Privacy and cybersecurity matters

4 minutes

Published September 2026 and currently in effect

At some point in their professional practice, physicians may encounter medico-legal issues related to information privacy and cybersecurity. These situations can be relatively simple, such as an email sent to the wrong recipient, or more complex, involving the inappropriate collection, use, or disclosure of large amounts of personal health information.

Obtain consent before recording patient encounters

Recording patient encounters for any purpose without consent would be considered an inappropriate collection and use of personal health information. For more information see “Recording clinical encounters with patients: What physicians need to know” and “Using clinical photography and video for educational purposes”.

A privacy breach can also result from cyberattacks if there is a loss of, or inability to, access patient information or if hackers gain access to patient information.

When a privacy breach occurs, physicians are often required to notify the affected parties and to report the incident, as outlined in CMPA’s article, Reporting a privacy breach: What are your responsibilities?. Privacy and cybersecurity breaches can also lead to complaints or investigations by regulatory authorities (Colleges), health authorities or hospitals, and privacy commissioners.

CMPA members (and eligible CMPA member-owned clinics) may contact CMPA for advice about their obligations to notify patients or report to other parties (e.g. College, health authority or hospital, privacy commissioner).

Because matters concerning the business of medicine are outside CMPA’s mandate, CMPA assistance does not generally extend to ransomware payments, or costs for data restoration, privacy breach notifications, forensic investigations, or hardware issues. Similarly, CMPA does not assist members in becoming privacy compliant.

Civil legal actions

CMPA will generally assist members and eligible CMPA member-owned clinics and clinic employees in defending civil legal actions and paying associated settlements or damages related to either complex or simple privacy matters arising from the practice of medicine.

However, CMPA does not generally pay the following:

  • fines, penalties, or other costs assessed against a member for a privacy or cybersecurity breach;
  • damages arising from a finding of inappropriate collection, use, or disclosure of personal health information (e.g. “snooping”, inappropriate recording of patients), or settlements arising from such allegations; and
  • damages or settlements related to a cybersecurity breach.

Members are encouraged to contact their provincial or territorial medical association, which may be able to identify insurance providers for cybersecurity and privacy breaches and that can assist with costs and damages that are outside the scope of CMPA assistance.

Privacy commissioner complaints and investigations

CMPA generally assists members and eligible CMPA member-owned clinics and clinic employees with complaints and investigations by privacy commissioners or their equivalent (e.g. ombudspersons) related to privacy and cybersecurity breaches arising from medical professional work.

CMPA does not pay fees, penalties, or other costs assessed for a privacy or cybersecurity breach.

College complaints, and health authority or hospital matters

CMPA generally assists members facing complaints and disciplinary proceedings at a regulatory authority (College), health authority, or hospital relating to the professional practice of medicine which may include privacy and cybersecurity breaches, in accordance with its principles of assistance for Regulatory authority (College) matters and Hospital complaints and investigations.

CMPA does not pay costs or fines arising from such proceedings.

More reading

Article: Cybersecurity threats: Are you prepared?

Article: Reporting a privacy breach: What are your responsibilities?