Trillium Hospital partner suffered a data breach incident after one of its staff used her access to Trillium's entire database to secretly review the confidential medical records of Trillium patients for many years and hundreds of times.
Records contain highly sensitive and private information about patients' medical histories including medications taken, treatments received, operations undergone, the diseases and disorders they may suffer from, and family circumstances, among others.
A proposed class action for a breach of privacy has been commenced against Trillium Health Partners, Mississauga Ophthalmologist Dr. Tony Vettese, and his assistant, Lisa Lyons.
TPRM report: https://scoringcyber.rankiteo.com/company/trillium-health-partners
"id": "tri21528522",
"linkid": "trillium-health-partners",
"type": "Breach",
"date": "06/2020",
"severity": "80",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Mississauga',
'name': 'Trillium Health Partners',
'type': 'Hospital'},
{'industry': 'Healthcare',
'location': 'Mississauga',
'name': 'Dr. Tony Vettese',
'type': 'Ophthalmologist'}],
'attack_vector': 'Insider Threat',
'data_breach': {'sensitivity_of_data': 'Highly sensitive and private',
'type_of_data_compromised': ['Medical histories',
'Medications taken',
'Treatments received',
'Operations undergone',
'Diseases and disorders',
'Family circumstances']},
'description': 'Trillium Hospital partner suffered a data breach incident '
"after one of its staff used her access to Trillium's entire "
'database to secretly review the confidential medical records '
'of Trillium patients for many years and hundreds of times.',
'impact': {'data_compromised': 'Confidential medical records',
'legal_liabilities': ['Proposed class action for breach of '
'privacy'],
'systems_affected': 'Entire database'},
'regulatory_compliance': {'legal_actions': ['Proposed class action for breach '
'of privacy']},
'threat_actor': 'Lisa Lyons',
'title': 'Data Breach at Trillium Hospital',
'type': 'Data Breach',
'vulnerability_exploited': 'Unauthorized Access by Insider'}