From clinical access to commercial funnel
PHIPA Decision 298 is often summarized as “doctor fined for snooping.” That summary is too gentle. The fact pattern is commercial misuse of a clinical privilege.
According to the decision record and the IPC’s case summary, a physician with hospital privileges used a shared electronic health record environment to identify parents of newborn males and contact them about circumcision services offered through his private pediatric clinic. Over a short period he conducted on the order of 146 targeted searches. Many of those families received outreach by phone or text. Parents complained. Hospitals moved quickly to investigate and suspend privileges.
This is the kind of case privacy officers should teach in orientation — not because every agent will copy it, but because it shows how “authorized technical access” and “authorized purpose” are not the same thing.
Why economics aggravates
Ontario’s AMP guidance for the health sector is explicit that one purpose of monetary penalties is to prevent custodians and others from deriving economic benefit from a contravention. Decision 298 puts that principle to work.
A few nuances matter for program design:
- Benefit can be prospective. The IPC’s analysis does not require a perfect accounting of revenue earned from each text message. The purpose — identifying eligible patients for private solicitation — is itself the problem.
- Volume shows intent. One mistaken open might be explainable. Dozens of structured searches over weeks look like a method.
- Vulnerability multiplies harm. Postpartum families are not ordinary marketing leads. The power imbalance is clinical and emotional.
- Mitigation still counts. Stopping when confronted and a clean prior record affected quantum. They did not erase the aggravating commercial purpose.
I agree with that structure. If AMPs only punished curiosity, commercial actors would treat weak controls as a cost of customer acquisition. Making economic motivation aggravating changes the expected value of cheating.
Detection: stop auditing only for famous names
Most health organizations still over-index on celebrity access and under-index on pattern analytics. Commercial misuse often looks like:
- Repeated searches by demographic criteria (age, sex, location, delivery date windows).
- Access bursts outside a physician’s usual clinic schedule or service line.
- Same user pivoting from hospital identity to private-practice outreach lists.
- Low or zero clinical documentation connected to the access events.
- Secondary use through phone/text systems not logged in the EMR.
If your SIEM or privacy audit tool cannot express “newborn + male + high-volume search + non-attending pattern,” you are flying partially blind.
Controls that respond to economic misuse
- Purpose attestation at query time for broad demographic searches, with sampling review.
- Separation of hospital credentials from private practice CRM tools — no copy-paste pipeline.
- Contract and bylaw language that expressly forbids using hospital PHI for independent commercial solicitation.
- Vendor and clinic onboarding when privileged staff operate parallel private businesses.
- Rapid containment playbooks that include cutting shared-EHR access while investigations run.
- Restitution and disgorgement thinking in settlement and discipline — not only training certificates.
- Dual-practice disclosure at appointment and reappointment so privacy and credentials share a risk list.
Culture problem, not only tech problem
Physicians and staff sometimes rationalize: “I’m offering a legitimate service; families can say no.” PHIPA does not organize itself around that rationalization. Personal health information from a hospital circle of care is not a marketing database for a side practice, full stop. Leaders need to say that without euphemism in orientation, in credentials meetings, and in the uncomfortable one-on-ones when someone’s private clinic growth plan starts to lean on hospital data access.
I also want privacy teams to partner with professional practice offices earlier. If the first time medical affairs hears about commercial misuse is when the IPC file opens, your internal network is too slow. Shared early-warning between audit analytics, privacy, and credentials is how you interrupt a 146-search pattern at search twenty.
Teaching the case without turning it into gossip
Use the published facts from the IPC decision and public summary. Focus training on purpose limitation, audit patterns, and dual-practice boundaries. Avoid turning a privacy case into workplace entertainment. The goal is deterrence and detection, not spectacle.
For multi-site shared records, ask one extra question in every credentials file: what private commercial activity could this access enable, and how would we know if it started? If nobody owns the answer, economic misuse will look like normal work until parents complain.
Actionable takeaway
Decision 298 teaches that economic motivation is not a footnote. It is a central reason AMPs exist under the health-sector guidance. One hundred forty-six searches is a system of extraction, not a slip. Build audit rules, bylaws, and clinic boundaries that assume someone will eventually try to turn clinical access into a sales channel — and make sure that attempt is unattractive, detectable, and expensive. This quarter, add at least one audit rule aimed at demographic bulk search patterns and one bylaw or policy sentence that bans commercial secondary use of hospital PHI in plain language. Does your organization explicitly ban — and actively monitor for — commercial secondary use of hospital PHI by privileged professionals?