Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts

Sunday, December 14, 2025

When student data is hacked & stolen: Regulators’ lessons from the PowerSchool data breach


You may recall hearing about a significant cybersecurity breach affecting school boards from the end of last year and the beginning of this year: the PowerSchool cybersecurity incident. In the past little while, the Information and Privacy Commissioners of Ontario and Alberta have released their reports of findings into the incident. (Ontario, Alberta) There is some interesting stuff in there that I think is worth chatting about. I’ll note that the Information and Privacy Commissioner of Saskatchewan also released a report of findings in August of this year.


This incident affected millions of students, parents, and educators across the country, involved sensitive personal information, and raised questions about outsourcing, cybersecurity, and accountability in the public sector. But many of these issues will be relevant for the private sector. You simply can’t outsource accountability for protecting data. 


One thing to be sensitive to is that school boards are chronically under-resourced and have a very hard time meeting their privacy and security obligations under existing budgets. Personally, I think the provinces should take a much more active role in working with school boards and their contractors to ensure the highest levels of cybersecurity. We’re seeing that with health information systems, and should expect it for student information systems.


Before I get into the main point of this episode, one digression … At least in Canada, we always have to ask “what privacy law applies?” When the incident came to light, it was completely clear that at least in Canada, public school boards and their students were affected. Every school board is subject to a provincial public sector privacy law. So there’d be no doubt that a provincial Information and Privacy Commissioner would have jurisdiction to investigate the incident. 


It was interesting that the federal commissioner jumped in there. The federal commissioner has jurisdiction under the federal Personal Information Protection and Electronic Documents Act – or PIPEDA – where there is a collection, use and disclosure of personal information in the course of commercial activity. 


In this case, the collection, use and disclosure of personal information was in the course of the school boards’ non-commercial activities. Just because the contractor – in this case PowerSchool is doing this for commercial purposes – should not give the federal commissioner jurisdiction. While both public and private sector privacy laws contain obligations to safeguard data, they work in very different ways. If a public sector privacy law applies to the school board, while the private sector law applies to the contractor with respect to the same information, it is unworkable. The two categories of laws are simply not compatible.


Regardless, the federal Office of the Privacy Commissioner of Canada also started making inquiries with PowerSchool, first announced on January 20. On February 11, the federal Commissioner announced they had launched an investigation and noted that they’d remain in close contact with provincial and territorial counterparts on the incident. There was no mention on the basis of his jurisdiction to investigate.


In July, the federal Commissioner announced that they’d negotiated a number of commitments from PowerSchool regarding cybersecurity upgrades, certification and monitoring. It’s worth noting that the letter of commitment specifically says that the Commissioner was of the view that PIPEDA applied in this case, PowerSchool did not agree, and reserves all future rights. And rightly so. At some point, we really need a court to step in to clearly lay down the lines between privacy laws in Canada. 


Thanks for indulging me for this digression. Now onto the main part of this episode, where I plan to cover four things:


  1. The background to PowerSchool and how schools use it

  2. What happened in the cyberattack

  3. What the Ontario and Alberta regulators investigated and concluded

  4. Where their findings align — and where they differ


PowerSchool is a major education technology provider. Across Canada, school boards use PowerSchool’s Student Information System, or SIS, to manage day-to-day education operations. That includes:


  • Student enrollment and attendance

  • Grades and academic records

  • Contact information for students and parents

  • Medical alerts, accommodations, and special needs

  • Staff and educator information


In many provinces, PowerSchool hosts this data in cloud-based environments that are largely operated and managed by PowerSchool itself, not the school boards. Of course, it’s done on the school boards’ behalf. 


Crucially, under Canadian privacy laws, school boards remain legally responsible for the personal information — even when a third-party service provider is handling it. That legal principle becomes very important once something goes wrong.


THE INCIDENT: WHAT HAPPENED?


The cyberattack was discovered in late December 2024.


Here’s what investigators from Ontario and Alberta determined happened. A threat actor obtained valid credentials belonging to a PowerSchool support contractor. These credentials had elevated privileges, meaning they could access PowerSchool’s internal support portal called PowerSource. PowerSource exists so that PowerSchool staff can provide remote technical support to customer school boards.


Once inside PowerSource with these credentials, the attacker was able to access multiple school boards’ Student Information System environments — effectively stepping through the front door.


From there, the attacker accessed student and educator databases, exfiltrated large volumes of personal information and copied data rather than encrypting systems. This was data theft, not ransomware in the traditional “systems locked” sense that we often see.


The compromised data included:


  • Names, dates of birth, and contact details

  • Student ID numbers

  • Medical alert fields and accommodations

  • Guardianship or custody indicators

  • Educator contact and employment details


In Alberta, some school boards reported that social insurance numbers were also involved.


After the breach was discovered, PowerSchool paid a ransom, reportedly believing that the data would be deleted. Months later, a second extortion attempt occurred involving the same stolen data — a reminder that once data is taken, control is largely lost.


Paying the ransom might have been a very sensible thing to do in the circumstances, but it’s no guarantee that the data’s been deleted and will never re-surface.


THE REGULATORY RESPONSE


Because public bodies were involved, this triggered investigations by provincial privacy regulators.


  • In Ontario, the Information and Privacy Commissioner investigated 20 school boards and the Ministry of Education.

  • In Alberta, the Information and Privacy Commissioner investigated 33 school boards, charter schools, and a francophone authority.


In both provinces, the regulators focused on a central legal question: Did the public bodies take reasonable measures to protect personal information, as required by their respective privacy statutes?



ONTARIO FINDINGS


The Ontario Commissioner concluded that, as a group, the institutions did not meet their statutory obligations under FIPPA and MFIPPA. That’s the Freedom of Information and Protection of Privacy Act and the Municipal Freedom of Information and Protection of Privacy Act. 


There were three major themes in the Ontario findings: (1) Inadequate Security Safeguards, (2) Weak Contracts and Oversight, and (3) Data Minimization and Retention Failures.  


1. Inadequate Security Safeguards


The Commissioner identified multiple weaknesses with Security Safeguards


  • PowerSchool accounts with excessive privileges - The rationale for the principle of least privilege is to reduce security and privacy risk by limiting the damage that can result from human error, malicious insiders, or compromised accounts. It should be implemented by granting users, systems, and applications only the specific permissions required to perform defined tasks, using restrictive defaults, role-based or task-based access controls, time-limited elevation of privileges, and regular access reviews to remove unnecessary or outdated permissions.


  • No mandatory multi-factor authentication for PowerSource access - This is one of the most important and effective measures for preventing unauthorized use of purloined credentials. 


  • Always-on” remote maintenance access - This meant that a bad guy with the credentials could get access to the maintenance tools, rather than only at the invitation of individual school boards.


  • Short log-retention periods, which limited detection of earlier suspicious activity


While PowerSchool operated the systems, Ontario emphasized that the school boards were still responsible for ensuring reasonable protections were in place.


2. Weak Contracts and Oversight


Ontario was particularly critical of how school boards managed their contracts with PowerSchool.

Many agreements:


  • Lacked meaningful audit rights

  • Did not require detailed security reporting

  • Had limited enforcement mechanisms

  • Did not clearly address subcontractors


Even more importantly from the OIPC’s point of view, the boards did not actively monitor PowerSchool’s compliance with those contracts. In other words, contractual promises existed — but verification did not.


3. Data Minimization and Retention Failures


The Ontario Commissioner also focused on data minimization and retention failures. The Commissioner found that many institutions simply collected more data than necessary and retained data far longer than required.


That significantly amplified the harm when the breach occurred. If you don’t need it, don’t collect it. If you no longer need it, don’t retain it. If you fail on either one of those – or both! – you  have more data that you have to protect and more data that’s affected if things go wrong. 


The Ontario Commissioner also found that breach response planning was inconsistent and, in some cases, inadequate.


ALBERTA FINDINGS


Alberta reached a similar conclusion, but approached the analysis somewhat differently.


The Alberta Commissioner found that the educational bodies failed to comply with section 38 of the FOIP Act, which requires reasonable security arrangements.


Key aspects of Alberta’s findings included (1) A lack of internal policies and guidance, (2) treating PowerSchool as an “employee”, and (3) an emphasis on the sensitivity of children’s data.


1. Lack of Internal Policies and Governance


Alberta placed strong emphasis on the fact that many educational bodies did not have adequate privacy or vendor-management policies, they could not point to documented procedures for assessing or monitoring service providers and they simply relied heavily on PowerSchool’s assurances.


From the Alberta OIPC’s perspective, privacy compliance begins with governance.


2. PowerSchool Treated as an “Employee”


One notable legal point in Alberta’s report is that, under FOIP, a service provider performing services for a public body is legally treated as an “employee”. That meant PowerSchool’s actions were attributed directly to the school boards themselves. This reinforces the idea that outsourcing does not reduce accountability.


3. Strong Emphasis on Sensitivity of Children’s Data


Alberta was particularly explicit in recognizing that children’s personal information is inherently highly sensitive, especially medical and accommodation data.


That sensitivity raised the expected standard of protection — and Alberta concluded that PowerSchool’s safeguards fell below that standard.


KEY DIFFERENCES BETWEEN ONTARIO AND ALBERTA 


The conclusions in Ontario and Alberta were broadly aligned, but there are some differences in emphasis.


1. Governance vs. Contracting Focus


  • Ontario focused heavily on contracts, oversight, and vendor management failures.

  • Alberta focused more on internal policies, governance frameworks, and statutory accountability.


2. Sensitivity of Information


  • Alberta placed stronger, more explicit weight on the heightened sensitivity of children’s data.

  • Ontario addressed sensitivity, but framed much of the analysis around risk amplification through retention and over-collection.


Despite these differences, both regulators reached the same core conclusion: The public bodies did not meet their legal obligations, and outsourcing did not excuse that failure.


BROADER LESSONS


There are several broader takeaways from these investigations.


First, outsourcing does not outsource accountability. Public bodies remain legally responsible for personal information, regardless of who hosts it. This is the same in the private sector for outsourcing. Accountability does not shift under Canadian privacy laws. 


Second, contracts alone are not enough: Oversight, auditing, and verification matter.


Third, data minimization is a security control: Retaining unnecessary data simply increases breach impact.


And finally, children’s data demands higher standards. Regulators are very clear on that point.


CONCLUSION 


The PowerSchool incident may be just another cybersecurity story, but like most such stories there are lessons to be learned or reminders of things we should already know.


It’s a case study in public-sector procurement, privacy governance, and risk management.


Ontario and Alberta both sent a clear message: If you rely on third-party platforms to manage sensitive data — especially data about children — you must actively govern those relationships, not simply trust them.


In the backdrop to all of this is the simple fact that most school boards are chronically under-resourced and have a very hard time meeting their privacy and security obligations under existing budgets. This is particularly the case for smaller – often rural – school boards. The same can be said for smaller municipalities. Personally, I think the provinces should take a much more active role in working with school boards and their contractors to ensure the highest levels of cybersecurity. For a system as widely used as PowerSchool, provincial departments of education should enter into master services agreements with all the appropriate security terms, and the provincial departments of education should actively oversee at least the security and audit portions of the delivery of services. 


One final thing to note – just because school boards are 100% accountable to their students for personal information they collect, use and disclose doesn’t mean that PowerSchool is necessarily off the hook. PowerSchool – and any contractor for that matter – can be liable to their customers for any contractual failings when it comes to safeguarding personal information. And depending on the contract terms, the contractor may be liable for the cost of any lawsuits that students and parents might bring against the school boards. And I can imagine some more extreme cases where students, parents and teachers could have a viable claim directly against PowerSchool. I understand there is one putative class action pending, started by a Calgary law firm. And this would be in addition to the at least 55 class action lawsuits filed in the United States by American plaintiffs. 


Thursday, April 25, 2019

My Atlantic Security Conference 2019 Presentation: The New Privacy and Cybersecurity Legal Risk Landscape (or how to play nicely with lawyers)

I was invited back this year to the Atlantic Security Conference as a speaker. It's a great event and shows that Halifax really punches above its weight when it comes to tech and skills.



My presentation was on The New Privacy and Cybersecurity Legal Risk Landscape (or how to play nicely with lawyers), focusing on the drivers that are forcing a convergence between privacy and infosec. It also talks about the skills that infosec folks can cultivate to become of greater value to their clients, by developing skills to translate between business folks and lawyers on security issues. The crowd was great with some fantastic questions.

Here's the presentation for anyone who may be interested.

Saturday, September 22, 2018

The value of legal privilege: Your diligent privacy consultant may become your worst enemy

A diligent privacy consultant will do a thorough privacy impact assessment, a threat risk assessment or a gap analysis. They'll take a thorough look at your current practices and benchmark them against not just your competitors but against best practices. Most companies will fall short in one way or another, and many will decide to only address 70% of the risks identified. But what about the other 30%? If you're later sued, your consultant's report will suggest to a judge or a jury that you decided not to get your house in order. What might have been negligence can quickly become recklessness.

The reality is that nothing that a consulant produces for you -- unless they are properly teamed with legal counsel -- will be privileged. I've seen loads of consultants who mark their reports as privileged, but a legend on a document will never stand up in court.

I'm involved with a class action lawsuit where the defendant had, on multiple occasions, brought in a privacy consultant to advise on a range of matters. As a diligent consultant should, they identified a number of problems with processes, practices and policies. They almost called the situation a dumpster fire. The organization sought to address most of these, but they didn't focus on all of them. When a huge breach happened and a huge class action lawsuit followed, the breach could be easily attributed to one of the areas where insufficient remediation took place. They went from being careless to being reckless. And the consultant's report will be Exhibit A in the lawsuit.

Even the most diligent organization, when it takes a microscope to its practices, will discover problems. Unless you're going to address every single shortcoming, you need to be aware of what you might discover. And what you discover may be handed on a silver platter to the plaintiffs.

In the case I'm referring to, if this report had been prepared by legal counsel--focusing on advising the organization about its actual legal risk rather than benchmarking against nebulous best practices--it never would become Exhibit A in the class action.

In this age of breach notification, when class actions will inevitably follow notifications, you need to make sure that you know your risks so you can address the most serious of them. And you need to make sure that these reports are truly seeking legal advice and will never see the light of day.

With many of my clients, we've been harnessing the capabilities of privacy consultants while structuring the engagement to make sure that all the findings are shielded from litigation discovery.

If you hire consultants, think about what might happen after a breach and you have to hand them over to plaintiffs' counsel. That can be addressed right now and you should think about it.

Thursday, April 26, 2018

AtlSecCon Presentation: Canada's new data breach notification regime

I had the pleasure of giving a presentation to the Atlantic Security Conference this afternoon on Canada's new data breach notification regime, which is coming into effect on November 1, 2018. It's posted below in case it's of interest to a wider audience.

Monday, March 16, 2015

Privacy Commissioner: Health Canada violated privacy laws by disclosing personal health information of over 40,000 Canadians

A press release issued today by my firm and the other firms listed below, who are representing more than 40,000 Canadians affected by a Health Canada privacy breach:

The Office of the Privacy Commissioner of Canada has completed its investigation of Health Canada's privacy breach affecting over 40,000 licensees of the Marihuana Medical Access Program (MMAP), concluding that Health Canada violated federal privacy laws.

In November 2013, Health Canada sent written notices to over 40,000 individuals, outlining changes to the MMAP. The envelopes used for the mail-out clearly included the words "Health Canada - Marihuana Medical Access Program" on the return address, indicating to anyone who saw the envelopes that the recipient was either licensed to possess medical marihuana or to grow it for medical purposes. The envelopes were oversized so more likely to come to people's attention. Previously, Health Canada had been discreet in its communications with program members.

Three hundred and thirty nine affected individuals complained to the Office of the Privacy Commissioner, who initiated an investigation. The complainants cited several concerns relating to the impact of Health Canada's actions on their personal lives including concerns about losing their jobs, reputational damage and personal safety.

In a finding dated March 3, 2015, the Commissioner determined that Health Canada had violated the federal Privacy Act, which is designed to protect the privacy of Canadians when the federal government handles their sensitive information. The Commissioner's Finding was only sent to the 339 individuals who filed complaints with the Privacy Commissioner, but a copy of the document can be found here. Affected individuals who were not among the original complainants do not have to file additional complaints to the Commissioner, as the investigation is concluded.

The finding rejects the justifications put forward by Health Canada, which include blaming the patients for having gone to the media about the breach, which brought attention to the matter. The government also suggested that including the full name of the program instead of an abbreviation that would protect privacy was one of the "reasonable options" available to it under the law.

McInnes Cooper, Branch MacMaster LLP, Charney Lawyers, and Sutts Strosberg LLP are jointly representing affected users in an intended class action lawsuit against Health Canada filed in the Federal Court.

"It was clear to me, as soon as my phone started ringing in November 2013, that there was no justification for the careless error made by Health Canada in this case," said privacy lawyer David Fraser of McInnes Cooper. "It's one thing to acknowledge making a mistake, which Health Canada did, but immediately turning around to blame the victims is repulsive."

"We are pleased that the Privacy Commissioner of Canada agrees that Health Canada violated the law in its mishandling of patients' personal information," said David Robins of Sutts Strosberg LLP.

"Hundreds of people have reached out to us through our secure website for the class action to tell us how the breach has affected them, from lost jobs, effects on family relationships and social stigma. Each person who was a part of the MMAP was promised by Health Canada that their confidentiality would be protected," said Ted Charney of Charney Lawyers, adding that "the Commissioner is not able to award compensation to the victims or penalize Health Canada for its unlawful conduct, so the class action lawsuit is important in pursuing justice."

"We expect that the court hearing to ask that the case be blessed as a certified class action will take place in the early summer. If the judge agrees, we can move forward with the merits of the case," said Ward Branch of Branch MacMaster. "The privacy commissioner's report serves as a helpful roadmap for the case."

Affected class individuals are encouraged to register at www.marijuanaclassaction.com. While class members are not required to "opt in" to participate in the intended class action lawsuit, providing contact information and advising class counsel about how this privacy breach has affected you individually will help class counsel in bringing the case forward. Those who have already registered on the secure website do not need to re-register, but may want to update their information if their circumstances have changed or if they have experienced additional harms as a result of the breach.

About Branch MacMaster LLP

Branch MacMaster LLP is a boutique litigation law firm established in 1998 and located in Vancouver, British Columbia. The firm focuses on class actions, health, insurance, and personal injury. The firm provides responsive, flexible, and cost-effective service to their clientele.

About Charney Lawyers

Charney Lawyers is a Toronto, Ontario firm with an established reputation for excellence in advocacy. The firm is experienced in personal injury, class proceedings, commercial litigation, insurance defence, employment law, medical malpractice, food borne illness, construction law and appeals.

About McInnes Cooper

McInnes Cooper is among the top business and litigation law firms in Canada, with more than 200 lawyers in seven Canadian offices, serving clients across North America and abroad. The firm is a market leader in energy and natural resources, business, litigation, employment, tax, real estate and insurance law. McInnes Cooper is the exclusive member firm in Newfoundland, New Brunswick, Nova Scotia and Prince Edward Island for Lex Mundi – the world's leading network of independent law firms with in-depth experience in 100+ countries worldwide.

About Sutts Strosberg LLP

Sutts, Strosberg LLP is a nationally recognized law firm committed to excellence in litigation, with offices in Windsor and Toronto. The firm has a special interest in class actions, having represented groups or classes of individuals in every province and territory, and in every level of court, and is experienced in complex civil and commercial disputes, corporate, commercial and financial transactions, medical malpractice cases, personal injury cases, family law and criminal law.

Tuesday, February 25, 2014

Court agrees to protect plaintiffs' identities in invasion of privacy case against Health Canada

In a decision issued yesterday, the Federal Court ordered the the identity of plaintiffs in a putative class action against Health Canada should be protected to allow them to pursue their claim against the Government for the breach of privacy of members of the Medical Marihuana Access Program.

As blogged about last year, my firm filed a proposed class action lawsuit against Health Canada after it sent a mailing to approximately 40,000 people who are authorized to possess or grow marijuana under the program administered by Health Canada. (More info is here.)

Shortly after the breach occurred, lawsuits were filed in the federal courts by my firm, McInnes Cooper of Nova Scotia, and Branch McMaster of British Columbia. Sutts Strosberg of Ontario filed a lawsuit in the Ontario Superior Court. Each of these cases has a separate named plaintiff and all three of them were filed with the intent that they would be certified as class actions on behalf of all similarly affected participants in the MMAP.

The suit commenced by McInnes Cooper was filed on behalf of “John Doe”, a resident of Nova Scotia. The suit commenced by Sutts Strosberg was filed on behalf of “Suzie Jones”, a resident of Ontario. The case commenced by Branch McMaster was filed on behalf of an individual who chose to identify himself. The “John Doe” and “Suzie Jones” cases have been consolidated into one case in the Federal Court of Canada.

“John Doe” and “Suzie Jones” are pseudonyms for the proposed representative plaintiffs, so that the identities of those individuals would not become known. On February 20, 2014, a motion was heard in the Federal Court of Canada for an order of the court protecting the identities of “John Doe” and “Suzie Jones”. In most cases, parties to a legal action are required to name themselves and this information appears on the public record. Because the case against Health Canada is based on the disclosure of program members’ identities in association with the MMAP, requiring participants in these lawsuits to name themselves would further harm their privacy.

On February 25, 2013 we received the decision of the Court. The Court agreed that to deny the plaintiffs anonymity in the court proceeding would disclose the very information they seek to protect and exacerbate the damage and/or risk of harm that has already been caused by Health Canada’s mailing that identified them as a participant in the Program.

Government lawyers, on behalf of Health Canada, argued that this was a matter related solely to marihuana use and that the plaintiffs’ privacy should not be protected. Relying on newspaper articles and internet research, they argued that public opinion about marihuana use has changed to be more accepting. The Court rejected this evidence as irrelevant, explaining:

“What the Plaintiffs’ marijuana use discloses is their medical and health information. The Plaintiffs are patients, no simply “users”. Disclosing their identities discloses that a course of treatment has been prescribed by them by a medical doctor, and that they suffer from serious health conditions and symptoms. Identifying the Plaintiffs by name or information that discloses their personal identity also discloses that they have or are likely to have medical marihuana in their homes – something that Health Canada itself saw as a serious safety and security risk.

Accordingly, I am satisfied that in the within case of John Doe and Suzy Jones, without the protection they seek on this motion, the important issues they raise in their Amended Statement of Claim may not be determined in this forum, and that the issues they raise regarding patient rights, privacy and whether Health Canada owes a duty of care and has breached that duty and is liable are issues that are in the public interest to be determined. The Plaintiffs have requested only that their personal identity be protected and with minimum intrusion on the open court process.”


It's particularly gratifying that the Court acknowledged that this isn't just a matter of protecting the privacy of marihuana users, but more centrally concerns sensitive health information that was disclosed.

(Members of the proposed class can register and get more information at http://www.marijuanaclassaction.com).

Monday, November 25, 2013

Class Action filed against Health Canada in Medical Marijuana privacy breach


Marijuana privacy breach class action blog post

This afternoon, my firm filed a statement of claim in the Federal Court against Health Canada (John Doe v. Her Majesty) in connection with the massive privacy breach associated with the government’s medical marijuana program. As we understand it, Health Canada irresponsibly deviated from their usual practice of plain brown envelopes, couriers and registered mail by sending a mailing to around 40,000 individuals associated with the program clearly announcing the “Medical Marihuana Program” on the return address.

Between Friday and today, I have had many calls from individuals whose privacy was compromised by this breach, most of them fearing for their jobs and all of them concerned about their own safety. If it gets out in your community that you lawfully possess cannabis, this makes you a target for break and enters. The risk is even more heightened if you are a licensed grower of the plant. While this is a lawful program, the use of medical marijuana is heavily stigmatized.

This is not like most large-scale privacy breaches where the harm is mostly theoretical, since the missing hard-drive or thumb-drive likely didn’t leave the building. In this case, sensitive personal information was exposed to people who had no right to see it. I am told that some people have already lost their jobs because of this. For the rest, it is hard to put a price on legitimate concern about your family’s safety. I lived for a number of years in a community of 400 people, where the Canada Post employees were also neighbours.

Health Canada has dismissed this as a simple administrative error that they’ll endeavour to not repeat. But that’s not good enough from our government. People get to choose the businesses they deal with. If you don’t like how your bank or other service provider handles your personal information, you can change banks or businesses. But that’s not the case with your government. It’s a non-consensual relationship and the government owes a special duty of care to its citizens to protect them and to protect their sensitive personal information. Participants in this program were obtaining a restricted drug for medical purposes and could not do so lawfully except through the government program. Citizens should not have to choose between doing it lawfully or doing it safely. And we are talking about sensitive personal health information, which is generally recognized in Canada as the most sensitive personal information.

If you, or anyone you know, has been affected by this breach, please go to http://www.healthprivacyclassaction.com to provide your contact information so we can keep you apprised of this case as it progresses. Please provide an e-mail address that is confidential only to you. If this breach has had a particular impact on you, there is a portion of the form to provide details about this. Any information you provide will be kept confidential.

Here is the media release:

McInnes Cooper law firm files national class action in medical marijuana privacy breach

HALIFAX, Nov. 25, 2013 /CNW/ - McInnes Cooper law firm today filed a proposed class action in Federal Court against the Government of Canada in response to Health Canada's breach of the privacy rights of 40,000 patients in the Marijuana Medical Access Program. Under the Marijuana Medical Access Program, patients are permitted to grow marijuana in their residence for medicinal purposes.  

Earlier this month, Health Canada sent these patients a letter via Canada Post that clearly indicated on the envelope that the named patient participated in the Marijuana Medical Access Program.

Health Canada's disclosure of the patients' private medical information has raised serious employment and security concerns, and caused the patients to suffer considerable stress and anxiety.

"As a result of Health Canada's error, we have already spoken with a number of people whose lives have been affected by this breach," said David Fraser, a national expert on privacy law, and McInnes Cooper's lead lawyer on this case.

"We have heard that some individuals have already lost their jobs as a result, and everyone we've spoken with is concerned about their safety in their homes."

SOURCE: McInnes Cooper

The statement of claim is here:

FEDERAL COURT

 

PROPOSED CLASS ACTION

 

 

BETWEEN:

 

JOHN DOE

 

                                                                                                                            PLAINTIFF

 

- and -

                                                                                                                                                                

                                                                                                                                                                 

HER MAJESTY THE QUEEN

 

                                                                DEFENDANT

 

 

STATEMENT OF CLAIM

 

 

TO THE DEFENDANT:

 

A LEGAL PROCEEDING HAS BEEN COMMENCED AGAINST YOU by the Plaintiff.  The claim made against you is set out in the following pages.

 

                IF YOU WISH TO DEFEND THIS PROCEEDING, you or a solicitor acting for you are required to prepare a statement of defence in Form 171B prescribed by the Federal Courts Rules, serve it on the Plaintiff’s solicitor or, where the Plaintiff does not have a solicitor, serve it on the Plaintiff, and file it, with proof of service, at a local office of this Court, WITHIN 30 DAYS after this Statement of Claim is served on you, if you are served within Canada.

 

                If you are served in the United States of America, the period for serving and filing your Statement of Defence is forty days.  If you are served outside Canada and the United States of America, the period for serving and filing your Statement of Defence is sixty days.

 

                Copies of the Federal Courts Rules, information concerning the local offices of the Court and other necessary information may be obtained on request to the Administrator of this Court at Ottawa (telephone: 613-992-4238) or at any local office.

 

                IF YOU FAIL TO DEFEND THIS PROCEEDING, judgment may be given against you in your absence and without further notice to you.

 

 

Date:  _____________________________________

 

Issued by:  _________________________________

[Registry Officer]

 

Address of local office:  1801 Hollis Street,

                                            17th Floor, Suite 1720

                                            Halifax, N.S.  B3J 1S7

                             

 

To:                   The Attorney General of Canada

Attention:     Mr. Willian F. Pentney, Deputy Attorney General of Canada

 

 

 

Claim

 

1.    The Plaintiff claims on his own behalf and on behalf of the proposed Class:

 

a.    An Order pursuant to Rules 334.16(1) and 334.17 of the Federal Courts Rules certifying this action as a class proceeding;

 

b.    An Order pursuant to Rules 334.12(3), 334.16(1)(e) and 334.17(b) appointing the Plaintiff as the representative plaintiff for the Class;

 

c.    Damages for the torts of intrusion upon seclusion, publicity given to private life, breach of confidence and negligence;

 

d.    An Order pursuant to Rule 334.28(1) and (2) for the aggregate assessment of monetary relief and its distribution to the Plaintiff and the Class;

 

e.    Prejudgment interest pursuant to section 36 of the Federal Courts Act;

 

f.     Costs, if appropriate; and

 

g.    Such further and other relief as this Honourable Court deems just.

 

Parties

 

2.    The Plaintiff is an individual who resides in Nova Scotia. He is employed in the health care field.

 

3.    The Plaintiff brings this action on his own behalf and on behalf of the members of the proposed class, which is defined as follows:

 

All persons who were sent a letter from Health Canada in November 2013 that had the phrase Marihuana Medical Access Program or a similar French phrase visible on the front of the envelope.

 

4.    The Defendant, Her Majesty the Queen, is named as a representative of the Federal Government of Canada and Health Canada. Health Canada administers the Marihuana Medical Access Program under the Marihuana Medical Access Regulations.

 

Medical Marihuana Access Program

 

5.    Through the Marihuana Medical Access Program, the Defendant grants access to marihuana for medical use to Canadians suffering from grave and debilitating illnesses.

 

6.    Marihuana (cannabis) is categorized as a controlled substance, regulated in Canada under the Controlled Drugs and Substances Act. It is not legal to grow or possess marihuana except with legal permission by the Defendant under the Marihuana Medical Access Program.

 

7.    The Plaintiff applied to participate in the Defendant’s Marihuana Medical Access Program to grow and possess marihuana to alleviate the pain that he suffers due to a medical condition. The Defendant approved the Plaintiff’s application.

 

Disclosure of the Plaintiff’s Private Information

 

8.    The Defendant typically corresponds to the Plaintiff by courier service with plain unmarked brown envelopes.

 

9.    During the week of November 21, 2013, the Defendant sent the Plaintiff a letter plainly and clearly indicating on the envelope that it was from Health Canada and that it was in regards to the Marihuana Medical Access Program.

 

10.  By publically indicating that the Plaintiff was a participant in the Marihuana Medical Access Program, the Defendant disclosed the personal health information about the Plaintiff. Furthermore, the Defendant’s disclosure creates a security concern by alerting other individuals that the Plaintiff may possess and/or grow marihuana at his residence.

 

Negligence

 

11.  At all material times, the Defendant owed a duty of care to the Plaintiff and the proposed Class.

 

12.  Furthermore, the Defendant had a statutory duty under subsection 8(1) of the Privacy Act to not disclose personal information without that individual’s consent. The Plaintiff’s and the Class’ participation in the Marihuana Medical Access Program constitutes personal information as it is confidential information and relates to their medical history.

 

13.  The Defendant breached its duty of care owed to the Plaintiff and the Class by:

 

a.    Failing to meet its statutory duties and/or policies in the collection, retention and disclosure of personal information;

 

b.    Failing to take reasonable steps to ensure the personal information was not disclosed;

 

c.    Failing to communicate with the Plaintiff and the Class in a manner that did not disclose their personal information; and

 

d.    Other such particulars as counsel may advise.

 

Publicity Given to Private Life

 

14.  Through its actions stated above, the Defendant gave publicity to the Plaintiff’s private, personal information, particularly his medical condition.

 

15.  The Plaintiff’s private personal information is of no legitimate concern to the public. The Defendant’s disclosure of the Plaintiff’s private personal information is highly offensive to a reasonable person.

 

Breach of Confidence

 

16.  The Plaintiff states that the Defendant committed the tort of breach of confidence.

 

17.  In applying to participate in the Marihuana Medical Access Program, the Plaintiff conveyed confidential information in confidence to the Defendant.

 

18.  In its actions stated above, the Defendant misused the Plaintiff’s confidential information to the Plaintiff’ detriment.

 

Intrusion upon Seclusion

 

19.  The Defendant’s above stated actions constitute an intrusion on seclusion in a manner that would be highly offensive to a reasonable person.

 

Relief Sought

 

20.  The Defendant’s actions have caused the Plaintiff and the Class to suffer the following damages:

 

a.    Costs incurred in taking additional security precautions;

b.    Damage to reputation;

c.    Damage to employment;

d.    Mental distress;

e.    General damages; and

f.     Inconvenience, frustration and anxiety.

 

General

 

21.  The Plaintiff proposes that this trial take place in Halifax.

 

DATED at Halifax, in the Province of Nova Scotia, this 25th day of November 2013.

 

 

PLACE OF TRIAL:                    HALIFAX, NOVA SCOTIA

 

 

                                                                ____________________________________

                                                                            David T.S. Fraser

Solicitor for the Plaintiff