Log In

Reset Password

‘Extremely concerning’ lack of control over Covid travel data

Large amounts of personal data was collected on behalf of the Bermuda Government through travel authorisation forms (File image)

A parliamentary committee has said that the health ministry could not confirm whether personal data provided for Covid-19 travel authorisations was taken by hackers in the September 2023 cyberattack that crippled government computer systems.

In a report presented to the House of Assembly on Friday, the group said an immediate remedy was needed to address the lack of clarity surrounding the issue.

The public accounts committee paper said that a “significant amount” of information was retained by the Government, but the Ministry of Health could not say how many people were listed in the records or who may have downloaded data before the hack.

Some data sets contained more than 200,000 entries but individuals may have been included multiple times, the report said.

The paper made seven recommendations, including that clear guidelines are provided for the use, retention and destruction of personal travel and health data received from resPartner — a company that was awarded three government contracts from 2020 to 2023 for portals that covered Covid-19 testing as well as authorisations used for visitors to the island and returning residents.

A government spokeswoman said yesterday that the findings were under review and highlighted that decisions taken “at pace and under extraordinary conditions” were made with the aim of protecting the community.

Denis Pitcher, the owner of resPartner, told The Royal Gazette that his company always took seriously the issue of data protection and followed government instructions on retention and deletion.

He added: “We confirm that all Covid-19-related personal information was deleted from our systems in advance of the transfer of data to the Government on April 11, 2023, and we are happy to provide formal written confirmation to that effect.”

The Report of the Parliamentary Standing Committee of the Public Accounts on:Compliance with Procurement Rules, Financial Instructions, Governance and Value for Money of Covid-19 Travel Authorisation Procurement and Operation came after a series of meetings on the topic held up until this month.

“Large amounts of personal data for Bermudians and travellers to Bermuda was [sic] collected by resPartner on behalf of the Government of Bermuda and ultimately provided to the Government,” it said.

“While resPartner indicates this data was deleted from resPartner systems, Government still retains a significant amount of the personal data and was unable to determine if it was accessed by hackers during the September 2023 cyberattack.”

Douglas De Couto, the One Bermuda Alliance MP and shadow finance minister, was the committee’s chairman and was joined by fellow OBA parliamentarians Vance Campbell and Ben Smith, as well as Progressive Labour Party legislators Curtis Dickinson, Renée Ming, Scott Simmons and Neville Tyrrell.

Their findings were presented in the House on the same day as a joint select committee report about the 2023 cyberattack on the Government, which said sources confirmed that personal data was compromised in that incident but provided little detail on what types of information or to whom it belonged.

The parliamentary standing committee paper said: “The Ministry of Health could not provide a definite answer on how many records were retained from the resPartner data.

“Some data folders were unable to be searched due to access controls.

“In addition, various Ministry of Health stakeholders were given the opportunity to download data for their specific purposes prior to deletion, but the ministry could not determine who downloaded what data at the time.

“For example, the accounts department used data extracts to confirm the number of people tested and the number of vaccine records created in the system.

“The ministry could not identify how many people are listed in the records, but noted that some data sets have over 200,000 entries and individuals may be listed multiple times.

“This data includes residents as well as visitors, including cruise ship passengers.

“The records contain different types of information. In some excerpts, only names, gender, date of birth and test results were retained, while others contain most or all of the original information including phone numbers, e-mail addresses, race, employer and occupation.”

It added: “The ministry could not confirm whether any of this data had been accessed by the cyberattack on the Government of Bermuda.

“Both resPartner and the Ministry of Health provided verbal assurance that resPartner had deleted all of the personal data from the resPartner systems, but no written certificate or confirmation could be provided.”

The report said: “The lack of clarity and control of the personal and sensitive data received by Government from resPartner is extremely concerning and should be remediated immediately.”

One of its recommendations was to “provide clear guidelines for the use of, retention of and destruction of the personal travel and health data Government received from resPartner” as if the Personal Information and Protection Act 2016, which became fully operational on January 1, 2025, had been in effect at that time.

The cover of the Auditor-General's report, Government of Bermuda's Response to Covid-19: Travel Authorisation (File image)

The committee’s investigation into the Government’s procurement and operation of the travel authorisation system with resPartner, which operated the resQwest brand, was launched in the wake of a March 2023 report by the Auditor-General.

Heather Thomas’s paper said then that there were “multiple violations” of law and the Code of Practice for Project Management and Procurement in the “awarding, development, implementation and operation of the electronic travel authorisation portal and the processing and collection of revenues generated by the use of this facility”.

David Burt claimed at the time that his initial review of the Auditor-General’s report was that it showed “a number of factual errors and incorrect inferences which could have easily been clarified” if Ms Thomas’s office had contacted the Government ahead of publication.

Premier’s assertion to MPs

David Burt told the House of Assembly in the early hours of Saturday that he wanted to correct an error in the public accounts committee’s report, which said that he signed a contract with BPMS that duplicated the travel authorisation system and provided a $2.5 million guarantee.

During the motion to adjourn, the Premier said: “That statement is false.

“I signed a service agreement that had no financial commitment at all. That agreement contained no guarantee, created no obligation for the Government to pay any funding and did not make the Government a guarantor of that loan.”

He added: “The $2.5 million guarantee was in a separate legal instrument relating to a loan made to InnoFund. It was executed approximately ten months later by the then Minister of Finance.

“The contemporaneous e-mails, the financial records and the parliamentary record all established that fact.”

Mr Burt added that government records showed a subsequent contract was “executed by the appropriate public officer”.

“These are not differences of opinion,” he said. “They are different documents, different dates, different legal obligations and different signatories.”

The Premier said that he planned to file a formal response supported by documentary evidence “to request that the parliamentary record be corrected”.

He added: “I rose two years ago when the [other] report was first written by the Auditor-General and said that it was factually incorrect.

“That is the record of this House.

“Then we get the same factual incorrectness repeated by a public accounts committee.”

The parliamentary committee’s report said that there were “material failures in following Government’s procurement regulations and financial instructions”.

It noted that fees from travellers for authorisation to enter the country were paid to resPartner rather than directly into the Government’s consolidated fund, “in contravention of the Constitution”.

“Even considering the initial emergency conditions, and operational issues preventing these direct payments, funds were still received directly by resPartner for 14 months after the underlying issues were resolved,” the report said.

It added: “Failures by the Government to follow its own processes and best practices in a clear and timely manner, including negotiations, led to a worse financial outcome for the Government in subsequent travel authorisation contracts.”

Other recommendations included the establishment of detailed, standardised procedures for procurement in emergency situations, and the continued improvement of education and training for all public officers in contract, procurement and financial instructions.

resPartner supports committee recommendations

Denis Pitcher, the owner of resPartner, said that the public accounts committee report documented “a number of significant issues with government procurement, contract approvals and financial controls during the Covid-19 response”.

He added: “As the report itself notes, ‘Approval delays left Bermuda's critical testing portal and [travel authorisation] system in a contractual limbo and could have left the island without either of these systems functioning except for goodwill by the vendors … ‘

“Despite these challenges, resPartner successfully delivered and maintained the travel authorisation, testing portal and vaccination management systems that enabled Bermuda to safely reopen and manage the pandemic.

“The report’s timeline documents our proactive engagement, including early requests for payment processing information prior to the launch of the travel authorisation system and prompt follow-ups on data handling after the program ended.”

Mr Pitcher said: “We support the committee’s recommendations for improved emergency preparedness going forward.”

A government spokeswoman said yesterday that the committee’s findings and recommendations were being “carefully” reviewed, with a full response to follow.

She added: “The Covid-19 pandemic presented governments around the world with an unprecedented public health emergency that required urgent decisions to protect lives, safeguard the healthcare system and respond to rapidly evolving circumstances.

“In that environment, the overriding priority was to act swiftly in the interests of public safety.

“While some decisions were necessarily taken at pace and under extraordinary conditions, they were made with the objective of protecting the community during an unprecedented crisis.

“The Government nevertheless recognises the importance of accountability and continuous improvement.

“It welcomes the opportunity to examine what worked well, where processes and procedures can be strengthened, and what lessons can be learned to ensure the country is even better prepared to respond to future public health emergencies.”

Payments to vendor

Records earlier released to The Royal Gazette through public access to information showed that resPartner, founded and owned by Denis Pitcher, a former fintech adviser — latterly unpaid — to the Premier, would be paid $2.4 million in the 2021-22 financial year.

The company was paid $1.2 million in the previous financial year.

Those payments broke down as $2 million for a Covid-19 test booking system, $1.3 million for the travel authorisation web portal and $300,000 for vaccine appointments software.

Travel authorisations incurred a fee of $75 from July 2020, later cut to $40.

Kim Wilson, the health minister, told Parliament in November 2020 that the travel authorisation contract was not put out to tender, in breach of the Government’s procurement rules, because the work had to be done before the island’s borders reopened.

Dr De Couto said yesterday: “While Covid-19 is several years behind us, the passage of time has allowed the committee to assess how government processes and capabilities have changed since then, and provide a view on what steps the Government can make to continue to improve.

“While the public accounts committee’s work was completely separate from the work of the joint select committee on the cyberattack, I believe there are some important shared themes, particularly around the government handling of Bermudians’ personal data.

“As the Government moves more of the country’s services online and relies more on digital systems, this data must be handled carefully.

“This includes full compliance with the Pipa so that Bermudians can use these services with confidence.”

To view the committee’s report and the Auditor-General’s 2023 report, see Related Media

Royal Gazette has implemented platform upgrades, requiring users to utilize their Royal Gazette Account Login to comment on Disqus for enhanced security. To create an account, click here.

You must be Registered or to post comment or to vote.

Published July 20, 2026 at 7:30 am (Updated July 20, 2026 at 6:03 am)

‘Extremely concerning’ lack of control over Covid travel data

Users agree to adhere to our Online User Conduct for commenting and user who violate the Terms of Service will be banned.