Midwives of Windsor tells clients an email account was breached in April 2023
- Organization
- Midwives of Windsor
- Exploit
- Credential Compromise
- Industry
- Healthcare
The Midwives of Windsor, an Ontario midwifery practice, notified clients in early January 2024 that an unauthorized party had gained access to one of the clinic's email accounts in April 2023.
According to the notification described in news coverage, the exposed information could include a client's name, date of birth, mailing address, email address, telephone number, information about their pregnancy, treatment and diagnosis details, prescription information, patient identification numbers and health insurance information. The name and date of birth of a client's child may also have been included. The clinic did not say how many people were affected.
The Information and Privacy Commissioner of Ontario said the practice reported the breach to its office on November 3, 2023, roughly seven months after the incident occurred and about two months before clients were told. The clinic said it had also notified law enforcement.
Midwives of Windsor said it acted immediately to secure the compromised email account and retained third-party experts to investigate. It said it was not aware of any misuse of the information but could not guarantee that none had occurred, and it advised clients to watch for suspicious communications that might be linked to the incident. Commentators questioned the length of the notification delay and whether the account had been protected with multifactor authentication.