The Bluewater Health breach: What they aren’t telling you

In Nathan’s latest column, he breaks down the media release from Bluewater Health concerning the 2023 cyberattack, contrasting the hospital’s reassuring public statements with an official investigator’s report that reveals significant security failures and legal non-compliance.

Following up on last week’s column on “copaganda,” we turn our lens from the police to another public institution: the hospital. On June 18, 2025, an email from Bluewater Health was sent out. It contained a media release, issued on behalf of five regional hospitals, announcing the conclusion of the Information and Privacy Commissioner's (IPC) investigation into the 2023 cyberattack.

The email’s tone is confident, the joint media release reassuring. But also attached was the IPC’s full 35-page report. Placing the hospitals' public statements next to the investigator's findings reveals a masterclass in narrative control—a story told by carefully omitting the most damning parts.

The hospital’s communications team frames the report’s conclusion as a victory lap, leading with the positives to suggest the ordeal is successfully behind them. The joint statement from the hospitals says they are:

“specifically pleased that the IPC has acknowledged the efforts by the hospitals and TransForm Shared Service Organization to contain the breach after it occurred, as well as improvements made in our data and information protections.”

They cap it off by stating:

“The IPC’s decision concludes the IPC’s investigation – determining no formal review or orders are required.”

This sounds like an exoneration. But the report gives a very different reason for why it’s not escalating the matter. It’s not a clean bill of health; it's a probationary pass. The report states a formal review is not warranted:

“based on the remediation steps already taken and the custodians' commitments to make further improvements.”

The story isn't "you did nothing wrong." It's "you've started fixing what was broken, so we'll stop here."

The report also identified two distinct privacy breaches: one where patient data was stolen and another where it was maliciously encrypted and made inaccessible. The hospitals only notified patients about the stolen data. The IPC found this was a failure of their legal duty, but you wouldn’t know it from the press release, which offers a breathtakingly soft interpretation of the investigator's actual finding.

The hospitals' release says:

“We acknowledge that the IPC has noted concern surrounding the notification of individuals whose data was encrypted by the threat actors.”

The IPC wasn’t just concerned; it determined the hospitals failed to comply with the law. The report states:

“Therefore, I find that the custodians did not notify in compliance with section 12(2) of the Act.”

The investigator is even more direct, stating the hospitals did not notify patients about the encryption:

“which they were required to do.”

The hospitals’ statement transforms a finding of legal non-compliance into a minor footnote.

Finally, the hospitals’ release frames the entire event as an attack by a villain from the outside, painting the institution as a simple victim. They call it a:

“criminal ransomware cyberattack which impacted health records and information systems.”

This narrative of external criminality conveniently omits the internal failure that left the door wide open.

The investigator identified a clear and preventable vulnerability. The report found the threat actor got in by:

“leveraging three compromised administrator accounts.”

Critically:

“At the time of the attack, the three administrator accounts used to infiltrate the TSSO network were not equipped with multi-factor authentication (MFA).”

The report concludes this was:

“likely a contributing factor in how their credentials were compromised in the first place.”

What’s missing from the hospital’s story is the unlocked door. This wasn't just a break-in; it was a preventable breach made possible by a basic security failure.

The question, as always, is who these communications are designed to protect. The release soothes public anxiety and defends the institution’s reputation. But by omitting the findings of legal failure and the root cause of the crisis, it withholds the full truth from the public.

Report a mistake

Tell us what needs correcting in this article.

Events

View all events →