
Saskatchewan’s information and privacy commissioner investigated two distinct kinds of unauthorized access disclosed in 2024: Saskatoon police members viewing restricted investigative records and a pharmacy student examining health files without a professional reason. Both exposed the danger of trusted-user “snooping.”
Police access was supposed to serve a duty
Law-enforcement databases contain sensitive information about victims, witnesses, suspects and officers. Permission to use a system does not authorize an employee to open any record out of curiosity or for personal reasons.
The commissioner’s findings said members accessed material they were not entitled to view.
Credential controls were part of the problem
Any use of another person’s credentials weakens accountability because audit logs may point to the wrong user. Agencies need individual authentication, limits based on assignment and alerts for unusual searches.
Policies alone are insufficient if supervisors do not review logs and enforce consequences.
The pharmacy breach involved 114 people
A fourth-year University of Saskatchewan pharmacy student on a Regina placement accessed personal health information belonging to people outside the student’s care. Another pharmacy worker detected the activity and it was reported.
Some names were recognizable public figures, but fame does not reduce a patient’s privacy rights.
Health records are especially sensitive
Medication histories can reveal diagnoses, reproductive health, mental-health treatment, substance use and other details. Improper viewing can cause humiliation, discrimination and loss of trust even when there is no proof that data were shared further.
Organizations should not wait for identity theft before treating access as a serious breach.
Several institutions shared responsibilities
The pharmacy, university programme, eHealth Saskatchewan and Health Ministry each had roles in access, education, detection, notification or remediation. Placement students need enough information to learn while receiving no broader access than their supervised duties require.
Responsibility cannot disappear between the school, host and system owner.
A complete response follows four steps
Privacy regulators commonly expect organizations to contain a breach, investigate its scope, notify affected people where appropriate and prevent recurrence. Disabling access is only the first task.
Preserving logs and documenting decisions allows independent review of what happened and why.
Training is necessary but not sufficient
Police, health professionals and students receive confidentiality instruction, yet curiosity, personal relationships or misuse can override awareness. Technical restrictions, recurring audits and proportionate discipline provide additional safeguards.
A culture in which colleagues report suspicious access is also protective.
Affected people deserved clarity
Notices should identify what information was viewed, when, by whom in general terms, whether it was copied or disclosed, the measures taken and how to complain. Vague reassurance can deepen mistrust.
The two cases did not show that every Saskatchewan police or pharmacy record was exposed. They did show that insider access is a predictable threat requiring design, monitoring and accountability.
Useful follow-up measures include audit frequency, time to detection, repeat incidents and completion of recommendations. Privacy protection is not merely a promise by trusted professionals; it is a system that can prove each sensitive record was opened for a legitimate reason.
Anyone who suspects improper access can first contact the responsible organization and may complain to Saskatchewan’s privacy commissioner. Prompt questions help preserve logs and establish the relevant time period.



