Health PEI Discloses Vendor Cyberattack Involving a 2011 Personal Health Information File
In this article & details
Health PEI has disclosed a privacy incident involving a file created in 2011 that contained personal health information. The notice applies to people who had a PEI health card number in or before 2011 and some non-residents who received health services in the province between 2008 and 2011.
The incident occurred in a vendor’s systems
According to Health PEI’s September 28 notice, an unauthorized person obtained a copy of the file during a cybersecurity incident affecting a company that provided services to the health authority. Health PEI and Government of Prince Edward Island systems were not compromised, and records stored in provincial systems were not accessed inappropriately.
The province’s official frequently asked questions confirm the affected groups and provide current guidance for people who may be concerned.
What information was involved
The file contained some or all of the following: names, date of birth, date of death where applicable, gender, PEI Personal Health Number, Medicare eligibility dates and codes, and health-card issue and expiry information. Health PEI currently considers the risk of misuse low, while acknowledging that a breach involving personal health information can be concerning.
The incident has been reported to the PEI Information and Privacy Commissioner, whose office has opened a file, and law enforcement has been notified. The vendor is reviewing its processes and implementing measures intended to reduce the chance of a similar incident.
Potential phishing risk deserves attention
Health PEI advises potentially affected people to be alert for suspicious emails, texts or calls seeking personal information or claiming to relate to health coverage, government programs or identity verification. Requests should be verified using independently obtained contact information rather than links or numbers contained in an unexpected message.
For pharmacies, the incident is also a reminder that privacy risk extends beyond the dispensary network. Claims processors, software vendors, document services and other suppliers may hold or receive health information. Contracts, access controls and incident-response plans should reflect that shared responsibility.
Practice guidance for pharmacists
- Brief staff on the incident and reinforce that unexpected requests involving PEI health cards or identity verification may be phishing attempts.
- Verify callers and senders through trusted contact channels before discussing coverage, demographic details or prescription information.
- Collect, disclose and retain only the minimum personal health information necessary for the authorized purpose.
- Review which vendors can access patient information, how access is logged and revoked, and who must be notified after a suspected breach.
- Document suspicious contacts or privacy concerns and escalate them promptly through the pharmacy’s privacy officer and applicable reporting process.