Skip to content

Ransomware at a shared IT provider put patient records on the dark web.

a health clinic · Ontario · October 2023. Ransomware at a shared IT provider reached five Ontario hospitals and one small clinic. Stolen patient records were published on the dark web — and the regulator found the clinic's contract was missing clauses the hospitals' agreement carried.

What happened

Identified in the record as IPC Ontario, PHIPA Decision 284.

6 organisations reached through one shared IT provider
Missing control

Privileged account management on administrator accounts, including MFA

First page of IPC Case of Note, PHIPA Decision 284 Ontario IPC case note Read the original →

In October and November 2023, five hospitals and one health care clinic reported a health privacy breach to the Information and Privacy Commissioner of Ontario. All six bought IT from the same shared provider, and the same attack reached them all.

“During the attack, an unauthorized party gained access to the TSSO network through three compromised administrator accounts.”

The attackers encrypted patient health information and later published the stolen records on the dark web. Under Ontario's health privacy law, that encryption alone — wherever in the provider's systems it happened — counts as the unauthorized use and loss of the information.

Weeks after the attack, the organisations told the public what had been taken — and warned that it might not stay private.

“certain patient, employee and professional staff data has been taken and may be released publicly”

When the regulator compared the six organisations, the difference was paperwork. The hospitals' shared agreement was detailed, with clauses on privacy, confidentiality and security. The clinic's agreement lacked key provisions. The IPC also found the lack of privileged account management on the administrator accounts, including multi-factor authentication, was likely a contributing factor in how the credentials were compromised in the first place.

“If using a third party service provider… custodians must conduct the necessary due diligence to ensure that providers have strong protections”

By the time the privacy regulator finished its investigation, the scale was on the record — hundreds of thousands of people across the six organisations.

“between the six facilities, more than 516,000 people had personal health information stolen”

No penalty was ordered, and no dollar figure appears anywhere in the case. The clinic has since amended its agreement.

The rule that applied — in Ontario

PHIPA s.12(2) — Ontario’s Personal Health Information Protection Act

“The encryption of PHI by an unauthorized party, regardless of whether encryption occurs at the server, container, or individual file level, constitutes the unauthorized use and loss of PHI under s. 12(2) of PHIPA.”

The document

The part that matters

Six organisations bought IT from the same provider and were hit by the same attack. What separated them was paperwork: the hospitals' agreement said what the provider had to do about security, and the clinic's did not. The clinic has since amended it.

Ontario, PHIPA, and a clinic small enough to buy its IT as a service — this is the closest documented case to our clinic clients. The caution is that the attack landed on the provider's network, not the clinic's: the clinic's failure was the agreement it had signed, which is a different and more uncomfortable thing to be responsible for.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
IPC Case of Note, PHIPA Decision 284 Copy held, taken 2026-08-20
Global News / CP, November 2023 Copy held 2026-08-20
CBC News, June 2025 Copy held 2026-08-20

The IPC's finding on multi-factor authentication is that its absence was “likely a contributing factor”, not that it caused the breach. No penalty was ordered in this case and no dollar figure appears anywhere in it.

What does your IT contract actually require of them?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small clinics →