The situation
By the time Sari called our office, the company had already done three things: reset every employee's password, issued the employee involved a verbal warning, and told itself the matter was closed. None of those steps, it turned out, actually addressed the legal exposure the company was carrying, which is roughly what Sari said when she explained why she was calling a lawyer about something her own operations manager had already, in her words, handled.
Sari and Kostas ran a family company built around two businesses: a chain of clinics Sari had grown over more than a decade, and a construction company Kostas had run separately before the two operations were brought under one family holding structure, together generating somewhere between twenty and sixty million dollars a year. The clinics held a substantial volume of client records, and it was there that the problem had surfaced.
An employee named Dimitri, who worked in an administrative role at one of the clinic locations, had been found accessing client files well outside what his job required, including records belonging to people he had no professional reason to look up. A colleague had noticed the pattern and flagged it to the operations manager, who confronted Dimitri, reset system passwords across the location as a precaution, and gave him a formal verbal warning, treating it as an internal conduct issue rather than something that might carry broader legal consequences.
What the operations manager had not done, and had no particular reason to know to do, was determine whether the company had any obligation to notify the clients whose records had been accessed, document the incident in a way that would hold up if a client later complained, or figure out whether Dimitri's continued access to other systems needed to be restricted while the situation was assessed properly. Sari and Kostas were, at the time this came to a head, traveling in Europe for a family event, which meant the entire matter had to be handled without either of them present at the clinic or in the province.
Sari had been the one to insist, over the operations manager's initial view that the matter was closed, that the company get proper legal advice before considering the file finished. Her instinct, she later said, was less about any specific legal rule she knew and more a general sense that a client's private information being accessed without reason was not the kind of thing an internal warning should be able to fully resolve on its own.
The gap nobody had noticed
The first thing our review found was that the operations manager's fix, while well-intentioned, had missed the most basic legal question: what had actually been accessed, and by whom else, beyond the one pattern a colleague happened to notice. Resetting passwords prevents future access; it does nothing to establish the scope of what already happened, and without that scope, the company had no way to know whether it needed to notify anyone at all.
The deeper gap, once we looked at the clinic's system permissions, was structural rather than a single employee's misconduct. Several months earlier, the clinic had switched to a new records system, and during the transition, administrative staff had been given broader access than their roles required, as a temporary measure meant to help with the changeover. That temporary access had never been scaled back. Dimitri was not exploiting a deliberate flaw; he was using access the company itself had left open long after the reason for granting it had passed. That distinction mattered, because it meant the company's exposure was not limited to one employee's judgment, it extended to a system-wide gap that had been sitting there, unnoticed, for months.
We also found that the incident had not been properly time-stamped or scoped at the point it was discovered. The colleague who first noticed the pattern had described it informally to the operations manager rather than in writing, and no one had pulled the system's access logs to confirm exactly which records Dimitri had opened, on which dates, or whether the access extended beyond the handful of files the colleague happened to remember. Without that record, the company could not honestly say how serious the breach was, only that it had happened.
Coordinating all of this while Sari and Kostas were out of the country added a real practical constraint, but it also clarified what needed to happen regardless of who was physically present: a proper log review, a documented investigation, and a decision about notification did not require either owner to be standing in the clinic. What it required was someone who knew what questions to ask, working with the operations manager and the company's IT contact by phone, which is what the next phase of the file became.
It also became clear, once we asked, that the clinic had no written policy at all governing what staff should do if they suspected a colleague of misusing system access. The colleague who first noticed the pattern had hesitated for nearly a week before saying anything, unsure whether raising it would be seen as overstepping. That hesitation was its own quiet gap, separate from the permissions issue, and one worth naming plainly rather than treating as incidental to the main story.
What we did
- Pulled the full system access log. Before drawing any conclusions about what had happened or advising on next steps, we had the clinic's IT contact export the complete access history tied to Dimitri's account over the preceding six months. Starting with hard data rather than a secondhand account mattered because any notification decision the company made later would need to be defensible on its own record, not on a colleague's partial and understandably incomplete recollection of what they had noticed in passing.
- Scoped exactly what had been accessed. The log showed Dimitri had viewed records belonging to fourteen clients over several weeks, none of whom had any connection to the administrative tasks his role covered, confirming the access pattern was deliberate rather than an isolated mistake, and giving the company an objective basis for every decision that followed instead of relying on impressions from a single conversation.
- Corrected the underlying permissions gap. Because the access log review showed Dimitri's account was not uniquely privileged, we worked with the IT contact to identify every administrative account still carrying the broadened permissions left over from the earlier system transition. Each one was rolled back to what its role actually required, which meant the fix addressed the structural condition that had allowed the incident rather than stopping at the one account already caught, leaving no comparable opening for a repeat elsewhere in the clinic.
- Conducted a documented investigation. We prepared a written investigation record setting out the access log findings, a summary of what Dimitri said when asked directly about his reasons for looking at the files, and a full timeline of the company's response from the colleague's first observation onward. Creating that paper trail mattered because the earlier informal handling, a hallway conversation and a password reset, would not have withstood a client complaint or a regulatory inquiry, while a documented investigation could.
- Assessed the company's notification obligations. Based on the confirmed scope of fourteen affected clients, we advised that each of them needed to be notified that their records had been accessed without authorization, but that notifying the clients was not the whole of the obligation. A custodian whose records are accessed without authority also has to notify the privacy commissioner in the circumstances the health privacy rules set out, and if the person responsible is a regulated health professional, their college may have to be told as well. Dimitri worked in an administrative role rather than as a regulated professional, so the college piece did not apply here, but the commissioner notification did, and we treated it as a separate, mandatory step rather than something the client letters could substitute for. Each notification needed to describe what information was involved and what steps the company had taken in response, not just that something had occurred.
- Drafted and coordinated the notification. We prepared plain-language notification letters for the affected clients, avoiding the kind of vague or defensive language that tends to prompt more complaints than it prevents, and coordinated their delivery with clinic staff on the ground, alongside the separate notification to the privacy commissioner that the health privacy rules required. Sari and Kostas remained abroad throughout this stage, reviewing and approving each letter by email before it went out, which kept them in control of the decision without requiring either of them to be physically present for any part of it.
- Advised on Dimitri's employment status. Given the confirmed scope and the deliberate pattern the log revealed, fourteen unrelated client files accessed over several weeks, we advised that the earlier verbal warning no longer reflected the seriousness of what had actually happened. We worked with the company to document a termination for cause, grounding the decision in the investigation record rather than in the operations manager's initial, more lenient response, so the termination could withstand a later challenge if one came.
- Built a permissions review into ongoing practice. We recommended, and the company adopted, a routine quarterly review of administrative system access at each clinic location, run by the IT contact and checked against a simple list of what each role should be able to see. The goal was narrow and specific: catch leftover permissions from staffing changes or system transitions before they sat unnoticed for months the way this one had, rather than relying on a colleague happening to notice unusual behaviour.
- Wrote a short internal reporting policy. To address the week-long hesitation before the original concern was raised, we drafted a plain, one-page policy telling staff exactly who to contact, what information to include, and what would happen next if they noticed a colleague accessing records improperly. The point was to remove the guesswork that had delayed the first report, so the next one would reach someone able to act on it within days, not the better part of a week.
The outcome
The matter was resolved within about six weeks of Sari's first call, entirely through phone calls, email, and coordination with staff on site, without either owner needing to return to Ontario before the core work was done. All fourteen affected clients were notified and the privacy commissioner was notified as the health privacy rules required, and the company received no complaints or further escalation from any of them, which is not something that can be promised in advance, but reflects the value of a prompt, clearly documented, and honest notification rather than a delayed or partial one.
Dimitri's employment ended, supported by a documented record that left little room for dispute about what had happened or why the company had acted. The permissions gap that had made his access possible was closed across every location, not just the one where the incident occurred, which meant the company fixed the structural problem rather than only the individual case.
Sari said afterward that the most useful part of the process was not any single step but the shift from treating the incident as a personnel problem to treating it as a legal and operational one, which the company's own initial response had not done. The quarterly permissions review it adopted afterward has, so far, caught two further instances of leftover access from staff changes, neither involving any misuse, and both corrected before they became anything more than a routine housekeeping item.
Kostas, whose own construction business operates under a separate reporting structure within the family holding company, asked afterward whether a similar permissions review made sense there too, even though nothing had gone wrong on that side of the business. The company extended the quarterly review across both operations on that basis, treating the clinic incident as a prompt to check the other business before a similar gap had the chance to surface on its own.
What you can learn from this
- A password reset and a verbal warning address the immediate incident, not the underlying legal question of what was accessed and whether anyone needs to be told. Treat the two as separate problems.
- Leftover access permissions from a system transition are a common, quiet source of exposure. Any temporary access granted during a changeover should have a firm expiry, not an indefinite one.
- A proper investigation needs the system's own access logs, not a colleague's recollection. Logs establish scope; memory only establishes that something happened.
- You do not need to be physically present to run a proper breach response. Clear instructions, a documented process, and remote coordination with staff on site can resolve a file just as effectively.
- A prompt, specific, and honest notification to affected clients tends to produce fewer complaints than a delayed or vague one. Clients respond better to being told plainly than to finding out later.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.