an electronic audit, the commissioner recovered that those audits aren't routine and the SHA didn't person an authoritative audit policy.
Kruzeniski determined that the SHA should marque respective changes to its interior procedures by the extremity of April. In aboriginal investigations, it should artifact idiosyncratic entree to aesculapian records erstwhile an worker is being investigated, institute regular auditing and supply privateness breach victims with much accusation astir who viewed their information.
The commissioner besides said the SHA should amended pass victims of who snooped connected their information, notifying them wrong 10 days.
Finally, portion the caregiver was terminated, the commissioner said their actions were superior capable to beryllium forwarded to prosecutors to find if an offence had occurred nether the Health Information Protection Act.
ABOUT THE AUTHOR
Chris Edwards is simply a newsman astatine CBC Saskatchewan. Before entering journalism, helium worked successful the tech industry.