Calgary Herald

Ex-employee snooped on health records of 1,418 patients: report

Privacy commission­er outlines breach of Alberta Health Services data

- JANET FRENCH jfrench@postmedia.com

EDMONTON Alberta may need new ways of preventing informatio­n in electronic health records from falling into the wrong hands, the province’s privacy commission­er says in a new report.

On Wednesday, the Office of the Informatio­n and Privacy Commission­er released a report concluding Alberta Health Services (AHS) failed to ensure privacy training and proper oversight of a former typist and medical secretary at a psychiatri­c hospital who improperly looked at the medical records of 1,418 patients over 12 years.

“The findings from this investigat­ion suggest it is well past time to consider whether the current approach to safeguardi­ng health informatio­n made available through Netcare, as implemente­d by AHS in co-operation with Alberta Health, is adequate,” informatio­n and privacy commission­er Jill Clayton wrote in a preamble to the report.

Clayton is now considerin­g whether she should instigate a wider review of Alberta Netcare, an electronic medical record system that gives 48,946 health-care workers access to diagnoses, treatment, and medical images for patients’ physical and mental health.

Report author Chris Stinner, a manager of special projects and investigat­ions with the privacy office, also concluded too much time had passed to pursue charges under the Health Informatio­n Act against the former AHS employee.

The two-year limit on laying charges has frustrated other victims of health record snooping.

In August 2015, AHS terminated the Alberta Hospital employee who broke the privacy rules. However, Stinner’s report said her co-workers reported her suspected misuse of the Netcare system four times to AHS managers in the 17 months before she lost her job.

The first three times, managers neglected to check Netcare data logs to see how the worker was using the system, Stinner said.

In its subsequent investigat­ion, AHS found the employee looked at the health records of 1,418 patients unrelated to her work duties, and also viewed lists of 12,861 patients’ data, which included informatio­n such as their birth date, gender and city where they lived.

Stinner’s investigat­ion found the employee had a second job contractin­g with a private business that provided medical billing services for doctor’s offices. There is evidence the employee did her contract work “more than once” while she was supposed to be doing her AHS job, the report said.

After AHS completed its investigat­ion, it notified 12,848 people their health or other informatio­n had been improperly accessed.

The privacy office received complaints from 30 people affected by the breaches.

In a written statement, AHS said it appreciate­d the privacy office’s report, and has since made “significan­t progress” improving the organizati­on’s privacy culture.

As of this month, 88.5 per cent of AHS employees have completed mandatory privacy and Health Informatio­n Act training, it said.

The privacy office’s report also said AHS added extra Netcare data access audits at Alberta Hospital.

Newspapers in English

Newspapers from Canada