-
Health P.E.I. states that an online security issue may impact a number of people up to 234,000.
-
An unauthorized person obtained a file containing health card and personal information.
-
Health P.E.I. says its internal systems remain protected and considers the misuse risk low.
Health P.E.I. says a cybersecurity incident may have exposed personal information linked to up to 234,000 people. The incident involved a third-party company that provides services to the provincial health authority.
The exposed file dates back to 2011 and contained health card information. Health P.E.I. says its internal systems remain protected and considers the risk of misuse low.
Third-Party Company Targeted in Cybersecurity Incident
Health P.E.I. reported the incident on September 7. The health authority said an unauthorized person obtained a copy of an old file held by its service provider, Maximus Canada. The file could contain information for as many as 234,000 people. However, Health P.E.I. cannot confirm the exact number of individuals involved.
The potentially affected group covers people who had a Prince Edward Island health card in or before 2011. It also includes non-residents who received health services on the Island between 2008 and 2011. The file contained several types of personal information. These included first and last names, dates of birth, gender and P.E.I. personal health numbers.
Some records could also contain dates of death. The file also included Medicare eligibility information. Health P.E.I. has not indicated that the incident exposed detailed medical histories or current clinical records. The authority also says its main internal data systems remain secure.
This incident underscores a bigger cybersecurity problem faced by the healthcare industry. Third-party providers often handle sensitive information, which creates another point that organizations must monitor.
What Information Could have Been Exposed?
The breached document is from 2011 which means that the compromised data is over ten years old. However, some details can still identify individuals today. Names, birth dates and health numbers can connect records to specific people. Medicare eligibility information can also reveal the relationship of a person with the provincial healthcare system.
The interim CEO of Health P.E.I., Laurae Kloschinsky, said the authority considers the overall risk low. She explained that health card information alone generally does not serve as a primary form of identification.
Still, privacy authorities recognize personal health information as highly sensitive. A separate reported case in Guatemala also involved claims of stolen health records, as covered in hacker claims to have stolen sensitive health records from Guatemala.
The Office of the Privacy Commissioner of Canada says organizations should protect such information against unauthorized access, theft and disclosure. The age of the file also raises questions about data retention. Organizations need to protect information for as long as they keep it, even when the records no longer support daily operations.
Therefore, older files still require proper access controls and security measures. Organizations must also review how third-party providers store and handle personal information. Health P.E.I. says it continues to work with its service provider to ensure stronger security practices.
Health P.E.I. Notes Internal Systems Remain Protected
Health P.E.I. says the incident did not compromise its own internal data systems. The authority stores most of its information inside systems with additional security layers. The health authority also says the risk of another breach remains low. However, officials continue working with the affected partner to review security practices.
Meanwhile, the privacy commissioner of the province has become involved in the investigation. Health P.E.I. also wants potentially affected people to understand what happened. The authority has opened a privacy office contact line for people who have questions.
The Office of the Privacy Commissioner of Canada advises people affected by privacy breaches to read notifications carefully. It also recommends monitoring accounts and remaining alert for possible fraud attempts.
That advice can matter even when an organization considers the risk low. Criminals can sometimes combine older information with data from other breaches. Health P.E.I. has not reported evidence of such misuse from this incident.
The case also shows why organizations must manage vendor security carefully. Privacy commissioners across Canada have urged healthcare institutions to use strong technical, administrative and physical safeguards.
Health P.E.I. Investigates the Potential Exposure
The investigation will help determine the full scope of the incident. It should also clarify exactly which records the unauthorized person obtained. At this stage, Health P.E.I. expects the affected file could cover about 234,000 individuals. That figure remains an estimate rather than a confirmed count.
This case also involves details of the different timelines. Some of the affected people were holding health cards prior to the mentioned year, while there are others who obtained health services on the Island from 2008 till 2011. Health P.E.I. has prompted people who have queries to reach its privacy office. The concerned authority has also provided a dedicated phone number and email for the concerned.
According to the Office of the Privacy Commissioner of Canada, privacy breaches refer to incidents when a person or group accesses, collects, uses, or discloses personal information without authorization. The focus of Health P.E.I. in the next steps would be on confirming the affected records and increasing protection in relation to third-party services.