Major data breach at Queensway Carleton Hospital could affect 100,000 patients
The personal and health information of about 100,000 Queensway Carleton Hospital patients could be affected by a major data breach, the hospital said Friday.
The breach involves the hospital's use of an Ottawa company's cloud-based platform over a two-year period starting in March 2021.
That company, Aetonix, discovered early last month that an unauthorized third party gained access to an internal test environment where personal health information was stored, the hospital said in a statement on Friday.
"Following a thorough review of the incident, Aetonix’s forensic investigation has concluded that the incident may have resulted in your personal health information being accessed or copied by an unauthorized third party," the hospital said.
"Patient data that may have been impacted include: patient ID numbers, patient visit ID (Account/Encounter number), patient name, gender, date of birth, marital status, mother tongue, home address and postal code, phone number, email address, OHIP number and version, insurance policy number, health care providers, scheduled surgical appointments, past medical history, and procedure description."
The hospital said it has stopped using the platform and there's no evidence the information has been misused.
"QCH takes the privacy and security of personal information very seriously, and we sincerely regret that this incident occurred."
The hospital is sending individual letters to about 100,000 patients who may potentially be impacted. The hospital says its electronic medical records and patient portal were not impacted and no financial or banking information was accessed.
Anyone who got a COVID-19 vaccine at a QCH-affiliated clinic also wouldn’t be affected – that data was uploaded straight to provincial ministry of health servers.
"We want to stress that neither QCH nor Aetonix are aware of any misuse of this information and Aetonix’s investigation could not confirm whether any unauthorized person actually viewed or copied your information," the hospital said.
COMPANY NOTIFIED LAW ENFORCEMENT
In a statement, Aetonix said all data uploaded to its aTouchAway platform by Canada-based health care providers, patients and caregivers prior to Feb. 23 may have been compromised.
"This incident was a result of data being present in a location where it should not have been stored, and which should not have been accessible via the public web," the company said.
Aetonix said law enforcement was notificed on March 17. The Ontario and Alberta information and privacy commissioners, along with the Manitoba ombudsman, were informed on March 20.
The company said its platform is still safe to use.
The hospital was using the aTouchAway platform to provide virtual communication services, care pathways, and remote patient monitoring for QCH patients.
HOSPITAL RETAINS TRANSUNION
The Queensway Carleton says it has retained TransUnion, a consumer reporting agency, so affected patients can register for a credit monitoring service at no cost.
The service will provide unlimited online access to the TransUnion credit report, which is primarily used to detect identity theft or fraud. It also includes identity theft insurance.
For more information, you can read the hospital's public notice here.
DIFFERENT FROM OTHER BREACHES
Technology analyst Carmi Levy tells CTV News Ottawa that the breach at QCH differs from some breaches already seen in the past.
“Compared to other breaches that we’ve seen, this one is someone different because it doesn’t involve the organization itself,” he said.
"Because we live in a world where companies now subscribe to software, subscribe to technology services in the cloud, this is a major problem because no matter who you’re connected to, you have to ask yourself the question are they secure as well?"
Levy says people should watch their accounts of signs of suspicious activity, such as increased phishing emails or text messages.
Ottawa Health Coalition co-chair Ed Cashman says this breach should be a concern for everyone.
"Not just patients, but the government and the hospitals. The reason being this is happening too many times and it’s happening everywhere," he says. "Potentially, it's the most intimate details of your life that are being exposed."
CTVNews.ca Top Stories
BREAKING Toronto MP and former Liberal cabinet minister Marco Mendicino won't seek re-election
Marco Mendicino, a prominent Toronto member of Parliament and former minister of public safety and immigration, won't run in the next federal election, CTV News has learned.
U.S. soldier shot self in head before Cybertruck exploded outside Trump's Las Vegas hotel, officials say
The highly decorated U.S. Army soldier inside the Tesla Cybertruck that burst into flames outside U.S. President-elect Donald Trump's Las Vegas hotel shot himself in the head before the explosion, officials said Thursday.
Wayne Osmond, singer and guitarist for The Osmonds, is dead at 73
Wayne Osmond, a singer, guitarist and founding member of the million-selling family act The Osmonds, who were known for such 1970s teen hits as "One Bad Apple," "Yo-Yo" and "Down By the Lazy River," has died. He was 73.
Toys "R" Us Canada closing 5 stores, expand HMV and add play spaces to some shops
Toys "R" Us Canada says it is closing five Ontario stores and revamping several others as it works to "optimize" its business.
FORECAST Weather warnings issued in 7 provinces and territories
Wintry weather conditions, including heavy snow and wind chill values around -55, prompted warnings in seven provinces and territories Thursday.
Rosita Missoni, matriarch of Italian fashion house that made zigzag knitwear iconic, dies at age 93
Rosita Missoni, the matriarch of the iconic Italian fashion house that made colorful zigzag-patterned knitwear high fashion and helped launch Italian ready-to-wear, has died. She was 93.
Apple to pay US$95M to settle lawsuit accusing Siri of snoopy eavesdropping
Apple has agreed to pay US$95 million to settle a lawsuit accusing the privacy-minded company of deploying its virtual assistant Siri to eavesdrop on people using its iPhone and other trendy devices.
Grieving orca mother Tahlequah carries dead baby for the second time
The famous mother orca who made waves around the world for carrying her dead calf for 17 days has suffered another tragic loss.
When you should see a doctor and other health advice, according to a nurse
As many begin the new year with health resolutions, here's one nurse's advice on when to see the doctor, get tests and seek preventative care.