Nova Scotia health data at risk due to ineffective cybersecurity: report
Nova Scotia doesn't provide effective cybersecurity for its digital health networks, and as a result is exposed to unnecessary risk, says a new report by the province's auditor general.
Kim Adair's report published Tuesday found a lack of accountability and collaboration between the three government entities that oversee the system: the health department, the cybersecurity and digital solutions department, and Nova Scotia's health authority.
The situation is problematic because of the province's growing reliance on digital networks to store people's personal and sensitive health information, the report says.
Citing attacks in other provinces, like Newfoundland and Labrador and Ontario, she said, "We've seen several health-care organizations fall victim to serious cyberattacks that have compromised sensitive information, disrupted patient care and disabled networks."
Nova Scotia's "lack of IT governance gives minimal accountability for cybersecurity during a time of rapid expansion" of the province's digital health network, Adair said.
The report says key governance structures established to manage and monitor the network, along with cybersecurity efforts, were abandoned by 2022.
The auditor said her office hired Toronto-based independent experts from Packetlabs to run cybersecurity tests between April 2021 and June 2023, which revealed a "pervasive tolerance" for accepting risk and a failure to manage ongoing risks. More specifically, the report found that external health sector contract holders -- such as pharmacies and doctors' offices -- weren't required to include cybersecurity training before accessing the network.
The report also said testing showed most proposed technology projects that added to or changed the data flow or architecture of the digital health system didn't fully comply with a mandatory three-phase review process put in place by a government panel. As well, the report said the review board allowed projects to connect to the network without meeting cybersecurity standards.
To strengthen the system, the 42-page report makes 20 recommendations, including the creation of an information technology governance framework to manage the digital health system, the completion of all outstanding cybersecurity assessments and regular mandatory cyber awareness training for all health network users.
Adair said her office would follow up on the progress of the digital health network a year from now. So far, she said, response from the government agencies involved has been positive.
In an emailed statement, a provincial spokesperson said the departments of health and of cybersecurity and digital solutions, along with Nova Scotia's health authority said changes in the system are already underway.
"We are making investments and reducing risk as much as possible, while we modernize our digital health infrastructure. We have already begun work on many of the auditor general's recommendations and will continue to work on the rest," spokesperson Rachel Boomer said in an email.
The province said it will not disclose details of the changes underway to prevent further cyber threats from bad actors.
This report by The Canadian Press was first published Oct. 22, 2024.
For more Nova Scotia news visit our dedicated provincial page.
CTVNews.ca Top Stories
Downtown Vancouver stabbing suspect dead after being shot by police
A suspect is dead after being shot by police in a Vancouver convenience store after two people were injured in a stabbing Wednesday morning, according to authorities.
2 Canadians confirmed dead in Poland, as consular officials gather information
Two Canadians have died following an incident in Poland, CTV News has learned.
Ontario Premier Doug Ford calls Donald Trump 'funny guy' in Fox News interview
Ontario Premier Doug Ford called U.S. president-elect Donald Trump a 'funny guy' on Wednesday in an interview with Fox News for his comment that Canada should become the United States's 51st state.
DEVELOPING As police search for suspect, disturbing video surfaces after U.S. health-care CEO gunned down in New York
UnitedHealthcare CEO Brian Thompson was killed Wednesday morning in what investigators suspect was a targeted shooting outside a Manhattan hotel where the health insurer was holding an investor conference.
Toddler fatally shot after his 7-year-old brother finds a gun in the family's truck
A two-year-old boy was fatally shot when his seven-year-old brother found a gun in the glovebox of the family's truck in Southern California, authorities said.
Millions in Cuba remain in dark after nationwide blackout
Cuba said it was generating only enough electricity to cover about 1/6th of peak demand late on Wednesday, hours after its national grid collapsed leaving millions without power.
'Utterly absurd': Freeland rebuffs Poilievre's offer of two hours to present fall economic statement
Deputy Prime Minister and Finance Minister Chrystia Freeland has rebuffed Conservative Leader Pierre Poilievre's offer to give up two hours of scheduled opposition time next Monday to present the awaited fall economic statement as 'utterly absurd.'
Canada Post stores continue to operate during strike — but why?
As many postal workers continue to strike across the country, some Canadians have been puzzled by the fact some Canada Post offices and retail outlets remain open.
Mattel sued over 'Wicked' dolls with porn website link
Mattel was sued this week by a South Carolina mother for mistakenly putting a link to an adult film site on the packaging for its dolls tied to the movie 'Wicked.'