“LifeLabs exposed British Columbians, along with millions of other Canadians, to potential identity theft, financial loss and reputational harm,” B.C. information and privacy commissioner Michael McEvoy said in a statement regarding a joint investigation into a breach last year at the laboratory-testing company. (CBC News)
Talking point: LifeLabs revealed last December that hackers had gained access to the personal information of up to 15 million customers in Ontario and B.C. that fall, and that the company was forced to pay a ransom to retrieve and secure the data. The privacy commissioners of both provinces have instructed LifeLabs to strengthen its security policies, finding that it collected more personal information than “reasonably necessary.” The company has reportedly started to do that by hiring a chief privacy officer and chief information officer; it has also hired Deloitte Canada to evaluate its response to the ransomware cyberattack. In their statements, the commissioners said the publication of their full report was being delayed by the company’s claim that the information provided to them for the investigation was confidential. “This investigation also reinforces the need for changes to B.C.’s laws that allow regulators to consider imposing financial penalties on companies that violate people’s privacy rights,” McEvoy said.