Ransomware at a shared IT provider put patient records on the dark web.
Missing control: Privileged account management on administrator accounts, including MFA
Source: IPC Case of Note, PHIPA Decision 284
You hold health records — the most regulated and most valuable category of personal data there is — usually with no dedicated IT staff, let alone a security team.
At a single-practitioner Alberta practice, someone answered an email that looked like it came from Microsoft. Four days later the mailbox belonged to somebody else, and every contact in it received a request to buy gift cards. The practice found out from its own patients. 207 of them had to be notified, and the two-factor authentication that would have stopped it was turned on afterwards — on most accounts.
Read the decision, and what the Commissioner said about it →
Missing control: Privileged account management on administrator accounts, including MFA
Source: IPC Case of Note, PHIPA Decision 284
Missing control: Two-factor authentication, added afterwards and only on “most” accounts
Source: Decision P2022-ND-015
Missing control: Multi-factor authentication and staff training — both bought afterwards
Source: Decision P2020-ND-048
Email is where we start: 82% of Canadian clinics with a website publish nothing that stops mail impersonating them — the weakest of any sector we measured.
It is one of the first things the free Snapshot checks — from the outside, nothing to install.
See what we’d find on your domain — get the free Security Snapshot →
The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.
Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.
An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.
At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.
Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.
Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.
And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →
Information and Privacy Commissioner of Ontario · PHIPA
If you do not report and notify, PHIPA allows a fine of up to $200,000 and up to a year’s imprisonment against an individual, and up to $1 million against the organisation.
| The rule | Who it binds | If you don’t | Source |
|---|---|---|---|
| What the Act provides for, on conviction | An individual custodian, and an organisation | A statutory maximum of $200,000 and up to one year’s imprisonment for an individual; $1,000,000 for an organisation Statutory maximum on conviction — state it as a maximum, never as a typical outcome. | Information and Privacy Commissioner of Ontario — potential consequences of a breach under PHIPA |
| The duty to report a theft | Every health information custodian | A reporting duty triggered by the incident itself | Information and Privacy Commissioner of Ontario — reporting a privacy breach |
| A separate duty to tell the patients | Every health information custodian | Independent of whether the IPC must be notified | Information and Privacy Commissioner of Ontario — reporting a privacy breach |
| An annual filing, with a date | Every health information custodian | Due every 1 March, for the previous calendar year | Information and Privacy Commissioner of Ontario — annual reporting of privacy breach statistics |
| A partner’s conditions, signed before you connect | Any custodian using the provincial electronic health record | Safeguards are a term of the agreement, not a recommendation A contractual duty owed to Ontario Health, separate from PHIPA — the obligation arrives from a partner, not the Commissioner. | Ontario Health — EHR agreements with health information custodians and coroners |
| Report a breach that could seriously harm someone | Every organisation subject to PIPEDA | Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. | PIPEDA s.10.1(1) — report to Commissioner |
| Notify the people affected | Every organisation subject to PIPEDA | The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. | Privacy Commissioner of Canada |
| Keep a record of EVERY breach for two years | Every organisation subject to PIPEDA | Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. | Breach of Security Safeguards Regulations, s. 6(1) |
| Make those records good enough to audit | Every organisation subject to PIPEDA | A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. | Privacy Commissioner of Canada |
| Satisfy your insurer before you need to claim | Any firm that wants cyber cover | A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. | Coalition Insurance Solutions Canada — cyber questionnaire |
| Answer your client’s regulator, not just your own | Any firm holding a federally regulated client’s data | A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. | OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024) |
An individual found guilty of committing an offence under PHIPA can be liable for a fine of up to $200,000 or up to one year in prison, or both. An organization or institution can be liable for a fine of up to $1,000,000.
Information and Privacy Commissioner of Ontario — potential consequences of a breach under PHIPA
Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.
Every one of these duties begins the same way: you notice. A duty to report presupposes detection, and nothing in the legislation makes detection happen on its own.
No cost, no obligation — you keep the findings either way.
One short form. No access to your systems, no software to install.
Passive, publicly observable checks only — the same view an attacker gets.
Your top findings in plain English — one page, no meeting required.