Skip to main content
CIPP/CCIPP/CPrivacyCanadaPHIPA

Decision 334: 436 Records, One Clerk, and Why the Hospital Was Spared

PHIPA Decision 334: a clerk's 436-record snooping drew a personal AMP while CHEO's response mattered—unauthorized access needs no profit motive.

5 min read
ShareLinkedIn

The second AMP clarifies the first

If Decision 298 taught Ontario that AMPs are real and that economic motivation matters, Decision 334 teaches something just as important: unauthorized access out of personal interest is still “AMP-eligible,” and organizational response quality can decide who pays.

The core facts, drawn from the IPC’s public materials and decision coverage:

  • A patient services clerk at the Children’s Hospital of Eastern Ontario (CHEO) inappropriately accessed PHI of 436 patients over a period of months in 2024.
  • The issue surfaced when a nurse appeared to know details she should not have known about a stepchild’s care; privacy investigation and audit expanded the scope dramatically beyond one chart.
  • The clerk had received training, continued the behaviour, and did not present as a model of accountability during the investigation.
  • The IPC imposed a $2,000 AMP on the clerk personally.
  • CHEO’s detection, investigation, and program posture were treated as material context — the hospital was not the AMP target in the way the clinic was in Decision 298.

That is progressive enforcement with a memory.

Snooping without profit is still serious

I still hear residual folklore in some departments: “It only really counts if they sold the data.” Decision 334 is a clean rebuttal. The IPC has reinforced that unauthorized access is a significant departure from PHIPA obligations even without copying, retention for resale, or measurable financial gain. Curiosity is not a legal purpose. Kinship, gossip, and “I was just checking” are not legal purposes either.

For children’s hospitals and any custodian holding highly sensitive records, that point should be non-negotiable in training. The population is vulnerable. The temptation to look is real. The rule has to be simpler than people’s rationalizations.

Why the hospital’s response matters

Comparing 298 and 334 is now a standard teaching move in my sessions:

Dimension Decision 298 (clinic / physician pattern) Decision 334 (CHEO clerk)
Actor Physician + private clinic program failures Employee agent
Motive theme Commercial solicitation Unauthorized personal access
Scale signal 146 searches / outreach pattern 436 patient records
Org outcome Clinic AMP; hospital safeguards noted Individual AMP; hospital not penalized the same way
Program message Weak private-clinic accountability costs money Strong detection and response can contain organizational penalty risk

The lesson is not “hire better luck.” The lesson is that demonstrable monitoring and a serious privacy office change the enforcement story.

What “good response” looks like operationally

From the public narrative around Decision 334, the effective pattern includes:

  1. A culture where staff escalate weird knowledge. A nurse speaking up was the tripwire.
  2. Audit capability that can expand from one MRN to a user’s full history. Scope discipline matters.
  3. Employment consequences that match severity. Termination is not a privacy control by itself, but it is part of deterrence.
  4. Timely reporting to the IPC when thresholds are met.
  5. Evidence of prior training — which, notably, did not save the clerk from an AMP, but shows the organization was not silent on expectations.

Training without monitoring is a sermon. Monitoring without consequences is theatre. You need both.

Designing for the 436 problem

Large-volume snooping is often a horizontal access problem: a role that can open many charts, weak alerts on after-hours or out-of-department views, and delayed random audits. Practical upgrades:

  • Role-based alerts when a user exceeds peer baselines for unique patient views.
  • Extra friction for break-glass and family-adjacent records.
  • Monthly sampling of high-volume non-clinical roles (clerks, registration, scheduling).
  • Documented coaching and progressive discipline before six months of drift accumulate.
  • Board metrics: time-to-detect unauthorized access, not only phishing click rates.
  • Clear sanctions guidance so managers do not improvise when the subject is a popular colleague.

Decision 334 also belongs in staff training with Decision 298, not as a replacement for it. One case is commercial pipeline abuse. The other is curiosity at scale. Staff need both stories. Executives need the comparison chart: program strength changes organizational outcomes even when agent misconduct is ugly.

What I tell privacy and people leaders together

Decision 334 is not only an AMP story. It is a culture story. A nurse who escalated unusual knowledge did more for patients than a policy nobody reads. Leaders should celebrate that behaviour publicly while still running the audit tools that confirm scope.

I also want executives to stop treating individual AMPs as proof the organization is safe. Individual liability can exist beside organizational credit. The goal is early detection, documented response, and fewer records exposed—not a victory lap because the hospital avoided a fine this time.

Keep primary sources in the training pack: the IPC second AMP materials, the first AMP summary, and PHIPA Decision 298 for the commercial-misuse contrast. Staff need both narratives.

Actionable takeaway

Decision 334 is Ontario’s second PHIPA AMP and a case study in individual liability paired with organizational response credit. Four hundred thirty-six records is enormous human exposure. Two thousand dollars will not impress every observer as a quantum — but personal liability plus job loss is a clear deterrent story for staff, and the spared-hospital dynamic is a clear incentive story for custodians who invest in real detection. Be the organization that finds it early and can prove how.

If a colleague knew something from a chart they should never have seen, would your culture escalate — and would your audit tools confirm — within days, not months?

Related services

Practical consulting aligned to this article’s focus—program design, controls, and operational delivery.

Browse all services