Skip to content

One phishing email took over the mailbox. The patients had to be told.

a registered psychologist’s practice · Alberta · March 2021. An employee at a one-practitioner psychology practice answered an email that looked like it came from Microsoft. Days later the mailbox was hijacked, and its contacts were asked to buy gift cards. The practice was ordered to notify 207 patients.

What happened

Identified in the record as Alberta OIPC Breach Notification Decision P2022-ND-015.

207 patients the practice was ordered to notify
Missing control

Two-factor authentication, added afterwards and only on “most” accounts

First page of Decision P2022-ND-015 Alberta OIPC decision Read the original →

On March 4 or 5, 2021, an employee responded to a phishing email that claimed to come from Microsoft. On March 8, the account was hijacked, and the employee's contacts were sent emails asking them to buy gift cards.

“The Organization was notified by the employee's contacts that they were receiving emails from the employee about gift cards.”

The Commissioner found a real risk of significant harm — the mailbox held contact and medical information — and ordered the practice to notify the 207 patients affected under Alberta's Personal Information Protection Act.

“The lack of reported incidents is not a mitigating factor as the identified harms can happen months and even years after a data breach.”

The practice is the smallest organisation among these cases — one practitioner, a handful of staff, an ordinary Microsoft mailbox. Afterwards, it turned on two-factor authentication — on most accounts. The gap between most and all is the gap this incident went through.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify the individuals whose personal information was collected in Alberta, pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

Read the remediation list again: two-factor authentication was turned on afterwards, and on most accounts. That is the same sentence as Hamilton's, at one-thousandth of the scale — the control was known, it was partially applied, and the gap was where the incident went through.

The smallest organisation on this page, and the closest to most of the firms we work with — one practitioner, a handful of staff, an ordinary Microsoft mailbox. The statute is Alberta's rather than Ontario's PHIPA, but the mechanism is identical in every province: one credential, one mailbox, and a duty to tell every patient in it.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2022-ND-015 Copy held 2026-08-20
The decisions index Copy held 2026-08-20

How many of your accounts is “most”?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small clinics →