Cybersecurity issues are an increasing concern in healthcare. CMPA considers cybersecurity issues in the context of privacy and protection of healthcare information.
Assistance within CMPA’s mandate
CMPA assists members (and their eligible clinics) with privacy-related matters, including complaints, investigations, and claims arising from the practice of medicine. However, CMPA is a mutual medical defence organization, not an insurance company, and our assistance focuses on helping Canadian physicians with medico-legal matters related to the practice of medicine.
As a medico-legal organization, issues related to the business of medicine fall outside our mandate. Accordingly, CMPA does not typically assist with ransomware payments or data restoration costs, privacy breach notification, forensic investigation, or hardware issues. CMPA also does not assist members in becoming privacy compliant nor does it pay fees, penalties, or other costs assessed for any privacy or cybersecurity breach.
This has been our approach to date and in reviewing the current landscape, we have made some changes.
Changes to CMPA assistance
Starting September 25, 2026, CMPA will no longer assist with the payment of:
- damages arising from a finding of inappropriate collection, use, or disclosure of personal health information (e.g., “snooping”, inappropriate recording of patients), or settlements arising from such allegations; and
- damages or settlements related to cyber breaches.
CMPA’s Principles of Assistance pertaining to Privacy and cybersecurity matters have been revised to reflect these changes.
What this means for members
If you are a physician with administrative authority at your clinic, tasked to oversee cybersecurity and/or a clinic owner, you should be aware of your potential liability and take steps to ensure appropriate insurance for privacy and cyber breaches.
Ideally, this insurance product would extend to the costs of remediating a cyber breach incident (such as forensics, breach notification, and data restoration) and potential damages awards and settlements related to cyber breaches and related to inappropriate collection, use, or disclosure of personal health information.
Assistance in identifying cyber and privacy breach insurance providers
Many provincial and territorial medical associations and federations play an important role in providing resources and support to help physicians run their practices, such as cyber and privacy insurance providers. We encourage you to contact your provincial or territorial association or federation. They may be able to provide assistance and identify cyber and privacy breach insurance providers that can help cover costs and damages that fall outside the scope of CMPA assistance.
More information on related CMPA assistance and guidance
Hospital-based physicians are typically not responsible for making decisions related to cybersecurity in their institution. If you have questions about CMPA assistance with privacy-related matters, we encourage you to read the following:
Members who wish to obtain more information or require clarification are invited to contact the CMPA at 1-800-267-6522, Monday to Friday between 8:30 a.m. to 4:30 p.m. ET.