Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Health P.E.I. Data Breach May Expose Personal Information of 234,000 People

Health P.E.I. Data Breach May Expose Personal Information of 234,000 People

By: Jordan Vector — Cybersecurity Expert

Last updated: September 30, 2026

Human Written
Health P.E.I. Data Breach May Expose Personal Information of 234,000 People
  • Health P.E.I. states that an online security issue may impact a number of people up to 234,000.

  • An unauthorized person obtained a file containing health card and personal information.

  • Health P.E.I. says its internal systems remain protected and considers the misuse risk low.

Health P.E.I. says a cybersecurity incident may have exposed personal information linked to up to 234,000 people. The incident involved a third-party company that provides services to the provincial health authority.

The exposed file dates back to 2011 and contained health card information. Health P.E.I. says its internal systems remain protected and considers the risk of misuse low.

Third-Party Company Targeted in Cybersecurity Incident

Health P.E.I. reported the incident on September 7. The health authority said an unauthorized person obtained a copy of an old file held by its service provider, Maximus Canada. The file could contain information for as many as 234,000 people. However, Health P.E.I. cannot confirm the exact number of individuals involved.

The potentially affected group covers people who had a Prince Edward Island health card in or before 2011. It also includes non-residents who received health services on the Island between 2008 and 2011. The file contained several types of personal information. These included first and last names, dates of birth, gender and P.E.I. personal health numbers.

Some records could also contain dates of death. The file also included Medicare eligibility information. Health P.E.I. has not indicated that the incident exposed detailed medical histories or current clinical records. The authority also says its main internal data systems remain secure.

This incident underscores a bigger cybersecurity problem faced by the healthcare industry. Third-party providers often handle sensitive information, which creates another point that organizations must monitor.

What Information Could have Been Exposed?

The breached document is from 2011 which means that the compromised data is over ten years old. However, some details can still identify individuals today. Names, birth dates and health numbers can connect records to specific people. Medicare eligibility information can also reveal the relationship of a person with the provincial healthcare system.

The interim CEO of Health P.E.I., Laurae Kloschinsky, said the authority considers the overall risk low. She explained that health card information alone generally does not serve as a primary form of identification.

Still, privacy authorities recognize personal health information as highly sensitive. A separate reported case in Guatemala also involved claims of stolen health records, as covered in hacker claims to have stolen sensitive health records from Guatemala.

The Office of the Privacy Commissioner of Canada says organizations should protect such information against unauthorized access, theft and disclosure. The age of the file also raises questions about data retention. Organizations need to protect information for as long as they keep it, even when the records no longer support daily operations.

Therefore, older files still require proper access controls and security measures. Organizations must also review how third-party providers store and handle personal information. Health P.E.I. says it continues to work with its service provider to ensure stronger security practices.

Health P.E.I. Notes Internal Systems Remain Protected

Health P.E.I. says the incident did not compromise its own internal data systems. The authority stores most of its information inside systems with additional security layers. The health authority also says the risk of another breach remains low. However, officials continue working with the affected partner to review security practices.

Meanwhile, the privacy commissioner of the province has become involved in the investigation. Health P.E.I. also wants potentially affected people to understand what happened. The authority has opened a privacy office contact line for people who have questions.

The Office of the Privacy Commissioner of Canada advises people affected by privacy breaches to read notifications carefully. It also recommends monitoring accounts and remaining alert for possible fraud attempts. 

That advice can matter even when an organization considers the risk low. Criminals can sometimes combine older information with data from other breaches. Health P.E.I. has not reported evidence of such misuse from this incident.

The case also shows why organizations must manage vendor security carefully. Privacy commissioners across Canada have urged healthcare institutions to use strong technical, administrative and physical safeguards.

Health P.E.I. Investigates the Potential Exposure

The investigation will help determine the full scope of the incident. It should also clarify exactly which records the unauthorized person obtained. At this stage, Health P.E.I. expects the affected file could cover about 234,000 individuals. That figure remains an estimate rather than a confirmed count.

This case also involves details of the different timelines. Some of the affected people were holding health cards prior to the mentioned year, while there are others who obtained health services on the Island from 2008 till 2011. Health P.E.I. has prompted people who have queries to reach its privacy office. The concerned authority has also provided a dedicated phone number and email for the concerned.

According to the Office of the Privacy Commissioner of Canada, privacy breaches refer to incidents when a person or group accesses, collects, uses, or discloses personal information without authorization. The focus of Health P.E.I. in the next steps would be on confirming the affected records and increasing protection in relation to third-party services.

Share this article

You might also like

Hacker Claims 8.6 Million French Patient Records Linked to Alaxione

Hacker Claims 8.6 Million French Patient Records Linked to Alaxione

A seller says a second file tied to French health tech firm Alaxione holds about 8.6 million patient records. The…

September 28, 2026
Mexico Probes Telegram Sale of 12.9 Million Records Linked to Call Centers

Mexico Investigates Sale of 12.9 Million Personal Records on Telegram

Mexico’s government says a Telegram seller offered more than 12.9 million records tied to various call centers. A government sample…

September 28, 2026
Hackers Exploit Critical Citrix NetScaler Flaws in Active Attacks

Hackers Exploit Critical Citrix NetScaler Flaws in Active Cyberattacks

Citrix says attackers are already using two critical flaws in its NetScaler ADC and NetScaler Gateway products. One flaw affects…

September 28, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.