Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

British Columbia: OIPC publishes report of findings following investigation into PHSA Health Information System

The Office of the Information and Privacy Commissioner for British Columbia ('OIPC') published, on 15 December 2022, the report of findings, following the investigation that it had launched into the Provincial Health Services Authority ('PHSA') concerning some security and privacy vulnerabilities of the Provincial Public Health Information System ('the System'). In particular, the OIPC found several vulnerabilities in the System, including:

  • a lack of proactive auditing for suspicious activity;
  • no ongoing program for managing application vulnerabilities;
  • no encryption of personal information within the database at rest; and
  • no universal requirement for multi-factor authentication to access the System.

In light of the above, the OIPC recommended the PHSA to take seven actions, including that it:

  • acquires, configures, and deploys a privacy-tailored proactive audit system;
  • ensures a multi-factor authentication solution; and
  • encrypts personal information within the database at rest.

You can read the press release here and the report here.