Showing posts with label information breaches. Show all posts
Showing posts with label information breaches. Show all posts

Thursday, April 25, 2019

My Atlantic Security Conference 2019 Presentation: The New Privacy and Cybersecurity Legal Risk Landscape (or how to play nicely with lawyers)

I was invited back this year to the Atlantic Security Conference as a speaker. It's a great event and shows that Halifax really punches above its weight when it comes to tech and skills.



My presentation was on The New Privacy and Cybersecurity Legal Risk Landscape (or how to play nicely with lawyers), focusing on the drivers that are forcing a convergence between privacy and infosec. It also talks about the skills that infosec folks can cultivate to become of greater value to their clients, by developing skills to translate between business folks and lawyers on security issues. The crowd was great with some fantastic questions.

Here's the presentation for anyone who may be interested.

Monday, March 16, 2015

Privacy Commissioner: Health Canada violated privacy laws by disclosing personal health information of over 40,000 Canadians

A press release issued today by my firm and the other firms listed below, who are representing more than 40,000 Canadians affected by a Health Canada privacy breach:

The Office of the Privacy Commissioner of Canada has completed its investigation of Health Canada's privacy breach affecting over 40,000 licensees of the Marihuana Medical Access Program (MMAP), concluding that Health Canada violated federal privacy laws.

In November 2013, Health Canada sent written notices to over 40,000 individuals, outlining changes to the MMAP. The envelopes used for the mail-out clearly included the words "Health Canada - Marihuana Medical Access Program" on the return address, indicating to anyone who saw the envelopes that the recipient was either licensed to possess medical marihuana or to grow it for medical purposes. The envelopes were oversized so more likely to come to people's attention. Previously, Health Canada had been discreet in its communications with program members.

Three hundred and thirty nine affected individuals complained to the Office of the Privacy Commissioner, who initiated an investigation. The complainants cited several concerns relating to the impact of Health Canada's actions on their personal lives including concerns about losing their jobs, reputational damage and personal safety.

In a finding dated March 3, 2015, the Commissioner determined that Health Canada had violated the federal Privacy Act, which is designed to protect the privacy of Canadians when the federal government handles their sensitive information. The Commissioner's Finding was only sent to the 339 individuals who filed complaints with the Privacy Commissioner, but a copy of the document can be found here. Affected individuals who were not among the original complainants do not have to file additional complaints to the Commissioner, as the investigation is concluded.

The finding rejects the justifications put forward by Health Canada, which include blaming the patients for having gone to the media about the breach, which brought attention to the matter. The government also suggested that including the full name of the program instead of an abbreviation that would protect privacy was one of the "reasonable options" available to it under the law.

McInnes Cooper, Branch MacMaster LLP, Charney Lawyers, and Sutts Strosberg LLP are jointly representing affected users in an intended class action lawsuit against Health Canada filed in the Federal Court.

"It was clear to me, as soon as my phone started ringing in November 2013, that there was no justification for the careless error made by Health Canada in this case," said privacy lawyer David Fraser of McInnes Cooper. "It's one thing to acknowledge making a mistake, which Health Canada did, but immediately turning around to blame the victims is repulsive."

"We are pleased that the Privacy Commissioner of Canada agrees that Health Canada violated the law in its mishandling of patients' personal information," said David Robins of Sutts Strosberg LLP.

"Hundreds of people have reached out to us through our secure website for the class action to tell us how the breach has affected them, from lost jobs, effects on family relationships and social stigma. Each person who was a part of the MMAP was promised by Health Canada that their confidentiality would be protected," said Ted Charney of Charney Lawyers, adding that "the Commissioner is not able to award compensation to the victims or penalize Health Canada for its unlawful conduct, so the class action lawsuit is important in pursuing justice."

"We expect that the court hearing to ask that the case be blessed as a certified class action will take place in the early summer. If the judge agrees, we can move forward with the merits of the case," said Ward Branch of Branch MacMaster. "The privacy commissioner's report serves as a helpful roadmap for the case."

Affected class individuals are encouraged to register at www.marijuanaclassaction.com. While class members are not required to "opt in" to participate in the intended class action lawsuit, providing contact information and advising class counsel about how this privacy breach has affected you individually will help class counsel in bringing the case forward. Those who have already registered on the secure website do not need to re-register, but may want to update their information if their circumstances have changed or if they have experienced additional harms as a result of the breach.

About Branch MacMaster LLP

Branch MacMaster LLP is a boutique litigation law firm established in 1998 and located in Vancouver, British Columbia. The firm focuses on class actions, health, insurance, and personal injury. The firm provides responsive, flexible, and cost-effective service to their clientele.

About Charney Lawyers

Charney Lawyers is a Toronto, Ontario firm with an established reputation for excellence in advocacy. The firm is experienced in personal injury, class proceedings, commercial litigation, insurance defence, employment law, medical malpractice, food borne illness, construction law and appeals.

About McInnes Cooper

McInnes Cooper is among the top business and litigation law firms in Canada, with more than 200 lawyers in seven Canadian offices, serving clients across North America and abroad. The firm is a market leader in energy and natural resources, business, litigation, employment, tax, real estate and insurance law. McInnes Cooper is the exclusive member firm in Newfoundland, New Brunswick, Nova Scotia and Prince Edward Island for Lex Mundi – the world's leading network of independent law firms with in-depth experience in 100+ countries worldwide.

About Sutts Strosberg LLP

Sutts, Strosberg LLP is a nationally recognized law firm committed to excellence in litigation, with offices in Windsor and Toronto. The firm has a special interest in class actions, having represented groups or classes of individuals in every province and territory, and in every level of court, and is experienced in complex civil and commercial disputes, corporate, commercial and financial transactions, medical malpractice cases, personal injury cases, family law and criminal law.

Tuesday, February 25, 2014

Court agrees to protect plaintiffs' identities in invasion of privacy case against Health Canada

In a decision issued yesterday, the Federal Court ordered the the identity of plaintiffs in a putative class action against Health Canada should be protected to allow them to pursue their claim against the Government for the breach of privacy of members of the Medical Marihuana Access Program.

As blogged about last year, my firm filed a proposed class action lawsuit against Health Canada after it sent a mailing to approximately 40,000 people who are authorized to possess or grow marijuana under the program administered by Health Canada. (More info is here.)

Shortly after the breach occurred, lawsuits were filed in the federal courts by my firm, McInnes Cooper of Nova Scotia, and Branch McMaster of British Columbia. Sutts Strosberg of Ontario filed a lawsuit in the Ontario Superior Court. Each of these cases has a separate named plaintiff and all three of them were filed with the intent that they would be certified as class actions on behalf of all similarly affected participants in the MMAP.

The suit commenced by McInnes Cooper was filed on behalf of “John Doe”, a resident of Nova Scotia. The suit commenced by Sutts Strosberg was filed on behalf of “Suzie Jones”, a resident of Ontario. The case commenced by Branch McMaster was filed on behalf of an individual who chose to identify himself. The “John Doe” and “Suzie Jones” cases have been consolidated into one case in the Federal Court of Canada.

“John Doe” and “Suzie Jones” are pseudonyms for the proposed representative plaintiffs, so that the identities of those individuals would not become known. On February 20, 2014, a motion was heard in the Federal Court of Canada for an order of the court protecting the identities of “John Doe” and “Suzie Jones”. In most cases, parties to a legal action are required to name themselves and this information appears on the public record. Because the case against Health Canada is based on the disclosure of program members’ identities in association with the MMAP, requiring participants in these lawsuits to name themselves would further harm their privacy.

On February 25, 2013 we received the decision of the Court. The Court agreed that to deny the plaintiffs anonymity in the court proceeding would disclose the very information they seek to protect and exacerbate the damage and/or risk of harm that has already been caused by Health Canada’s mailing that identified them as a participant in the Program.

Government lawyers, on behalf of Health Canada, argued that this was a matter related solely to marihuana use and that the plaintiffs’ privacy should not be protected. Relying on newspaper articles and internet research, they argued that public opinion about marihuana use has changed to be more accepting. The Court rejected this evidence as irrelevant, explaining:

“What the Plaintiffs’ marijuana use discloses is their medical and health information. The Plaintiffs are patients, no simply “users”. Disclosing their identities discloses that a course of treatment has been prescribed by them by a medical doctor, and that they suffer from serious health conditions and symptoms. Identifying the Plaintiffs by name or information that discloses their personal identity also discloses that they have or are likely to have medical marihuana in their homes – something that Health Canada itself saw as a serious safety and security risk.

Accordingly, I am satisfied that in the within case of John Doe and Suzy Jones, without the protection they seek on this motion, the important issues they raise in their Amended Statement of Claim may not be determined in this forum, and that the issues they raise regarding patient rights, privacy and whether Health Canada owes a duty of care and has breached that duty and is liable are issues that are in the public interest to be determined. The Plaintiffs have requested only that their personal identity be protected and with minimum intrusion on the open court process.”


It's particularly gratifying that the Court acknowledged that this isn't just a matter of protecting the privacy of marihuana users, but more centrally concerns sensitive health information that was disclosed.

(Members of the proposed class can register and get more information at http://www.marijuanaclassaction.com).

Monday, November 25, 2013

Class Action filed against Health Canada in Medical Marijuana privacy breach


Marijuana privacy breach class action blog post

This afternoon, my firm filed a statement of claim in the Federal Court against Health Canada (John Doe v. Her Majesty) in connection with the massive privacy breach associated with the government’s medical marijuana program. As we understand it, Health Canada irresponsibly deviated from their usual practice of plain brown envelopes, couriers and registered mail by sending a mailing to around 40,000 individuals associated with the program clearly announcing the “Medical Marihuana Program” on the return address.

Between Friday and today, I have had many calls from individuals whose privacy was compromised by this breach, most of them fearing for their jobs and all of them concerned about their own safety. If it gets out in your community that you lawfully possess cannabis, this makes you a target for break and enters. The risk is even more heightened if you are a licensed grower of the plant. While this is a lawful program, the use of medical marijuana is heavily stigmatized.

This is not like most large-scale privacy breaches where the harm is mostly theoretical, since the missing hard-drive or thumb-drive likely didn’t leave the building. In this case, sensitive personal information was exposed to people who had no right to see it. I am told that some people have already lost their jobs because of this. For the rest, it is hard to put a price on legitimate concern about your family’s safety. I lived for a number of years in a community of 400 people, where the Canada Post employees were also neighbours.

Health Canada has dismissed this as a simple administrative error that they’ll endeavour to not repeat. But that’s not good enough from our government. People get to choose the businesses they deal with. If you don’t like how your bank or other service provider handles your personal information, you can change banks or businesses. But that’s not the case with your government. It’s a non-consensual relationship and the government owes a special duty of care to its citizens to protect them and to protect their sensitive personal information. Participants in this program were obtaining a restricted drug for medical purposes and could not do so lawfully except through the government program. Citizens should not have to choose between doing it lawfully or doing it safely. And we are talking about sensitive personal health information, which is generally recognized in Canada as the most sensitive personal information.

If you, or anyone you know, has been affected by this breach, please go to http://www.healthprivacyclassaction.com to provide your contact information so we can keep you apprised of this case as it progresses. Please provide an e-mail address that is confidential only to you. If this breach has had a particular impact on you, there is a portion of the form to provide details about this. Any information you provide will be kept confidential.

Here is the media release:

McInnes Cooper law firm files national class action in medical marijuana privacy breach

HALIFAX, Nov. 25, 2013 /CNW/ - McInnes Cooper law firm today filed a proposed class action in Federal Court against the Government of Canada in response to Health Canada's breach of the privacy rights of 40,000 patients in the Marijuana Medical Access Program. Under the Marijuana Medical Access Program, patients are permitted to grow marijuana in their residence for medicinal purposes.  

Earlier this month, Health Canada sent these patients a letter via Canada Post that clearly indicated on the envelope that the named patient participated in the Marijuana Medical Access Program.

Health Canada's disclosure of the patients' private medical information has raised serious employment and security concerns, and caused the patients to suffer considerable stress and anxiety.

"As a result of Health Canada's error, we have already spoken with a number of people whose lives have been affected by this breach," said David Fraser, a national expert on privacy law, and McInnes Cooper's lead lawyer on this case.

"We have heard that some individuals have already lost their jobs as a result, and everyone we've spoken with is concerned about their safety in their homes."

SOURCE: McInnes Cooper

The statement of claim is here:

FEDERAL COURT

 

PROPOSED CLASS ACTION

 

 

BETWEEN:

 

JOHN DOE

 

                                                                                                                            PLAINTIFF

 

- and -

                                                                                                                                                                

                                                                                                                                                                 

HER MAJESTY THE QUEEN

 

                                                                DEFENDANT

 

 

STATEMENT OF CLAIM

 

 

TO THE DEFENDANT:

 

A LEGAL PROCEEDING HAS BEEN COMMENCED AGAINST YOU by the Plaintiff.  The claim made against you is set out in the following pages.

 

                IF YOU WISH TO DEFEND THIS PROCEEDING, you or a solicitor acting for you are required to prepare a statement of defence in Form 171B prescribed by the Federal Courts Rules, serve it on the Plaintiff’s solicitor or, where the Plaintiff does not have a solicitor, serve it on the Plaintiff, and file it, with proof of service, at a local office of this Court, WITHIN 30 DAYS after this Statement of Claim is served on you, if you are served within Canada.

 

                If you are served in the United States of America, the period for serving and filing your Statement of Defence is forty days.  If you are served outside Canada and the United States of America, the period for serving and filing your Statement of Defence is sixty days.

 

                Copies of the Federal Courts Rules, information concerning the local offices of the Court and other necessary information may be obtained on request to the Administrator of this Court at Ottawa (telephone: 613-992-4238) or at any local office.

 

                IF YOU FAIL TO DEFEND THIS PROCEEDING, judgment may be given against you in your absence and without further notice to you.

 

 

Date:  _____________________________________

 

Issued by:  _________________________________

[Registry Officer]

 

Address of local office:  1801 Hollis Street,

                                            17th Floor, Suite 1720

                                            Halifax, N.S.  B3J 1S7

                             

 

To:                   The Attorney General of Canada

Attention:     Mr. Willian F. Pentney, Deputy Attorney General of Canada

 

 

 

Claim

 

1.    The Plaintiff claims on his own behalf and on behalf of the proposed Class:

 

a.    An Order pursuant to Rules 334.16(1) and 334.17 of the Federal Courts Rules certifying this action as a class proceeding;

 

b.    An Order pursuant to Rules 334.12(3), 334.16(1)(e) and 334.17(b) appointing the Plaintiff as the representative plaintiff for the Class;

 

c.    Damages for the torts of intrusion upon seclusion, publicity given to private life, breach of confidence and negligence;

 

d.    An Order pursuant to Rule 334.28(1) and (2) for the aggregate assessment of monetary relief and its distribution to the Plaintiff and the Class;

 

e.    Prejudgment interest pursuant to section 36 of the Federal Courts Act;

 

f.     Costs, if appropriate; and

 

g.    Such further and other relief as this Honourable Court deems just.

 

Parties

 

2.    The Plaintiff is an individual who resides in Nova Scotia. He is employed in the health care field.

 

3.    The Plaintiff brings this action on his own behalf and on behalf of the members of the proposed class, which is defined as follows:

 

All persons who were sent a letter from Health Canada in November 2013 that had the phrase Marihuana Medical Access Program or a similar French phrase visible on the front of the envelope.

 

4.    The Defendant, Her Majesty the Queen, is named as a representative of the Federal Government of Canada and Health Canada. Health Canada administers the Marihuana Medical Access Program under the Marihuana Medical Access Regulations.

 

Medical Marihuana Access Program

 

5.    Through the Marihuana Medical Access Program, the Defendant grants access to marihuana for medical use to Canadians suffering from grave and debilitating illnesses.

 

6.    Marihuana (cannabis) is categorized as a controlled substance, regulated in Canada under the Controlled Drugs and Substances Act. It is not legal to grow or possess marihuana except with legal permission by the Defendant under the Marihuana Medical Access Program.

 

7.    The Plaintiff applied to participate in the Defendant’s Marihuana Medical Access Program to grow and possess marihuana to alleviate the pain that he suffers due to a medical condition. The Defendant approved the Plaintiff’s application.

 

Disclosure of the Plaintiff’s Private Information

 

8.    The Defendant typically corresponds to the Plaintiff by courier service with plain unmarked brown envelopes.

 

9.    During the week of November 21, 2013, the Defendant sent the Plaintiff a letter plainly and clearly indicating on the envelope that it was from Health Canada and that it was in regards to the Marihuana Medical Access Program.

 

10.  By publically indicating that the Plaintiff was a participant in the Marihuana Medical Access Program, the Defendant disclosed the personal health information about the Plaintiff. Furthermore, the Defendant’s disclosure creates a security concern by alerting other individuals that the Plaintiff may possess and/or grow marihuana at his residence.

 

Negligence

 

11.  At all material times, the Defendant owed a duty of care to the Plaintiff and the proposed Class.

 

12.  Furthermore, the Defendant had a statutory duty under subsection 8(1) of the Privacy Act to not disclose personal information without that individual’s consent. The Plaintiff’s and the Class’ participation in the Marihuana Medical Access Program constitutes personal information as it is confidential information and relates to their medical history.

 

13.  The Defendant breached its duty of care owed to the Plaintiff and the Class by:

 

a.    Failing to meet its statutory duties and/or policies in the collection, retention and disclosure of personal information;

 

b.    Failing to take reasonable steps to ensure the personal information was not disclosed;

 

c.    Failing to communicate with the Plaintiff and the Class in a manner that did not disclose their personal information; and

 

d.    Other such particulars as counsel may advise.

 

Publicity Given to Private Life

 

14.  Through its actions stated above, the Defendant gave publicity to the Plaintiff’s private, personal information, particularly his medical condition.

 

15.  The Plaintiff’s private personal information is of no legitimate concern to the public. The Defendant’s disclosure of the Plaintiff’s private personal information is highly offensive to a reasonable person.

 

Breach of Confidence

 

16.  The Plaintiff states that the Defendant committed the tort of breach of confidence.

 

17.  In applying to participate in the Marihuana Medical Access Program, the Plaintiff conveyed confidential information in confidence to the Defendant.

 

18.  In its actions stated above, the Defendant misused the Plaintiff’s confidential information to the Plaintiff’ detriment.

 

Intrusion upon Seclusion

 

19.  The Defendant’s above stated actions constitute an intrusion on seclusion in a manner that would be highly offensive to a reasonable person.

 

Relief Sought

 

20.  The Defendant’s actions have caused the Plaintiff and the Class to suffer the following damages:

 

a.    Costs incurred in taking additional security precautions;

b.    Damage to reputation;

c.    Damage to employment;

d.    Mental distress;

e.    General damages; and

f.     Inconvenience, frustration and anxiety.

 

General

 

21.  The Plaintiff proposes that this trial take place in Halifax.

 

DATED at Halifax, in the Province of Nova Scotia, this 25th day of November 2013.

 

 

PLACE OF TRIAL:                    HALIFAX, NOVA SCOTIA

 

 

                                                                ____________________________________

                                                                            David T.S. Fraser

Solicitor for the Plaintiff

 

Tuesday, January 15, 2013

Massive BC privacy breach involves millions of health records

The Canadian Press, via the CBC, is reporting on a series of new data breaches from British Columbia that likely involved millions of health records. And, as with the HRSDC breaches, portable electronic USB storage devices are involved.

It appears that the province is not planning to notify everyone involved.

B.C. privacy breach shows millions affected - British Columbia - CBC News:

Ministry notifying more than 38,000 people about shared data

The personal-health data of millions of British Columbians has been accessed without proper authorization, and in the most serious cases, the provincial government says it will notify 38,486 individuals of the breaches by letter.
Health Minister Margaret MacDiarmid made the announcement as part of an ongoing investigation into research-grant practices between ministry employees and researchers at the universities of B.C. and Victoria.

MacDiarmid said that during three separate instances in October 2010 and June 2012, the health information was saved on USB sticks and shared with researchers or contractors without the proper permission or protocols.

McDiarmid said the data did not include names, addresses or financial information, but it wasn't supposed to be shared with other health researchers.

Also included was data from Statistics Canada's Canadian Community Health Survey, including information on the mental, physical and sexual health of individuals, as well as their lifestyles and the use of health services.

“We don't have any evidence at all that any of this information was used for any purpose other than health research. There is minimal if any risk that this information that would be used in a way that would be harmful to these individuals.”
MacDiarmid said her ministry decided to write the letters following discussions with the Office of the Information and Privacy Commissioner.

Elizabeth Denham, the information and privacy commissioner, also said Monday her independent investigation should be complete in the coming weeks, and she will then issue a public report with findings and recommendations.

Seven ministry workers have already been fired, sparking two separate lawsuits.

Friday, January 11, 2013

HRSDC "loses" sensitive personal information of another half MILLION Canadians

The CBC is reporting tonight that Human Resources and Skills Development Canada has lost a hard drive containing very sensitive personal information on more than five hundred thousand Canadians. This time, it was a portable hard drive and the information is about 583,000 student loan recipients.


Federal agency loses data on 583,000 Canadians - Nova Scotia - CBC News:
A portable hard drive containing personal information about more than half a million people who got student loans has gone missing, the federal government revealed Friday.

Human Resources and Skills Development Canada says the device disappeared from an HRSDC office in Gatineau, Que., in early November.

The hard drive had personal information on 583,000 Canadians who were clients of the Canada Student Loans program from 2000 to 2006. Borrowers from Quebec, Nunavut and the Northwest Territories are not affected.

The information on the missing hard drive includes:

  • Student names, social insurance numbers, dates of birth, contact information and loan balance of Canada Student Loan borrowers. 
  • Personal contact information for 250 HRSDC employees. 
The government says no banking or medical information was on the hard drive.

Letters are going out to everyone affected to tell them what steps to take to protect themselves.  

No evidence of fraud

So far, there's no sign that any of the missing data has been accessed or used for fraudulent purposes, but the government has called in the RCMP and alerted the office of the privacy commissioner.

"I want all Canadians to know that I have expressed my disappointment to departmental officials at this unacceptable and avoidable incident in handling Canadians’ personal information," said Human Resources and Skills Development Minister Diane Finley in a statement.

"I have requested that HRSDC employees across Canada receive comprehensive communications on the seriousness of these recent incidents and that they participate in mandatory training on a new security policy to ensure that similar situations do not occur again."
She says employees who fail to adhere to the new policy could be fired.

This is the second incident involving missing personal information that her department has faced in less than a month.

In late December, HRSDC revealed that a USB key containing personal information on about 5,000 Canadians disappeared in November.

Update: Check out the Government of Canada media release on this breach.

Saturday, December 29, 2012

Government "loses" sensitive personal information on thousands of Canadians

Over the past week, Human Resources and Skills Development Canada has been notifying approximately 5000 people that their personal information has been lost. According to reports, the information was on a USB device that has been "misplaced". The information includes Social Insurance Number(SIN); surname; primary and, if applicable, secondary medical condition; birthdate; presence of other payers (e.g., workers' compensation); level of education; occupation type; and, Service Canada processing centre.

This is an ENORMOUS screw up by the Government of Canada. Unencrypted personal information should never be put on these devices as they are notoriously easy to lose. I am also surprised that the Privacy Commissioner's office, at least as quoted in the media, has not yet decided whether to do a formal investigation.
Personal info for thousands lost by federal government - Politics - CBC News

A federal government department says there is no evidence that missing personal information about thousands of Canadians has been used for fraudulent purposes.Human Resources and Skills Development Canada says an employee reported on Nov. 16 that a USB key containing personal information, including Social Insurance Numbers, of about 5,000 Canadians was missing.

The department, which handles a variety of files including pensions, old age security, employment insurance and childcare tax credits, says all those affected have been contacted.

A spokesperson said in an email Friday evening that the affected people have been advised of the incident and informed of the steps they can take to help protect their personal information.

HRSDC notified the privacy commissioner's office on Dec. 21 that the data had been lost.

About 60 people have already called an information line at the privacy commissioner's office expressing concern about the incident and complaints have already been filed.
"It's too early to say whether or not these will turn into official, full, investigations," said Anne-Marie Hayden, a spokeswoman for the privacy commissioner.
"We'd have to look at what we receive first and determine next steps from there."
HRSDC said it has seen no evidence that any of the information contained on the missing USB key has been used for fraudulent purposes.

"Nonetheless, we have advised affected individuals to carefully review and verify bank information, credit card information and other financial transaction statements as a means of safeguarding their personal information as a precautionary measure," the email said.

"We are currently analyzing this incident with the view of preventing a similar occurrence in the future," it added.

The commissioner's office is working with HRSDC in an effort to figure out what happened.

Each year, federal departments are required to report on how well they comply with privacy legislation.

In the 2010-2011 report — the most recent one posted on HRSDC's website — the department noted that it had been the subject of three complaints regarding how it handled personal information.

Monday, November 07, 2011

2,700 personal tax files go missing after auditor takes work home

The Globe & Mail is reporting that approximately 2,700 personal tax files are missing after a Canada Revenue Agency employee did something that appears staggeringly stupid:

2,700 personal tax files go missing after auditor takes work home - The Globe and Mail

... The major breach occurred in early 2006, when an auditor in the agency’s Toronto office asked a government computer technician to download 37,488 of her e-mails and 776 documents onto 16 CDs. The confidential material covered the years 2000 to 2006, and was not encrypted as required by agency rules.

The woman took the CDs home, and allowed a male friend to copy at least one of them to a laptop.

The breach only came to light when the woman produced the CDs during a grievance hearing before the Public Service Labour Relations Board in 2008. She wanted the panel to read a key 2005 e-mail on one of the CDs, in support of her grievance that the CRA had not accommodated her health problems....

I can't imagine the justification for having taken the unencrypted CDs home. Copying them onto another laptop is simply surreal. But then not reporting the breach of any of the taxpayers involved or to the Privacy Commissioner is staggering.

This is further support to my belief that one of the most significant risks to data security is portable data. If employees are given secure remote access to their work data, the possibility of breaches such as this is virtually eliminated.

Friday, April 08, 2011

Presentation: Dealing with data breaches

This past weekend, I had the pleasure of being invited to speak at the Canadian Corporate Counsel Association's annual spring training for new in-house counsel. My portion of the presentation focused on dealing with data breaches and investigations by Canadian regulators.

Here's a copy of the presentation, in case it's of interest:

In case you can't see the embedded presentation, follow this link: https://docs.google.com/present/view?id=ddpx56cg_438dq7nkrdc&interval=30.

Tuesday, March 15, 2011

Missing Alberta health care provider hard drive had thousands of patient images

An unencrypted hard-drive has gone missing at Covenant Health in Alberta, leading to an investigation by the province's Information and Privacy Commissioner. The drive, it appears, contained exclusively images, but many of them would be considered to be highly sensitive including video of surgeries. The names and hospital numbers of the 3,600 relevant patients are also apparent from the directory and file naming systems. The drive apparently went missing when an employee was moving offices. Because it was not a "portable" drive, the data was not encrypted.

See: Missing hard drive had thousands of patient images - Calgary - CBC News.

Monday, January 17, 2011

Nova Scotia review officer considers investigation of WCB over misdirected file

Last week, the Halifax Chronicle Herald reported that the provincial Workers' Compensation Board mistakenly sent the wrong person's file to an individual who was contesting his claim under the program.

It looks like it was a one-off error:

WCB sends wrong file to man - Metro - TheChronicleHerald.ca)

.... MacLean insists the board does not often mix up its clients and she can’t remember the last time a file was mailed out in error.

"Our employees all go through (Freedom of Information and Protection of Privacy Act) and privacy breach training and we take this all very seriously."

And they have procedures to follow if something does go awry.

To help avoid personal information falling into a stranger’s hands, she said the envelope is stamped with a warning message that asks the recipient to alert the board if the received the envelope in error. It also asks the recipient not to open or destroy its contents.

However, she admitted, she didn’t know how anyone could tell if the file wasn’t theirs without first opening the envelope and reading the contents.

The board is mailing Kinsman his correct file, MacLean said.

Today the paper is reporting that the newly established Privacy Review Officer is considering an investigation: Privacy watchdog mulls probe of WCB - Front - TheChronicleHerald.ca.

I'm not sure that this error indicates any sort of a systemic problem, but I expect we'll hear more about it in the future.

Tuesday, January 20, 2009

Heartland data breach could be bigger than TJX's

Heartland Payment Systems has announced that it suffered a significant data breach last year after it was discovered that hackers had installed software on their systems to capture credit card information. The firm apparenly processes over 100 Million tranactions a month, leading to speculation that this may dwarf the 2007 TJX breach. See: Heartland data breach could be bigger than TJX's.

Tuesday, June 20, 2006

Europe to continue sharing passenger records with US

According to Computerworld, European authorities have supposedly found a way around European privacy laws to allow the continued sharing of air passenger personal information with American law enforcement:

Europe to continue sharing passenger records with US:

June 19, 2006 (IDG News Service) -- Two weeks after Europe’s highest court overturned a European Union agreement to share passenger data with American authorities, the European Commission has proposed a new law that does much the same as the one that was annulled.

The Commission, the Union’s executive body, agreed Monday to propose a new law that uses different legal grounds to have the same effect: it will allow European airlines to share personal information about their passengers flying to the U.S. with U.S. customs and security officials.

Normally it would be illegal under Europe-wide privacy laws for a company to share European citizens’ personal data with a country with weaker data protection laws such as the U.S. However, after the attacks of Sept.11, 2001, mounted using commercial airline flights, American authorities demanded the information.

Airlines would be fined or worse, denied landing slots by American aviation authorities if they failed to provide the information, which includes details such as name, address and credit card information. But they would be sued in Europe for breaking data protection law if they did provide the Americans with the information.

To avoid havoc in the airline industry and a potential disruption of transatlantic flights, the Commission and the 25 national governments passed a law allowing the handover of most of the information the U.S. demanded....

For a bit o' background, check out: The Canadian Privacy Law Blog: European court blocks passenger data sharing deal with US.

Discussion about data theft and corporate irresponsibility

An unlucky slashdotter has started a discussion thread on data thefts and possible consumer recourse. Unfortunately, some of the advice involves burning buildings to the ground and moving to Nigeria, both of which may not be the most prudent course of action. In any event, check it out:

Slashdot Data Theft and Corporate Irresponsibility?

"Today, I received a letter from a student loan provider notifying me that my name and social security number had been stolen along with a contractor's computer. This makes -four- agencies that have lost my personal information, in the last year. Today's letter was the most disappointing yet: the company, Texas Guaranteed, did not offer any credit report monitoring like the previous three had. Their advice? Send a letter to the credit bureaus. Gee, thanks. Clearly, mass identity theft is completely out of hand and there doesn't seem to be any government regulation for handling these situations, nor does there seem to be any punitive action against businesses that lose customers' data. Do we, as consumers, have any recourse against these businesses?"

Thanks to Rob Hyndman for passing along the link.

Monday, June 19, 2006

Fake Name Generator

Some people who are concerned about their privacy are understandably nervous about giving their names, addresses, and whatnot to random websites just to look at an article, etc. Many use fake info, but websites are catching on by trying verify the info by matching the address to the US ZIP code. If you are one of those people, you may be interested in the Fake Name Generator, which will produce a name, address, date of birth and mother's maiden name. It's all random. Here's what I got:

Joesph T. Villanvera
129 North Street
Grand Rapids, MI 49546

Phone: 231-394-0713
Mother's maiden name: Mogle
Birthday: March 18, 1964

But you can call me Joe.

Win fabulous prizes!

Sorry for the misleading headline, but if you are a student and you wrote a great paper on technology law issues this year (or ever), think about submitting it for the Canadian IT Law Association Student Writing Competition. The deadline is June 30, 2006 so you'd better hurry.

If you aren't a student, you're out of luck. Sorry.

Ontario Commissioner introduces RFID Guidelines

Ontario's Information and Privacy Commissioner has just produced a set of guidelines for implementing RFID technology to better protect privacy in its implementation. The guidelines are here and are being released along with a companion Practical Tips for Implementing RFID Privacy Guidelines. Earlier this month, the Commissioner released Worried about RFIDs? in video and paper form.

The Commissioner's press release is here:

Commissioner Cavoukian issues RFID Guidelines aimed at protecting privacy

TORONTO, June 19 /CNW/ - Ontario's Information and Privacy Commissioner, Dr. Ann Cavoukian, today released privacy Guidelines for the growing field of radio frequency identification (RFID).

These Guidelines flow from her earlier work in 2003 when the Commissioner first identified the potential privacy concerns raised by RFID technology. Following a history of ground-breaking work on building privacy into the design of emerging technologies, these Guidelines are a natural progression of this pragmatic approach.

"I have always found it beneficial to assist those working on emerging technologies, and to be proactive whenever possible - to develop effective guidelines and codes before any problems arise," said Commissioner Cavoukian. "These made-in-Canada Guidelines provide guidance and solutions regarding item-level consumer RFID applications and uses."

EPCglobal Canada, an industry association that sets standards for electronic product codes, has been collaborating with the IPC in the development of these Guidelines, and will be seeking Board approval by its member companies to signify the association's endorsement of the Guidelines.

"This technology offers exciting benefits to consumers and businesses alike. As the trusted source for driving adoption of EPC/RFID technology for increased visibility within the supply chain, privacy is as important as anything else we are doing," said Art Smith, President and CEO, EPCglobal Canada. "We promote an environment that encourages ongoing innovation while respecting privacy issues."

RFID tags contain microchips and tiny radio antennas that can be attached to products. They transmit a unique identifying number to an electronic reader, which in turn links to a computer database where information about the item is stored. RFID tags may be read from a distance quickly and easily, making them valuable for managing inventory but pose potential risks to privacy if linked to personal identifiers. RFID tags are the next generation technology from barcodes.

Although RFID technology deployed in the supply chain management process poses little threat to privacy, item-level use of RFID tags in the retail sector, when linked to personally identifiable information, can facilitate the tracking and surveillance of individuals. The goal of these Guidelines is to alleviate concerns about the potential threat to privacy posed by this technology and to enhance openness and transparency about item-level use of RFID systems by retailers.

The Guidelines address key privacy issues regarding the use of RFID technology at an item-level in the retail sector, said Commissioner Cavoukian.

The Guidelines are based on three overarching principles, including:

  • Focus on RFID information systems, not technologies: The problem does not lie with RFID technologies themselves, but rather, the way in which they are deployed that can have privacy implications. The Guidelines should be applied to RFID information systems as a whole, rather than to any single technology component or function;
  • Build in privacy and security from the outset - at the design stage: Just as privacy concerns must be identified in a broad and systemic manner, so, too, must the technological solutions be addressed systemically. A thorough privacy impact assessment is critical. Users of RFID technologies and information systems should address the privacy and security issues early in the design stages, with a particular emphasis on data minimization. This means that wherever possible, efforts should be made to minimize the identifiability, observability and linkability of RFID data; and
  • Maximize individual participation and consent: Use of RFID information systems should be as open and transparent as possible, and afford individuals with as much opportunity as possible to participate and make informed decisions.

A companion piece to the Guidelines - Practical Tips for Implementing RFID Privacy Guidelines, is also being released by the Commissioner to help organizations put the Guidelines into practice.

The Guidelines and Practical Tips for Implementing RFID Privacy Guidelines are available on the IPC's website (www.ipc.on.ca).

Sunday, June 18, 2006

Incident: Laptop with D.C. workers' data stolen

There goes another one: Laptop with D.C. workers' data stolen - Yahoo! News.

Too many data breaches

It is increasingly difficult to stay on top of all the security/privacy breaches as of late. Thanks to the Privacy Rights Clearinghouse, all the latest are set out in a handy table at http://www.privacyrights.org/ar/chrondatabreaches.htm and includes these recent additions:

Ohio University

Innovation Center

(Athens, OH)

a server containing data including e-mails, patent and intellectual property files, and 35 Social Security numbers associated with parking passes was compromised.

A breach was discovered on a computer that housed IRS 1099 forms for vendors and independent contractors for calendar years 2004 and 2005.

A breach of a computer that hosted a variety of Web-based forms, including some that processed on-line business transactions. Although this computer was not set up to store personal information, investigators did discover files that contained fragments of personal information, including Social Security numbers. The data is fragmentary and it is not certain if the compromised information can be traced to individuals. Also found on the computer were 12 credit card numbers that were used for event registration.

330,000 [Updated 6/16/06]

June 11, 2006

Denver Election Commission (Denver, CO)

Records containing personal information on more than 150,000 voters are missing at city election offices. The microfilmed voter registration files from 1989 to 1998 were in a 500-pound cabinet that disappeared when the commission moved to new offices in February. The files contain voters' Social Security numbers, addresses and other personal information.

June 13, 2006

Minn. State Auditor (St. Paul, MN)

Three laptops possibly containing Social Security numbers and other personal information on some employees of local governments the auditor oversees have gone missing.

Oregon Dept. of Revenue (Portland, OR)

Electronic files containing personal data of Oregon taxpayers may have been compromised by an ex-employee's downloaded a contaminated file from a porn site. The "trojan" attached to the file may have sent taxpayer information back to the source when the computer was turned on.

U.S. Dept of Energy, Hanford Nucear Reservation

Current and former workers at the Hanford Nuclear Reservation that their personal information may have been compromised, after police found a 1996 list with workers' names and other information in a home during an unrelated investigation.

Encrypt it

ABC News could be accused of stating the obvious in Encryption Can Save Data in Laptop Lapses, but the article does have some interesting info on specific lessons that the VA, EDS and Ernst & Young have recently learned the hard way.