Showing posts with label intrusion upon seclusion. Show all posts
Showing posts with label intrusion upon seclusion. Show all posts

Wednesday, July 08, 2015

Court of Appeal finds negligence and breach of confidence claims should go forward in privacy class action against the Federal Government

The Federal Court of Appeal in Condon v Canada, 2015 FCA 159 (not yet available on CanLII but here as a Google Drive PDF), has reversed a lower court decision to not certify claims of negligence and breach of confidence in the class action lawsuit that followed the Federal Government's loss of a hard drive containing personal information about 583,000 Canada Student Loan recipients.

The plaintiffs, in Condon v Canada, 2014 FC 250, sought certification under a number of causes of action, including breach of contract, intrusion upon seclusion (invasion of privacy), negligence and breach of confidence. Breach of contract and intrusion upon seclusion do not require damages for an individual to recover, and both of these causes of action were certified. Those that do require damages to succeed, negligence and breach of confidence, were not successful at the certification motion.

The Court of Appeal noted that the proper test for certification is only to review the pleadings and to not inquire into the evidence. Since the plaintiffs had pleaded damages, that should be determinative:

[13] As stated by the Supreme Court, the determination of whether the pleadings disclose a reasonable cause of action is to be based on the assumption that the facts as pleaded are true. This would mean that evidence is not to be submitted at the hearing of the motion. Otherwise, the hearing of the motion could turn into a full hearing on the merits.

[14] In this case, the parties submitted affidavit evidence. In paragraphs 68 and 69 of her reasons the Federal Court Judge noted that:

68 In addition, a summary review of the evidence adduced by both parties leads the Court to the conclusion that the Plaintiffs have not suffered any compensable damages. The Plaintiffs have not been victims of fraud or identity theft, they have spent at most some four hours over the phone seeking status updates from the Minister, they have not availed themselves of any credit monitoring services offered by the credit reporting agencies nor have they availed themselves of the Credit Flag service offered by the Defendant.

69 Nor does the evidence adduced support a claim for increased risk of identity theft in the future. Since the Data Loss, Equifax has produced reports pertaining to the credit files of the 88,548 individuals who availed themselves of the Credit Flag service. These reports show that there had been no increase in the relevant indicia that would be consistent with an increase in criminal activities involving those individuals' Personal Information. The rate of criminal activities registered was not higher than the 3% of the population generally victim of identity theft. Moreover, the Plaintiffs submitted a CBC news article concerning a Class Member who had been a victim of identity theft yet the article noted no proven causal link between the Data Loss and that theft.

[15] It appears that the Federal Court Judge evaluated the evidence in concluding that the Appellants had not suffered any “compensable damages”. The determination of whether the Appellants had a reasonable cause of action in negligence or breach of confidence should have been made based on the facts as pled, not on the evidence adduced in support of the motion.

[22] Reading the Consolidated Statement of Claim with this principle in mind, the Appellants have claimed that they have suffered damages and they have identified the nature of the damages that they are claiming. In particular, the Appellants have claimed special damages for “costs incurred in preventing identity theft” and “out-of-pocket expenses” and, as noted above, it is to be assumed that these costs have been incurred. As a result there was no basis to not include the claims for negligence and breach of confidence as part of the class proceeding.

The Federal Court of Appeal has sent the matter back to the trial level for determination, including the claims for negligence and breach of confidence and to determine the common questions in the class proceeding in relation to those claims.

Friday, November 21, 2014

Newfoundland Supreme Court considers privacy class action, clears first hurdle to certification

The Supreme Court of Newfoundland and Labrador this week considerd the first part of a bifurcated application to certify a class action in Hynes v. Western Regional Integrated Health Authority, 2014 NLTD(G) 137. The cases arose from inappropriate browsing of personal health records by an employe of the defendant health authority. The application was split into two parts and the first focused on whether the pleadings disclosed a cause of action.

The court agreed that the case could proceed on the basis of the following causes of action:

  • breach of privacy based on statutory tort established under the Privacy Act;
  • breach of privacy based on common law tort (“intrusion upon seclusion”);
  • negligence; and
  • breach of contract.

What's remarkable is that Newfoundland already has a statutory tort of invasion of privacy under the Privacy Act. This case stands for the proposition that the existence of the statutory invasion of privacy law does not preclude the existence of the common law "intrusion upon seclusion" tort as described in Jones v Tsige. This is the opposite of the repeated holdings of the courts of British Columbia, where courts have held that the provincial Privacy Act means that the common law tort does not exist there. (See: No common law tort of invasion of privacy in British Columbia, judge finds.)

Friday, November 07, 2014

Ontario Court awards $10K damages for Legal Aid file-peeking

The Ontario Superior Court of Justice has recently released its decision in McIntosh v. Legal Aid Ontario, 2014 ONSC 6136. While the background facts are messy and complicated (and, once again, related to jilted relationships), the one important takeaway is that the Court granted $10,000 in damages to the plaintiff based on the tort of intrusion upon seclusion after the defendant peeked into her Legal Aid file.

The defendant did not appear to defend the claim, so the court was left with assessing damages on a pretty sparse record, but one that was full of unsubstantiated claims of harms.

According to the plaintiff, her ex-boyfriend provided the defendant with the plaintiff’s full name and date of birth. The defendant used that information to access the plaintiff’s file with Legal Aid Ontario. A few days later, the defendant called the plaintiff and said that she had obtained confidential information from the plaintiff’s Legal Aid Ontario case file. The defendant’s review of the file disclosed that the plaintiff was involved with a Children’s Aid file. The defendant threatened to call the Children’s Aid Society in an effort to have the plaintiff’s children taken away from her. The plaintiff filed a complaint with legal aid and with the Information and Privacy Commissioner of Ontario. Following that investigation, Legal Aid Ontario provided a written of apology to the plaintiff. The plaintiff asserted that information was provided by the defendant to Children's Aid, an investigation took place and it was subsequently closed. There was no evidence of any other disclosure of the plaintiff’s private information.

In her claim made against Legal Aid Ontario and the individual defendant, the plaintiff alleged that as a result of such breach of privacy, she has experienced “substantial anxiety, emotion [sic] upset, depression, significant stress, embarrassment, weight loss, insomnia, isolation, and an inability to concentrate at work.”

In the course of the hearing, virtually no evidence was led to substantiate any of the pecuniary or health-related claims. The Court was left with deciding damages solely on the basis of the peeking into the file.

Here's the court's analysis of the calculation of damages in this case:

[29] The plaintiff asserts in her affidavit that the defendant used the private information to contact the Children’s Aid Society in an effort to have the plaintiff’s children taken away from her, but no documentation of any sort was filed in support of this bald allegation. The failure of the plaintiff to specify disclosure of information to the Children’s Aid Society with the original complaints or as part of the investigative process, coupled with the lack of any sort of supporting documentation, leads me to conclude that the plaintiff has failed to satisfy me that there was any disclosure of the plaintiff’s private information.

[30] In view of this finding, I am left with the task of assessing damages based upon the defendant’s improper access to the plaintiff’s private information only.

[31] The information that had been provided by the plaintiff to Legal Aid Ontario was clearly personal information. It was provided with an expectation that the plaintiff’s privacy interests would be respected and that the information would be used in connection with her legal aid application alone.

[32] The tone of the original complaint to Legal Aid Ontario itself is more consistent with irritation rather than devastation.

[33] If the invasion of her privacy did affect her emotional state, the evidence suggests that it did so in a minor fashion only. There is no detailed medical report, only a doctor’s note concerning a consultation for anxiety, something that has already been noted was a pre-existing condition. Having said that, I am satisfied that the evidence supports a finding that the disclosure of personal information caused the plaintiff a measure of annoyance, anxiety and distress.

[34] Although Legal Aid Ontario provided a letter of apology, the defendant has not seen fit to do so.

[35] After taking all of these factors into consideration, I award general damages in the amount of $10,000. In determining this amount, I have taken into consideration the resolution that occurred between the plaintiff and Legal Aid Ontario, who was originally named as a party defendant, but who is no longer involved in the claim


Though damages for intrusion upon seclusion may range from nominal to $20,000 (per Jones v Tsige), but we may see $10,000 become the standard award.

Thanks to Dan Michaluk for bringing this case to my attention. Check out his commentary on this blog at AllAboutInformation.ca.

Friday, February 14, 2014

Ontario provincial health privacy law does not pre-empt invasion of privacy claim in tort

The Ontario Superior Court in Hopkins v. Kay, 2014 ONSC 321 (CanLII) has concluded that the Personal Health Information Protection Act does not pre-empt a claim for "intrusion upon seclusion" against a hospital and its employees for unlawfully perusing personal health records:

[29] While it is argued by counsel for the Hospital that Jones dealt with Federal privacy legislation (“PIPEDA”), it is equally clear to me that Sharpe J.A. conducted a review of other similar legislation and specifically referred in his decision to PHIPA. At paragraphs 47-51, however, and again at paragraphs 52-54, there can be no doubt that Sharpe J.A. was well aware of the provisions of PHIPA and the potential impact of recognizing a common law tort of breach of privacy. In dealing with whether or not the legislation had occupied the field, the comments of Justice Sharpe at paragraph 54 are particularly apropos when he states:
Significantly, however, no provincial legislation provides a precise definition of what constitutes an invasion of privacy. The courts and provinces with a statutory tort are left with more or less the same task as courts and provinces without such statutes. The nature of these acts does not indicate that we are faced with a situation where sensitive policy choices and decisions are best left to the legislature. To the contrary, existing provincial legislation indicates that when the legislatures have acted, they have simply proclaimed a sweeping right to privacy and left it to the courts to define the contours of that right.
[30] I am not satisfied from a review of Jones that it should be, as suggested by counsel for the Hospital, restricted to the facts of that case. Rather, I am of the view that the Court of Appeal in Jones has determined that the common law right to proceed with a claim, based on the tort of breach of privacy, as alleged in the plaintiff’s statement of claim is a claim that should be allowed to proceed. This is not a case that, in my view, is so plain and obvious that the court should strike out the claim. If the position of the Hospital is to be sustained, it will require a decision of the Court of Appeal, which as the British Columbia Court of Appeal has done, determines that there is no claim for breach of privacy and that the claim must rest on the provisions of PHIPA. The defendants’ motion is therefore dismissed with costs.

Thanks to Barry Sookman for pointing this case out ...

Monday, November 25, 2013

Class Action filed against Health Canada in Medical Marijuana privacy breach


Marijuana privacy breach class action blog post

This afternoon, my firm filed a statement of claim in the Federal Court against Health Canada (John Doe v. Her Majesty) in connection with the massive privacy breach associated with the government’s medical marijuana program. As we understand it, Health Canada irresponsibly deviated from their usual practice of plain brown envelopes, couriers and registered mail by sending a mailing to around 40,000 individuals associated with the program clearly announcing the “Medical Marihuana Program” on the return address.

Between Friday and today, I have had many calls from individuals whose privacy was compromised by this breach, most of them fearing for their jobs and all of them concerned about their own safety. If it gets out in your community that you lawfully possess cannabis, this makes you a target for break and enters. The risk is even more heightened if you are a licensed grower of the plant. While this is a lawful program, the use of medical marijuana is heavily stigmatized.

This is not like most large-scale privacy breaches where the harm is mostly theoretical, since the missing hard-drive or thumb-drive likely didn’t leave the building. In this case, sensitive personal information was exposed to people who had no right to see it. I am told that some people have already lost their jobs because of this. For the rest, it is hard to put a price on legitimate concern about your family’s safety. I lived for a number of years in a community of 400 people, where the Canada Post employees were also neighbours.

Health Canada has dismissed this as a simple administrative error that they’ll endeavour to not repeat. But that’s not good enough from our government. People get to choose the businesses they deal with. If you don’t like how your bank or other service provider handles your personal information, you can change banks or businesses. But that’s not the case with your government. It’s a non-consensual relationship and the government owes a special duty of care to its citizens to protect them and to protect their sensitive personal information. Participants in this program were obtaining a restricted drug for medical purposes and could not do so lawfully except through the government program. Citizens should not have to choose between doing it lawfully or doing it safely. And we are talking about sensitive personal health information, which is generally recognized in Canada as the most sensitive personal information.

If you, or anyone you know, has been affected by this breach, please go to http://www.healthprivacyclassaction.com to provide your contact information so we can keep you apprised of this case as it progresses. Please provide an e-mail address that is confidential only to you. If this breach has had a particular impact on you, there is a portion of the form to provide details about this. Any information you provide will be kept confidential.

Here is the media release:

McInnes Cooper law firm files national class action in medical marijuana privacy breach

HALIFAX, Nov. 25, 2013 /CNW/ - McInnes Cooper law firm today filed a proposed class action in Federal Court against the Government of Canada in response to Health Canada's breach of the privacy rights of 40,000 patients in the Marijuana Medical Access Program. Under the Marijuana Medical Access Program, patients are permitted to grow marijuana in their residence for medicinal purposes.  

Earlier this month, Health Canada sent these patients a letter via Canada Post that clearly indicated on the envelope that the named patient participated in the Marijuana Medical Access Program.

Health Canada's disclosure of the patients' private medical information has raised serious employment and security concerns, and caused the patients to suffer considerable stress and anxiety.

"As a result of Health Canada's error, we have already spoken with a number of people whose lives have been affected by this breach," said David Fraser, a national expert on privacy law, and McInnes Cooper's lead lawyer on this case.

"We have heard that some individuals have already lost their jobs as a result, and everyone we've spoken with is concerned about their safety in their homes."

SOURCE: McInnes Cooper

The statement of claim is here:

FEDERAL COURT

 

PROPOSED CLASS ACTION

 

 

BETWEEN:

 

JOHN DOE

 

                                                                                                                            PLAINTIFF

 

- and -

                                                                                                                                                                

                                                                                                                                                                 

HER MAJESTY THE QUEEN

 

                                                                DEFENDANT

 

 

STATEMENT OF CLAIM

 

 

TO THE DEFENDANT:

 

A LEGAL PROCEEDING HAS BEEN COMMENCED AGAINST YOU by the Plaintiff.  The claim made against you is set out in the following pages.

 

                IF YOU WISH TO DEFEND THIS PROCEEDING, you or a solicitor acting for you are required to prepare a statement of defence in Form 171B prescribed by the Federal Courts Rules, serve it on the Plaintiff’s solicitor or, where the Plaintiff does not have a solicitor, serve it on the Plaintiff, and file it, with proof of service, at a local office of this Court, WITHIN 30 DAYS after this Statement of Claim is served on you, if you are served within Canada.

 

                If you are served in the United States of America, the period for serving and filing your Statement of Defence is forty days.  If you are served outside Canada and the United States of America, the period for serving and filing your Statement of Defence is sixty days.

 

                Copies of the Federal Courts Rules, information concerning the local offices of the Court and other necessary information may be obtained on request to the Administrator of this Court at Ottawa (telephone: 613-992-4238) or at any local office.

 

                IF YOU FAIL TO DEFEND THIS PROCEEDING, judgment may be given against you in your absence and without further notice to you.

 

 

Date:  _____________________________________

 

Issued by:  _________________________________

[Registry Officer]

 

Address of local office:  1801 Hollis Street,

                                            17th Floor, Suite 1720

                                            Halifax, N.S.  B3J 1S7

                             

 

To:                   The Attorney General of Canada

Attention:     Mr. Willian F. Pentney, Deputy Attorney General of Canada

 

 

 

Claim

 

1.    The Plaintiff claims on his own behalf and on behalf of the proposed Class:

 

a.    An Order pursuant to Rules 334.16(1) and 334.17 of the Federal Courts Rules certifying this action as a class proceeding;

 

b.    An Order pursuant to Rules 334.12(3), 334.16(1)(e) and 334.17(b) appointing the Plaintiff as the representative plaintiff for the Class;

 

c.    Damages for the torts of intrusion upon seclusion, publicity given to private life, breach of confidence and negligence;

 

d.    An Order pursuant to Rule 334.28(1) and (2) for the aggregate assessment of monetary relief and its distribution to the Plaintiff and the Class;

 

e.    Prejudgment interest pursuant to section 36 of the Federal Courts Act;

 

f.     Costs, if appropriate; and

 

g.    Such further and other relief as this Honourable Court deems just.

 

Parties

 

2.    The Plaintiff is an individual who resides in Nova Scotia. He is employed in the health care field.

 

3.    The Plaintiff brings this action on his own behalf and on behalf of the members of the proposed class, which is defined as follows:

 

All persons who were sent a letter from Health Canada in November 2013 that had the phrase Marihuana Medical Access Program or a similar French phrase visible on the front of the envelope.

 

4.    The Defendant, Her Majesty the Queen, is named as a representative of the Federal Government of Canada and Health Canada. Health Canada administers the Marihuana Medical Access Program under the Marihuana Medical Access Regulations.

 

Medical Marihuana Access Program

 

5.    Through the Marihuana Medical Access Program, the Defendant grants access to marihuana for medical use to Canadians suffering from grave and debilitating illnesses.

 

6.    Marihuana (cannabis) is categorized as a controlled substance, regulated in Canada under the Controlled Drugs and Substances Act. It is not legal to grow or possess marihuana except with legal permission by the Defendant under the Marihuana Medical Access Program.

 

7.    The Plaintiff applied to participate in the Defendant’s Marihuana Medical Access Program to grow and possess marihuana to alleviate the pain that he suffers due to a medical condition. The Defendant approved the Plaintiff’s application.

 

Disclosure of the Plaintiff’s Private Information

 

8.    The Defendant typically corresponds to the Plaintiff by courier service with plain unmarked brown envelopes.

 

9.    During the week of November 21, 2013, the Defendant sent the Plaintiff a letter plainly and clearly indicating on the envelope that it was from Health Canada and that it was in regards to the Marihuana Medical Access Program.

 

10.  By publically indicating that the Plaintiff was a participant in the Marihuana Medical Access Program, the Defendant disclosed the personal health information about the Plaintiff. Furthermore, the Defendant’s disclosure creates a security concern by alerting other individuals that the Plaintiff may possess and/or grow marihuana at his residence.

 

Negligence

 

11.  At all material times, the Defendant owed a duty of care to the Plaintiff and the proposed Class.

 

12.  Furthermore, the Defendant had a statutory duty under subsection 8(1) of the Privacy Act to not disclose personal information without that individual’s consent. The Plaintiff’s and the Class’ participation in the Marihuana Medical Access Program constitutes personal information as it is confidential information and relates to their medical history.

 

13.  The Defendant breached its duty of care owed to the Plaintiff and the Class by:

 

a.    Failing to meet its statutory duties and/or policies in the collection, retention and disclosure of personal information;

 

b.    Failing to take reasonable steps to ensure the personal information was not disclosed;

 

c.    Failing to communicate with the Plaintiff and the Class in a manner that did not disclose their personal information; and

 

d.    Other such particulars as counsel may advise.

 

Publicity Given to Private Life

 

14.  Through its actions stated above, the Defendant gave publicity to the Plaintiff’s private, personal information, particularly his medical condition.

 

15.  The Plaintiff’s private personal information is of no legitimate concern to the public. The Defendant’s disclosure of the Plaintiff’s private personal information is highly offensive to a reasonable person.

 

Breach of Confidence

 

16.  The Plaintiff states that the Defendant committed the tort of breach of confidence.

 

17.  In applying to participate in the Marihuana Medical Access Program, the Plaintiff conveyed confidential information in confidence to the Defendant.

 

18.  In its actions stated above, the Defendant misused the Plaintiff’s confidential information to the Plaintiff’ detriment.

 

Intrusion upon Seclusion

 

19.  The Defendant’s above stated actions constitute an intrusion on seclusion in a manner that would be highly offensive to a reasonable person.

 

Relief Sought

 

20.  The Defendant’s actions have caused the Plaintiff and the Class to suffer the following damages:

 

a.    Costs incurred in taking additional security precautions;

b.    Damage to reputation;

c.    Damage to employment;

d.    Mental distress;

e.    General damages; and

f.     Inconvenience, frustration and anxiety.

 

General

 

21.  The Plaintiff proposes that this trial take place in Halifax.

 

DATED at Halifax, in the Province of Nova Scotia, this 25th day of November 2013.

 

 

PLACE OF TRIAL:                    HALIFAX, NOVA SCOTIA

 

 

                                                                ____________________________________

                                                                            David T.S. Fraser

Solicitor for the Plaintiff

 

Wednesday, July 24, 2013

No common law tort of invasion of privacy in British Columbia, judge finds

This probably shouldn't be too surprising for lawyers practicing in this area, but a judge of the British Columbia Supreme Court has stated that there is no common law tort of invasion of privacy in the province. In Demcak v. Vo, 2013 BCSC 899, the plaintiffs were suing the City of Richmond (among others) related to an inspection of the property carried out under provincial law and municipal authority:

[10] The City has a statutory authorization to enter and inspect property including residences and uses of property within the City boundaries. That statutory authorization is provided for in s. 16 of the Community Charter, S.B.C. 2003, c. 26. The City may also attend pursuant to relevant enacted bylaws. The consent of the occupants is not required where valid written notice of the inspection is given. This occurred in the case at bar.

The inspectors entered the premises and took photos. The plaintiff claimed for trespass and some sort of "invasion of privacy". The plaintiff, notably, did not make any claims under the British Columbia Privacy Act, which creates a statutory right of action for invasion of privacy. The Court found that there was no common law tort of invasion of privacy and struck the claim from the plaintiff's pleadings.

[8] The issue which arises from these allegations is whether there is a tort for breach of privacy in British Columbia. No common law tort of invasion or breach of privacy exists in British Columbia: Hung v. Gardiner, 2002 BCSC 1234 (CanLII), 2002 BCSC 1234 at para. 110 aff’d 2003 BCCA 257 (CanLII), 2003 BCCA 257 and Bracken v. Vancouver Police Board, 2006 BCSC 189 (CanLII), 2006 BCSC 189 at para. 28. The plaintiffs are not represented by counsel, and notwithstanding they appear to have received legal advice, the claim as filed is ill founded.

[9] A breach of privacy is actionable under statue in British Columbia pursuant to the Privacy Act, R.S.B.C. 1996, c. 373 (“Privacy Act”). The plaintiffs made no pleadings regarding the Privacy Act. The pertinent sections to the case at bar are:

Violation of privacy actionable

1 (1) It is a tort, actionable without proof of damage, for a person, wilfully and without a claim of right, to violate the privacy of another.

(2) The nature and degree of privacy to which a person is entitled in a situation or in relation to a matter is that which is reasonable in the circumstances, giving due regard to the lawful interests of others.

(3) In determining whether the act or conduct of a person is a violation of another's privacy, regard must be given to the nature, incidence and occasion of the act or conduct and to any domestic or other relationship between the parties.

(4) Without limiting subsections (1) to (3), privacy may be violated by eavesdropping or surveillance, whether or not accomplished by trespass.

Exceptions

2 (1) In this section:

"court" includes a person authorized by law to administer an oath for taking evidence when acting for the purpose for which the person is authorized to take evidence;

"crime" includes an offence against a law of British Columbia.

(2) An act or conduct is not a violation of privacy if any of the following applies:

(a) it is consented to by some person entitled to consent;

(b) the act or conduct was incidental to the exercise of a lawful right of defence of person or property;

(c) the act or conduct was authorized or required under a law in force in British Columbia, by a court or by any process of a court;

(d) the act or conduct was that of

(i) a peace officer acting in the course of his or her duty to prevent, discover or investigate crime or to discover or apprehend the perpetrators of a crime, or

(ii) a public officer engaged in an investigation in the course of his or her duty under a law in force in British Columbia,

and was neither disproportionate to the gravity of the crime or matter subject to investigation nor committed in the course of a trespass.

...

[10] The City has a statutory authorization to enter and inspect property including residences and uses of property within the City boundaries. That statutory authorization is provided for in s. 16 of the Community Charter, S.B.C. 2003, c. 26. The City may also attend pursuant to relevant enacted bylaws. The consent of the occupants is not required where valid written notice of the inspection is given. This occurred in the case at bar.

[11] The owner of a rented residential property or landlord has the right to inspect that property as provided in s. 29(1) of the Residential Tenancy Act, S.B.C. 2002, c. 78. Again, clear written notice of the inspection was given to the plaintiffs more than 24 hours before the inspection according to the filed documents.

[12] On the facts of the case now before me, the inspections of the property, including the residences or vehicles thereon, were authorized by law. These inspections are outside the scope of the tort created by s. 1 of the Privacy Act. As there is no common law tort of privacy in BC, the claims contained in para. 13 of the present notice of civil claim are without legal foundation and cannot hope to succeed. The claims in that paragraph are dismissed.

It is worth noting that the Court didn't go into any detailed analysis of the issue, but it is clear to me that what was complained-of did not fit within the tort set out in the Privacy Act, nor would it be actionable as an intrusion upon seclusion under the Jones v Tsige tort.

Wednesday, January 18, 2012

Ontario recognizes tort of invasion of privacy

A unanimous panel of the Ontario Court of Appeal has just released its decision in Jones v Tsige, 2012 ONCA 32. The court has recognized that there is a tort of invasion of privacy in Ontario. The decision can be found here: Jones v. Tsige, 2012 ONCA 32, but here is the gist of the tort:

2. Defining the tort of intrusion upon seclusion

a) Introduction

[65] In my view, it is appropriate for this court to confirm the existence of a right of action for intrusion upon seclusion. Recognition of such a cause of action would amount to an incremental step that is consistent with the role of this court to develop the common law in a manner consistent with the changing needs of society.

b) Rationale

[66] The case law, while certainly far from conclusive, supports the existence of such a cause of action. Privacy has long been recognized as an important underlying and animating value of various traditional causes of action to protect personal and territorial privacy. Charter jurisprudence recognizes privacy as a fundamental value in our law and specifically identifies, as worthy of protection, a right to informational privacy that is distinct from personal and territorial privacy. The right to informational privacy closely tracks the same interest that would be protected by a cause of action for intrusion upon seclusion. Many legal scholars and writers who have considered the issue support recognition of a right of action for breach of privacy: see e.g. P. Winfield, “Privacy” (1931), 47 L.Q.R. 23; D. Gibson, “Common Law Protection of Privacy: What to do Until the Legislators Arrive” in Lewis Klar (ed.), Studies in Canadian Tort Law (Toronto: Butterworths, 1977) 343; Robyn M. Ryan Bell, “Tort of Invasion of Privacy – Has its Time Finally Come?” in Todd Archibald & Michael Cochrane, Annual Review of Civil Litigation (Toronto: Thomson Carswell, 2005) 225; Peter Burns, “The Law and Privacy: the Canadian Experience” (1976), 54 Can. Bar Rev. 1; John D.R. Craig, “Invasion of Privacy and Charter Values: The Common Law Tort Awakens” (1997), 52 McGill L.J. 355.

[67] For over one hundred years, technological change has motivated the legal protection of the individual’s right to privacy. In modern times, the pace of technological change has accelerated exponentially. Legal scholars such as Peter Burns have written of “the pressing need to preserve ‘privacy’ which is being threatened by science and technology to the point of surrender”: “The Law and Privacy: the Canadian Experience” at p. 1. See also Alan Westin, Privacy and Freedom (New York: Atheneum, 1967). The internet and digital technology have brought an enormous change in the way we communicate and in our capacity to capture, store and retrieve information. As the facts of this case indicate, routinely kept electronic data bases render our most personal financial information vulnerable. Sensitive information as to our health is similarly available, as are records of the books we have borrowed or bought, the movies we have rented or downloaded, where we have shopped, where we have travelled, and the nature of our communications by cell phone, e-mail or text message.

[68] It is within the capacity of the common law to evolve to respond to the problem posed by the routine collection and aggregation of highly personal information that is readily accessible in electronic form. Technological change poses a novel threat to a right of privacy that has been protected for hundreds of years by the common law under various guises and that, since 1982 and the Charter, has been recognized as a right that is integral to our social and political order.

[69] Finally, and most importantly, we are presented in this case with facts that cry out for a remedy. While Tsige is apologetic and contrite, her actions were deliberate, prolonged and shocking. Any person in Jones’ position would be profoundly disturbed by the significant intrusion into her highly personal information. The discipline administered by Tsige’s employer was governed by the principles of employment law and the interests of the employer and did not respond directly to the wrong that had been done to Jones. In my view, the law of this province would be sadly deficient if we were required to send Jones away without a legal remedy.

c) Elements

[70] I would essentially adopt as the elements of the action for intrusion upon seclusion the Restatement (Second) of Torts (2010) formulation which, for the sake of convenience, I repeat here:

One who intentionally intrudes, physically or otherwise, upon the seclusion of another or his private affairs or concerns, is subject to liability to the other for invasion of his privacy, if the invasion would be highly offensive to a reasonable person.

[71] The key features of this cause of action are, first, that the defendant’s conduct must be intentional, within which I would include reckless; second that the defendant must have invaded, without lawful justification, the plaintiff’s private affairs or concerns; and third, that a reasonable person would regard the invasion as highly offensive causing distress, humiliation or anguish. However, proof of harm to a recognized economic interest is not an element of the cause of action. I return below to the question of damages, but state here that I believe it important to emphasize that given the intangible nature of the interest protected, damages for intrusion upon seclusion will ordinarily be measured by a modest conventional sum.

d) Limitations

[72] These elements make it clear that recognizing this cause of action will not open the floodgates. A claim for intrusion upon seclusion will arise only for deliberate and significant invasions of personal privacy. Claims from individuals who are sensitive or unusually concerned about their privacy are excluded: it is only intrusions into matters such as one’s financial or health records, sexual practices and orientation, employment, diary or private correspondence that, viewed objectively on the reasonable person standard, can be described as highly offensive.

[73] Finally, claims for the protection of privacy may give rise to competing claims. Foremost are claims for the protection of freedom of expression and freedom of the press. As we are not confronted with such a competing claim here, I need not consider the issue in detail. Suffice it to say, no right to privacy can be absolute and many claims for the protection of privacy will have to be reconciled with, and even yield to, such competing claims. A useful analogy may be found in the Supreme Court of Canada’s elaboration of the common law of defamation in Grant v. Torstar where the court held, at para. 65, that “[w]hen proper weight is given to the constitutional value of free expression on matters of public interest, the balance tips in favour of broadening the defences available to those who communicate facts it is in the public’s interest to know.”

Wednesday, September 02, 2009

IPC issues advice on the "circle of care" under PHIPA

The Information and Privacy Commissioner of Ontario has released written guidance on the "circle of care" under that province's Personal Health Information Protection Act, entitled Circle of Care: Sharing Personal Health Information for Health-Care Purposes.

Here's the news release:

Privacy Commissioner Cavoukian and seven health organizations team up to eliminate confusion over key element of health privacy law

TORONTO, Sept. 2 /CNW/ - Ontario's Information and Privacy Commissioner, Dr. Ann Cavoukian, today released a new publication that includes specific practical examples to help clarify any confusion over when health information custodians can assume a patient's implied consent to collect, use or disclose personal health information.

The brochure, Circle of Care: Sharing Personal Health Information for Health-Care Purposes, was developed with the collaboration of seven health organizations. "This brochure cuts through the confusion surrounding the term circle of care," said the Commissioner. "We are using seven relevant examples from across the broader continuum of the health sector to provide such clarification."

"There had been some confusion in the health sector as to the meaning and scope of the circle of care concept," explained Commissioner Cavoukian. "In part, this may have been because the term does not appear in the Personal Health Information Protection Act, 2004. It is, however, commonly used in the health-care community to describe the provisions in the Act that permit health-care providers to assume a patient's implied consent to collect and use personal health information - and to share that information with other health-care providers - in order to provide health care to that patient, unless the patient expressly indicates otherwise."

The Act is based on the premise that privacy can be protected, without needless delays in the health system.

"Overall, the Act is working very well, but clarity needed to be brought to bear on the circle of care concept," said Commissioner Cavoukian.

The seven examples in the brochure address this. As a fictional 61-year-old patient is followed through much of the health-care system, the examples provide specific guidance relating to when a health provider can assume implied consent.

The seven health organizations that worked with the IPC include (in alphabetical order): the College of Physicians and Surgeons, the Ontario Association of Community Care Access Centres, the Ontario Association of Non-Profit Homes and Services for Seniors, the Ontario Hospital Association, the Ontario Long Term Care Association, the Ontario Medical Association and the Ontario Ministry of Health and Long-Term Care.

Here is a condensed version of one of the examples used in the brochure:

A patient is sent by his family doctor to a laboratory for blood and urine testing. A geriatrician, a specialist whom the patient has been referred to by his family doctor, would like to obtain the results of those tests. He would also like to obtain a list of the patient's current prescriptions from the pharmacy where he fills all his prescriptions.

Can the laboratory and pharmacy disclose this personal health information and can the geriatrician collect information based on assumed implied consent?

Yes. The laboratory, pharmacy and geriatrician may assume implied consent. The personal health information was received by the laboratory and pharmacy - and will be received by the geriatrician - for the purpose of providing health care to this patient.

"Personal health information may be shared within the circle of care - among health-care providers who are providing health care to a specific patient - but not outside that circle," stressed Commissioner Cavoukian. "Any sharing of personal health information with other health-care providers for purposes other than the provision of health care - or the sharing of personal health information with persons or organizations that are not health-care providers, such as insurers and employers - requires the express consent of the patient."

To see a copy of the brochure, visit http://www.ipc.on.ca/.

Thursday, April 17, 2008

Incident: Ontario patient files found in dumpster

The Ontario Information and Privacy Commissioner is investigating after old medical records were found in a dumpster behind a coffee shop by a retiree. The affected patients will have to be notified as the information is subject to PHIPA, which contains Canada's only mandatory breach notification. See: TheSpec.com - Local - St. Joe's patient files found in dumpster.

Monday, March 31, 2008

Ontario's Commissioner recommends PHIPA to Americans

Last week's New York Times had an editorial on Safeguarding Private Medical Data:

... These are good steps, but a larger solution is needed. There should be a federal law imposing strict privacy safeguards on all government and private entities handling medical data. Congress should pass a bill like the Trust Act, introduced by Representative Edward Markey, a Democrat of Massachusetts, imposing mandatory encryption requirements and deadlines for notifying patients when their privacy is breached. As the N.I.H. has shown, medical privacy is too important to be left up to the medical profession.

In today's edition, Ontario's Information and Privacy Commissioner responds:

Ontario’s Example on Privacy - New York Times

To the Editor:

Re: Editorial: Safeguarding Private Medical Data (March 26, 2008)

I couldn’t agree with you more. In Ontario, we take privacy very seriously, especially when it comes to medical data.

Four years ago, we passed the Personal Health Information Protection Act, or Phipa, and haven’t looked back. This law provides solid privacy protection for health data but doesn’t act as a barrier to the delivery of health services. It doesn’t interfere with health care but ensures that it comes wrapped in a layer of privacy.

As privacy commissioner of Ontario, I can investigate complaints and issue orders if Phipa is breached. One order I issued requires that any identifiable health data must be encrypted if removed from a health care facility on a laptop or any other medium.

Medical privacy is far too important to be left to chance, or to the well intentioned. Strong legislated safeguards are needed.

Take a look at Phipa, which could serve as an excellent model.

Ann Cavoukian

Toronto, March 27, 2008

Tuesday, November 14, 2006

Electronic health information and privacy

I spent yesterday in Ottawa at the Electronic Health Information and Privacy Conference. The speakers were very good and the topics covered a very wide range of sub-topics, including privacy enhancing technology, data masking, and research use of personal health information.

IT Business has some coverage of the conference here. What I found to be one of the most telling observations was made by Dr. Geiger of the Ottawa Hospital:

As Dr. Glen Geiger, the Ottawa Hospital’s medical director of clinical information systems told the conference, even hospital employees don’t want their personal health information loaded onto the electronic patient record. They flag their records to have them registered in special outpatient accounts so the results do not populate the electronic record, Geiger said.

“Treating personal health information for staff differently from that of everyone else creates two classes of citizens,” Geiger said. “That’s wrong. If our staff don’t trust us to keep their information private, why should anyone else?”

I continue to be puzzled about the assumption that PIPEDA allows "implied consent" within a mythical "circle of care". This assumption is expressed in a number of areas, but the prime example is in the PIPEDA Awareness Raising Tools (PARTs) Initiative for the Health Sector.

This may appear eminently reasonable, but I don't think it's a foregone conclusion that a judge would agree. The relevant provision in PIPEDA says that the form of the consent has to be based on the sensitivity of the information. If health information is among the most sensitive (not much debate on this topic), it follows that it requires robust consent. Implied consent doesn't really cut it. I've written about this before if you want to read about it in greater depth (see Focus on Privacy: The Application of PIPEDA to Personal Health Information).

40. Can consent be implied for the use and disclosure of personal health information under PIPEDA?

Yes, once patients are made aware of their privacy rights (see answer #38), consent is implied if the patient continues to seek care and treatment. Thus current practice of implied consent for the primary use of personal information in the direct care and treatment of an individual patient, as defined in a circle of care, will continue under PIPEDA. For example, a lab may infer consent because the individual would reasonably expect that the results be sent to the provider who ordered the lab work.

41. Is consent implied for the disclosure of personal health information to private insurance companies or third party payers for the purposes of reimbursement of health services rendered?

In certain circumstances, yes. In circumstances where the current practice is to obtain written consent by making the patient sign a reimbursement form, the practice should continue. Where no form is signed, implied consent is acceptable provided patients understand that this is happening and have not behaved in a way that may indicate a refusal of consent (see answer #38).

42. When does PIPEDA require express consent?

In commercial activities, the patient's oral or written consent is generally required for all uses and disclosures that are not directly related to the care and treatment of a patient.

This position is also adopted in the Pan-Canadian Health Information Privacy and Confidentiality Framework. Implied consent within the circle of care may be the rule in Ontario's PHIPA, but assuming it is also the rule in PIPEDA is more than a little bit risky.

Tuesday, August 01, 2006

Ontario Commissioner issues second order under PHIPA

The Information and Privacy Commissioner of Ontario has issued her second order under the province's new Personal Health Information Protection Act.

The complaint concerns a pretty deplorable situation that took place at the Ottawa Hospital. The complainant was admitted to the hospital and advised that shd did not want her estranged husband and his girlfriend (both were employees of the hospital) to know of her admission or of her situation. Subsequent discussion with her husband demonstrated that he knew about her admission and the patient complained.

An investigation revealed that the girlfriend had accessed the complainant's electronic health record a number of times and disclosed it to the estranged husband. The Commissioner was less than impressed, as demonstrated by the postscript to the executive summary:

POSTSCRIPT

This was a truly regrettable situation in which a patient who was admitted to a hospital, made a specific request to prohibit her estranged husband and his girlfriend, a nurse at the hospital, from having any information regarding her hospitalization, only to learn that the exact opposite had occurred.

Despite having alerted the hospital to the possibility of harm, the harm nonetheless occurred. While the hospital had policies in place to safeguard health information, they were not followed completely, nor were they sufficient to prevent a breach of this nature from occurring. In addition, the fact that the nurse chose to disregard not only the hospital’s policies but her ethical obligations as a registered nurse, and continued to surreptitiously access a patient’s electronic health record, disregarding three warnings alerting her to the seriousness of her unauthorized access, is especially troubling. Protections against such blatant disregard for a patient’s privacy by an employee of a hospital must be built into the policies and practices of a health institution.

This speaks broadly to the culture of privacy that must be created in healthcare institutions across the province. Unless policies are inter-woven into the fabric of a hospital’s day-today operations, they will not work. Hospitals must ensure that they not only educate their staff about the Act and information policies and practices implemented by the hospital, but must also ensure that privacy becomes embedded into their institutional culture.

As one of the largest academic health sciences centres in Canada, the Ottawa Hospital had properly developed a number of policies and procedures; but yet, they were insufficient to prevent members of its staff from deliberately undermining them.

See Health Order HO-002 released July 31, 2006. (Executive Summary)

Wednesday, December 14, 2005

PHIPA declared substantially similar

Thanks to a regular correspondent for pointing this out ...

The Personal Health Information Protection Act of Ontario has been declared to be substantially similar to PIPEDA:

Canada Gazette:

Health Information Custodians in the Province of Ontario Exemption Order

P.C. 2005-2224 November 28, 2005

Whereas the Governor in Council is satisfied that the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, of the Province of Ontario, which is substantially similar to Part 1 of the Personal Information Protection and Electronic Documents Act (see footnote a), applies to the health information custodians referred to in the annexed Order;

Therefore, Her Excellency the Governor General in Council, on the recommendation of the Minister of Industry, pursuant to paragraph 26(2)(b) of the Personal Information Protection and Electronic Documents Act (see footnote b), hereby makes the annexed Health Information Custodians in the Province of Ontario Exemption Order.

HEALTH INFORMATION CUSTODIANS IN THE PROVINCE OF ONTARIO EXEMPTION ORDER

EXEMPTION

1. Any health information custodian to which the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, applies is exempt from the application of Part 1 of the Personal Information Protection and Electronic Documents Act in respect of the collection, use and disclosure of personal information that occurs within the Province of Ontario.

COMING INTO FORCE

2. This Order comes into force on the day on which it is registered.

Monday, October 31, 2005

Ontario's Commissioner faults paper disposal company and clinic for breach of privacy in medical records

Full marks to the Information and Privacy Commissioner for the fast investigation and report related to sensitive medical records being used as props on a Toronto movie set (see: The Canadian Privacy Law Blog: Incident: Medical records blowing in the wind in Toronto). She has issued the first order under the Personal Health Information Protection Act.

From the Commisioner's website:

IPC - Medical records found scattered across Toronto streets: Commissioner Cavoukian issues first Order under new law

NEWS RELEASE : October 31, 2005

TORONTO – An investigation into how personal health records ended up being strewn across the streets of downtown Toronto on October 1 as a backdrop for a film production has resulted in a ruling by Information and Privacy Commissioner Ann Cavoukian that both a Toronto X-ray/ultrasound clinic and a paper disposal company had breached Ontario’s Personal Health Information Protection Act (PHIPA).

The Commissioner, who was appalled at learning of this breach, went to the scene herself shortly after being advised of the records being scattered on the streets. “The Order I released today – the first under the new Act – should be carefully reviewed by every health information custodian and paper disposal company in Ontario. Everyone handling personal health records has to realize that the storage and destruction of such sensitive information has to be carried out in the most secure manner so that mistakes such as this are virtually eliminated.”

In her Order, Commissioner Cavoukian said that the personal health records were collected by a paper disposal company that engaged in both shredding and recycling activities. A portion of the personal health records picked up from the clinic were mistakenly believed to be intended for recycling. The records were subcontracted to another recycling company, which later sold them – intact – to the film company for use on its set.

The Commissioner found that:

  • the Toronto clinic failed to take all reasonable steps to secure the personal health information in its custody or control;
  • the clinic failed to ensure that the personal health information was disposed of in a secure manner; and
  • the clinic failed to comply with section 17(1) of PHIPA, which requires it to be responsible for the proper handling of personal health information by itself and its agents. Commissioner Cavoukian said that, in the above context, a written contractual agreement would be required setting out the agent’s duty to securely shred the materials and require the agent to provide a written attestation confirming that shredding has been completed.

The Commissioner also found that:

  • the paper disposal company’s action in forwarding the records to a recycling facility instead of shredding them, while caused by a mistaken belief that the records were intended for recycling, contravened the Act.

Commissioner Cavoukian ordered the clinic to review its information practices to ensure that the location of all personal health information within its custody or control is documented, and that this personal health information is adequately secured.

The Commissioner ordered the clinic to put into place a written contractual agreement with any agent it retains to dispose of personal health information. The agreement must set out the obligation for secure disposal and requires the agent to provide written confirmation once secure disposal has been carried out.

“Secure disposal,” the Commissioner said in her Order, “must consist of permanently destroying paper records by irreversible shredding or pulverizing, thus making them unreadable. Further, steps must be taken to ensure that no unauthorized person will have access to the personal health information between the time the records leave the health information custodian’s custody until their actual destruction.”

Similarly, the paper disposal company, which fell under PHIPA because it functioned as an agent, having been given personal health information directly by a health information custodian, was ordered by the Commissioner to put into place a written agreement that includes the requirement for the disposal company to engage in secure shredding and provide an attestation confirming destruction of records.

Among other requirements, the Commissioner also ordered the paper disposal company to put procedures into place that will prevent paper designated for shredding from being mixed together with paper that is intended to be disposed of via recycling.

This Order will establish the practice to be followed by all health information custodians and their agents in Ontario, with respect to the Commissioner’s expectations for the secure disposal of health information records under Ontario’s new Health Information Privacy law.

The Commissioner’s Order, HO-001 is available on the IPC website.

Some media coverage, as well:

Clinic, paper firm broke privacy rules

October 31, 2005

TORONTO -- Ontario's privacy commissioner has found a clinic and a paper-disposal company broke privacy rules after personal health records were strewn on a downtown movie set.

Ann Cavoukian says the health records were collected by a company that engaged in both shredding and recycling.

The company mistakenly believed that the records picked up from the X-ray and ultrasound clinic were meant to be recycled.

As a result, it subcontracted the paper to another recycling company, which later sold it to a film company for use on its set.

The health records then ended up being strewn across the streets of downtown Toronto on Oct. 1 as a backdrop for a film production.

Cavoukian says she was appalled at the breach of Ontario's Personal Health Information Protection Act.

'Everyone handling personal health records has to realize that the storage and destruction of such sensitive information has to be carried out in the most secure manner so that mistakes such as this are virtually eliminated,'' Cavoukian said.

The Toronto clinic, which she did not identify, failed to take all reasonable steps to secure the information and ensure it was disposed of securely.

The paper-disposal company also breached the act by sending the records for recycling instead of shredding them.

She also ordered both facilities to put measures in place to preclude a recurrence. "