Skip to Content

Workplace Snooping Scandal Highlights Growing Privacy Risks for Employers

Published for Norfolk Shredding – Secure Document Destruction & Privacy Compliance


What Canadian Organizations Must Learn About Employee Access to Sensitive Data

A recent workplace privacy scandal in British Columbia is raising urgent questions about how organizations manage access to sensitive personal information. The case, involving healthcare workers who improperly accessed patient records, illustrates how even seemingly minor or “curious” data access can escalate into serious privacy breaches with legal and reputational consequences.

For businesses across Canada, from healthcare providers to HR departments and financial institutions, the lesson is clear: Employee access to personal data must be carefully controlled, monitored, and documented.

The Incident: When Curiosity Becomes a Privacy Breach

The controversy stems from findings by the B.C. information and privacy commissioner that dozens of healthcare employees improperly accessed patient records across multiple health authorities. This included numerous incidents of “snooping,” or accessing personal information without a legitimate work-related reason.

Privacy lawyer Lyndsay Wasser emphasized that such incidents are not rare. In fact, she described employee snooping as a fairly common problem across organizations handling sensitive information.

This underscores a critical risk for employers. Unauthorized access can occur even when employees technically have system permissions, if the purpose of access is not legitimate.

Authorized Access vs. Authorized Purpose

A key takeaway from the case is the distinction between having access to data and having a valid reason to use it. Many workplaces rely on trust or informal norms rather than clear policies defining appropriate data use.

For example, employees may access records out of curiosity, personal relationships, or benign intentions, such as looking up contact information or compensation details. However, these actions can still constitute privacy violations.

Access privileges do not equal permission to use data for any purpose. Organizations must ensure employees understand both technical access limits and legal privacy obligations.

Legal, Financial, and Reputational Risks for Employers

When workplace snooping occurs, employers face complex decisions about discipline and liability. Depending on the circumstances, unauthorized access can justify termination or trigger regulatory scrutiny.

Courts and tribunals typically evaluate the sensitivity of the information accessed, the employee’s intent and role, the organization’s privacy policies and training, and the organization’s response after discovering the breach.

Failure to demonstrate strong privacy governance can expose employers to lawsuits, regulatory penalties, and loss of public trust.

Why This Matters Beyond Healthcare

Although the case involved medical records, the broader implications apply across sectors. HR files, payroll data, customer information, and financial records all carry similar risks.

In a digital workplace, the challenge is amplified by centralized databases and remote access systems, making unauthorized viewing easier and more difficult to detect.

Best Practices for Preventing Workplace Privacy Breaches

Organizations can reduce the risk of internal data misuse by adopting proactive privacy controls.

  • Implement clear access policies: Define precisely when and why employees may access personal data, and avoid relying on assumptions or informal practices.
  • Provide role-specific privacy training: Ensure staff understand legal obligations under Canadian privacy laws and internal policies.
  • Monitor and audit data access: Regularly review access logs to detect unusual or unauthorized activity.
  • Establish discipline protocols: Develop consistent procedures for investigating and responding to privacy violations.
  • Secure physical and digital records: Combine cybersecurity measures with proper document destruction practices to minimize exposure risks.

The Role of Secure Document Destruction in Privacy Compliance

While digital security is essential, many privacy breaches still originate from improperly handled physical records. Organizations must adopt secure shredding practices to prevent unauthorized access to sensitive information once it is no longer needed.

At Norfolk Shredding, we help businesses maintain compliance with privacy regulations through certified document destruction and secure information management solutions.

Privacy protection doesn’t end with access controls. It includes how records are stored, managed, and destroyed.

Final Thoughts

The B.C. snooping scandal serves as a powerful reminder that internal privacy risks can be just as damaging as external cyber threats.

By strengthening policies, training employees, and adopting secure document destruction practices, organizations can protect personal data, maintain regulatory compliance, and preserve stakeholder trust.


References

Thomas, Stacy. “B.C. snooping scandal puts workplace privacy and employer liability under microscope.” Canadian HR Reporter, Feb. 20, 2026.

First-Ever PHIPA Monetary Penalties Signal a New Era in Health Privacy Enforcement

Published for Norfolk Shredding – Secure Document Destruction & Privacy Compliance


In August 2025, Ontario’s privacy landscape shifted significantly when the Office of the Information and Privacy Commissioner of Ontario (IPC) issued its first Administrative Monetary Penalties (AMPs) under the Personal Health Information Protection Act, 2004 (PHIPA).

This landmark enforcement decision, PHIPA Decision 298, demonstrates that healthcare organizations and professionals who fail to protect personal health information (PHI) may now face direct financial consequences, reinforcing the growing importance of robust data governance and secure information disposal practices.

What Are Administrative Monetary Penalties (AMPs)?

As of January 1, 2024, PHIPA grants the IPC authority to impose monetary penalties for privacy violations.

Maximum AMP thresholds include up to $50,000 for individuals and up to $500,000 for organizations.

These penalties form part of a progressive enforcement model, meaning they are typically reserved for serious or repeated privacy violations, particularly where organizations or individuals derive financial benefit from misuse of personal health information.

Compliance insight: AMPs are unlikely for isolated or unintentional errors but may apply where governance failures, systemic issues, or intentional misuse are present.

Case Overview: PHIPA Decision 298

The IPC’s first AMP decision involved a physician affiliated with Windsor Regional Hospital and a private clinic.

Key findings included the following:

  • The physician conducted 146 unauthorized electronic health record searches over three weeks.
  • PHI from 831 patients may have been accessed.
  • Parents of 91 newborn males were contacted to promote paid circumcision services.
  • The physician derived financial benefit from this activity.
  • The clinic lacked documented privacy policies, procedures, or governance controls.

Penalties issued were a $5,000 AMP imposed on the physician and a $7,500 AMP imposed on the clinic.

Although the hospital was not fined, the IPC issued recommendations to strengthen its privacy governance, staff obligations, and policy distribution processes.

Why This Decision Matters

AMPs are now a real enforcement risk.

PHIPA Decision 298 confirms that monetary penalties are not theoretical; they are now an active regulatory tool used to deter privacy violations.

Economic gain from privacy violations is a major factor.

The IPC emphasized that AMPs may be used to remove financial incentives for improper use of personal information.

Privacy governance failures can lead to financial penalties.

The clinic’s lack of a privacy management program was a key aggravating factor in the penalty decision.

Best practice: Organizations handling health information must implement formal privacy policies, staff training, and secure data lifecycle management, including certified document destruction.

Organizations are responsible for their agents.

Healthcare institutions must ensure employees and contractors access PHI only within their legitimate “circle of care.”

Broader Implications for Canadian Privacy Compliance

This decision marks the first instance of a Canadian privacy regulator using administrative monetary penalties, potentially setting a precedent for:

  • expanded enforcement powers in other provincial privacy regimes
  • increased scrutiny of data governance practices
  • higher compliance expectations for organizations handling sensitive personal data.

Public sector bodies, healthcare providers, and private organizations must now treat privacy compliance as both a legal and financial risk management priority.

How Secure Information Disposal Supports PHIPA Compliance

A comprehensive privacy program extends beyond digital safeguards. Secure document destruction is a critical component of PHIPA compliance and risk mitigation.

At Norfolk Shredding, we help organizations prevent unauthorized access to confidential records, maintain compliant retention and destruction schedules, demonstrate accountability during audits or investigations, and reduce exposure to privacy breaches and regulatory penalties.

Privacy protection starts at disposal. Proper shredding ensures sensitive information does not become a liability.

Final Takeaway

PHIPA Decision 298 represents a turning point in Ontario’s privacy enforcement framework. The introduction of monetary penalties underscores the importance of proactive privacy governance, staff accountability, and secure information handling practices.

Organizations that invest in strong compliance frameworks, including certified document destruction services, will be better positioned to avoid regulatory penalties and maintain public trust.


Reference

Original article summary adapted from Lexology, “First Administrative Monetary Penalties Under PHIPA Signal New Enforcement Era,” available at https://www.lexology.com/library/detail.aspx?g=ad61fc9f-6895-4d97-b7c1-63174bb31585

Fax Machines Still Threaten Patient Privacy in Canada: Why Secure Document Destruction Matters More Than Ever

Healthcare privacy risks don’t always come from sophisticated cyberattacks. In many cases, they stem from outdated technologies still embedded in daily operations — including the humble fax machine.

A recent article by journalist Francine Kopun in the Toronto Star highlights how faxing remains one of the leading causes of patient privacy breaches in Ontario’s healthcare system, raising serious concerns about how sensitive medical information is transmitted and ultimately handled.

For organizations handling confidential records, this underscores a critical truth: privacy risks don’t end with digital systems — they extend to physical documents and legacy workflows.


The Persistent Privacy Risk of Fax Machines

Despite years of modernization efforts, fax machines continue to play a major role in healthcare communications. According to privacy data cited in the reporting, misdirected faxes account for a significant portion of unauthorized disclosures of personal health information.

This ongoing reliance on outdated systems illustrates a wider problem:

Manual processes increase the risk of human error

Manual handling, data entry, and tracking are prone to mistakes and oversights.

Paper-based workflows create physical document vulnerabilities

Paper documents can be lost, accessed by unauthorized individuals, or damaged.

Sensitive information can be mishandled, misplaced, or improperly discarded

Without secure controls, sensitive information can end up in the wrong hands, or the trash.

Paper-based processes may be routine, but the risks are real.

Healthcare providers are working to transition toward secure digital solutions, but infrastructure challenges and interoperability issues mean the transition is far from complete.


Why Outdated Information Practices Create Modern Privacy Threats

While cyber threats often dominate headlines, legacy technologies can be just as dangerous when it comes to privacy compliance.

Fax machines introduce risks such as:

  • Documents sent to incorrect recipients
  • Printed medical records left unattended
  • Confidential files disposed of without proper destruction
  • Lack of encryption or access control

These vulnerabilities can lead to compliance violations, reputational damage, and loss of public trust — especially in sectors handling sensitive personal information like healthcare.


The Role of Secure Document Destruction in Privacy Protection

Even as organizations move toward digital transformation, paper records remain a critical compliance concern.

Secure shredding services play a vital role by:

  • Ensuring proper disposal of confidential documents
  • Supporting compliance with privacy legislation such as PHIPA and PIPEDA
  • Reducing risk of data exposure from physical records
  • Providing verifiable audit trails and certificates of destruction

At Norfolk Shredding, secure document destruction helps organizations close the privacy gap created by outdated workflows and human error.

Privacy Compliance Isn’t Just Digital

“Modern privacy risks often originate in legacy systems and physical processes.”
Organizations must address both digital security and paper record management to maintain compliance.

Moving Toward Safer Information Management

The continued reliance on fax technology highlights a broader challenge: true privacy protection requires a holistic approach to information governance.

Organizations can reduce risk by:

  • Transitioning to secure digital communication platforms
  • Implementing strict document retention and destruction policies
  • Training staff on proper handling of sensitive information
  • Partnering with certified shredding providers

Final Thoughts: Protecting Trust Through Responsible Information Handling

The Toronto Star’s reporting serves as an important reminder that privacy breaches often arise from overlooked operational risks — not just advanced cyber threats.

By modernizing communication systems and ensuring proper disposal of physical records, organizations can better safeguard sensitive information and maintain public trust.


Protect Your Business Information with Norfolk Shredding

Whether your business needs secure document destruction, scheduled shredding services, or support with protecting confidential records, Norfolk Shredding is committed to helping organizations safeguard sensitive information while supporting environmentally responsible recycling initiatives.

To learn more about secure document destruction services, contact Norfolk Shredding today at 1-855-561-1716.


References

Kopun, Francine. “Fax machines are Ontario’s top cause of patient privacy breaches, new data reveals. Why is health care still stuck on them?” Toronto Star, 2026.

Bill C-22 and the Encryption Debate: Why Privacy Advocates Are Raising Alarm Bells

As Canada continues to debate the future of digital privacy and lawful access legislation, concerns surrounding Bill C-22 are rapidly intensifying. In a recent article, Canadian internet law expert Michael Geist warns that the federal government may be repeating mistakes made during the rollout of the Online News Act (Bill C-18), where early warnings from industry experts and technology companies were largely dismissed until serious consequences followed.

For businesses, consumers, and organizations responsible for safeguarding sensitive information, the debate around encryption, metadata retention, and digital surveillance is more than political theatre, it is fundamentally about trust, cybersecurity, and data protection.

What Is Bill C-22?

Bill C-22 is Canada’s proposed lawful access legislation designed to provide law enforcement and security agencies with expanded tools to access digital communications and subscriber information during investigations.

According to critics, however, several provisions within the bill could weaken encryption standards and create cybersecurity vulnerabilities that affect every Canadian internet user.

Major technology companies and privacy advocates have publicly expressed concern, including:

Signal

Apple

Meta

Canadian Chamber of Commerce

Signal reportedly stated it would rather leave the Canadian market than compromise its end-to-end encryption protections. Apple similarly warned that the legislation could potentially force companies to create backdoors into secure systems.

Why Encryption Matters for Privacy and Security

Encryption is one of the most important safeguards protecting personal, corporate, financial, and healthcare information from cybercriminals and unauthorized access.

When governments propose legislation that could weaken encryption systems, cybersecurity experts often warn about unintended consequences:

  • Increased vulnerability to hacking and ransomware
  • Greater exposure of sensitive personal data
  • Risks to confidential business communications
  • Reduced public trust in digital platforms
  • Potential international trade and cross-border data concerns

Michael Geist argues that government officials have repeatedly characterized critics as “misunderstanding” the bill, despite warnings coming from technology companies, cybersecurity professionals, legal experts, and even members of the U.S. Congress.

Echoes of the Online News Act

One of the central themes of Geist’s article is that the government appears to be following a familiar pattern seen during the debate over the Online News Act (Bill C-18).

At that time, major platforms warned that the legislation would result in news content being blocked in Canada. Government officials publicly downplayed those concerns, until companies like Meta ultimately removed Canadian news links from their platforms.

Geist suggests the same “it won’t happen” messaging is now unfolding around Bill C-22 and encryption concerns.

Metadata Retention Raises Additional Concerns

Beyond encryption, privacy advocates are also alarmed by metadata retention provisions within Bill C-22.

Metadata can include:

  • Who communicated with whom
  • When communications occurred
  • Device identifiers
  • Location data
  • Duration and frequency of communications

While metadata may not include message content itself, experts warn that long-term retention of this information can create highly detailed digital profiles of individuals and organizations.

Critics argue that mandatory metadata retention could dramatically expand surveillance capabilities while simultaneously increasing the amount of sensitive information available to hackers in the event of a breach.

Why This Matters to Businesses

For organizations handling confidential customer records, employee information, financial documents, or legal files, cybersecurity and privacy compliance are critical operational responsibilities.

At Norfolk Shredding, protecting sensitive information goes beyond physical document destruction. Modern information security requires businesses to think holistically about how data is stored, transmitted, retained, and ultimately destroyed.

Whether discussing digital encryption standards or secure paper shredding practices, the underlying principle remains the same:

Protecting sensitive information protects businesses, customers, and communities.

The Growing Importance of Data Security

As cyber threats continue to evolve, businesses must remain proactive about information governance and privacy protection.

Key best practices include:

  • Secure destruction of physical documents
  • Strong digital encryption practices
  • Limited data retention policies
  • Employee cybersecurity training
  • Proper disposal of electronic devices and storage media
  • Working with trusted privacy and security partners

Legislation like Bill C-22 demonstrates how rapidly the privacy landscape can change, and why organizations must stay informed about emerging cybersecurity risks and regulatory developments.

Protect Your Business Information with Norfolk Shredding

Whether your business needs secure document destruction, scheduled shredding services, or support with protecting confidential records, Norfolk Shredding is committed to helping organizations safeguard sensitive information while supporting environmentally responsible recycling initiatives.

To learn more about secure document destruction services, contact Norfolk Shredding today at 1-855-561-1716.


References

Geist, Michael. “Bill C-22’s Groundhog Day: Why the Government’s Dismissal of Signal, Apple and the U.S. Congress Concerns Runs Back the Disastrous Online News Act Playbook.” Michael Geist Blog Article. Published May 14, 2026.

Additional context and related analysis by Michael Geist:

  • “The Lawful Access Two-Headed Surveillance Monster: How Bill C-22 Went Off the Rails”
  • “The Lawful Access Privacy Risks: Unpacking Bill C-22’s Expansive Metadata Retention Requirements”
  • “How Much Further Will Lawful Access Go?: Police Chief Tells Bill C-22 Hearing That Three Years of Metadata Retention Would Be ‘Ideal’”

Let our experts review your current waste and recycling program and show you the benefits of partnering in business with us.

HGC Management Inc
danger alert

IF YOU NEED TO CANCEL OR POSTPONE SERVICE, WE REQUIRE
NOTICE 48 HOURS PRIOR TO YOUR SCHEDULED SERVICE DATE.

Back to top