Rogue Employee, Repeat Snooping — Privacy Breach Findings Against eHealth Saskatchewan and Medical Clinic

eHealth Saskatchewan (Re), 2026 CanLII 33026 and 33028 (SK IPC)
Saskatchewan Information and Privacy Commissioner — April 8, 2026

A former eHealth employee, later hired by a private medical clinic, snooped on the personal health information of nearly 30 people across two separate employment periods – while facing criminal fraud charges. In eHealth Saskatchewan (Re), 2026 CanLII 33026 and 33028 (SK IPC), the Saskatchewan Information and Privacy Commissioner found breaches of the Health Information Protection Act (HIPA) but also found that both eHealth and the clinic had reasonable safeguards in place. The case raises important questions about what more can be done when a determined rogue employee circumvents privacy controls.

Background

Danniela Morgan was hired by eHealth Saskatchewan in November 2020 as a Registry Administrator, with access to major health databases including Panorama, the Panorama COVID Quick Entry system, and the Shared Client Index (SCI) Enterprise Viewer. Her access was terminated when she left eHealth in October 2021.

In September 2024, Morgan was charged criminally with fraud and identity theft offences. Days later, in October 2024, she was hired by Dr. Yang Zhan at the Regina Cardiology Clinic as a Medical Office Assistant, gaining access to eHealth’s web-based eHR Viewer. Between October 2024 and April 2025, Morgan accessed the personal health information of 23 individuals without any legitimate need-to-know. She left Dr. Zhan’s employ in February 2025, but her access was not revoked until an affected individual complained in April 2025.

eHealth’s own investigation also discovered that during her earlier 2020–2021 employment, Morgan had snooped on the records of 6 additional individuals.

The Decision

The Commissioner found privacy breaches occurred in both periods, characterizing Morgan as a “rogue employee” whose wilful, unauthorized access defeated safeguards that were otherwise reasonable. Neither eHealth nor Dr. Zhan were found to have inadequate safeguards—the breach was the product of intentional misconduct rather than systemic failure.

The Commissioner’s recommendations included: requiring signed SCI account request forms, implementing ongoing proactive audit and monitoring programs, updating user access recertification policies, banning Morgan from future access to eHealth systems, requiring Dr. Zhan to implement written policies on annual privacy training, routine audits, and timely revocation of access on termination, and offering affected individuals credit monitoring for a minimum of five years. The matter was also referred to the Attorney General of Saskatchewan for a prosecution opinion regarding Morgan’s wilful violation of HIPA.

Key Takeaway

Even where an employer has reasonable privacy safeguards in place, a determined bad actor can circumvent them. The lesson is not that the safeguards failed, but that employers must layer their defences: proactive auditing, prompt access revocation on departure, and robust background-check practices (here, Morgan was hired while facing criminal charges). For health-sector employers, this case reinforces the need for timely access revocation, routine proactive monitoring, and clear policies that do not rely solely on employee honesty to protect sensitive health information.

Webinars

Our complimentary webinars address the practical and legal issues for Canadian employers.

View our Webinars