
PHIPA governs how Ontario health information custodians and their agents collect, use and disclose personal health information, and it gives patients the right to see and correct their records. If you run or manage a clinic, hospital department or care practice, your three priorities right now are: limit what you collect, protect what you hold and be ready to respond to a breach within hours, not days. Start by naming a privacy contact, checking that your breach protocol actually works and reviewing your riskiest vendor contracts.
TL;DR:
- Ontario health providers must regularly review intake forms, minimize unnecessary data collection, and apply de-identification to reduce privacy risks.
- Organizations should establish and test breach response protocols, ensure vendor contracts include audit rights and breach notification clauses, and maintain clear documentation.
- Medical practices need to assign a privacy contact, create a public privacy statement, and conduct privacy impact assessments especially for AI and digital health tools.
- Technical safeguards like encryption, role-based access, logging, and multi-factor authentication are essential to meet PHIPA’s reasonable steps requirement.
- Outourcing certain services does not transfer PHIPA accountability, so contracts must clearly define vendors’ privacy obligations and support ongoing compliance efforts.
PHIPA applies to “health information custodians”, a term that covers physicians, nurse practitioners, hospitals, long-term care homes, pharmacies, labs and most other providers who handle personal health information as part of delivering care. The Personal Health Information Protection Act sets out this definition, along with the related categories of “agent” and “health information network provider” (HINP).
An agent acts on a custodian’s behalf, such as an employee or contracted biller, and the custodian stays accountable for what that agent does with the information. A HINP provides services that let two or more custodians share an electronic health record system, which adds a layer of technical responsibility without shifting legal custody.
Inside a shared EHR or multi-provider clinic, these roles often blur. A few checks keep responsibilities clear:
PHIPA’s limiting principles require custodians to collect, use and disclose personal health information only to the extent necessary for the identified purpose, generally for providing or assisting in care. This “limiting” rule, set out in the statute itself, is the backbone of day-to-day compliance and the one most organizations quietly violate through outdated intake forms and overly broad data fields.
Consent is the second pillar. PHIPA allows implied consent for the direct provision of care within a “circle of care,” but express consent is required for most disclosures outside that circle, such as to an employer or insurer. A small number of exceptions exist, including public health reporting and certain law enforcement requests, and these should be documented rather than assumed.
In practice, tightening collection and consent comes down to a short sequence of changes:
Pro Tip: Review your intake forms once a year as if you were a stranger filling them in: anything you can’t explain the clinical reason for probably shouldn’t be there.
De-identification deserves particular attention because it is one of the few controls that removes risk rather than just managing it. A patient satisfaction survey, for instance, rarely needs a name or health card number attached once it leaves the clinical record. Building that separation into your systems now avoids a harder conversation later when the Information and Privacy Commissioner of Ontario asks why a field existed at all.
Patients have the right to request access to their own record and to ask for corrections when information is inaccurate or incomplete. PHIPA sets a response timeline of 30 days, with a permitted extension of up to 30 additional days if the custodian provides written notice explaining the delay.
Every custodian must also make a written public statement available describing its information practices: what is collected, how it’s used, how to reach the privacy contact and how to make an access or correction request. The PHIPA statute requires this transparency measure, and many organizations post it on their website or in waiting areas alongside a sample from the Ontario government’s own information practices statement.
A workable process for handling these requests looks like this:
Getting this right protects patients and gives you a clean paper trail if the IPC ever asks how a request was handled.
PHIPA requires custodians to take reasonable steps to protect personal health information against theft, loss and unauthorized use or disclosure, and to retain, transfer and dispose of records securely, as set out under section 12 of the statute. “Reasonable” is deliberately flexible: a solo practitioner and a 200-bed hospital will implement it differently, but both need to show deliberate, documented effort.
Administrative controls come first: written privacy policies, mandatory privacy training for every employee and contractor, and signed confidentiality agreements before anyone touches a record. Technical controls follow: encryption of data at rest and in transit, multifactor authentication on every account with PHI access, role-based access so staff see only what their job requires, and logging that lets you reconstruct who accessed what and when.
The IPC has found that failures to maintain basic privacy practices, audits and information-practice statements have led to formal findings against custodians, underscoring that “reasonable” is measured against what a prudent organization would have had in place, according to IPC case decisions.
When a breach happens, PHIPA requires custodians to notify affected individuals and, in prescribed circumstances, the Information and Privacy Commissioner of Ontario. Ontario Regulation 329/04 sets the specific criteria that trigger mandatory reporting, and the IPC’s own guidance describes the standard as notifying “at the first reasonable opportunity” rather than after an internal investigation drags on, as explained in its breach reporting guidance.
A workable response sequence looks like this:
Custodians also submit an annual statistical report of privacy breaches to the IPC by March 1 covering the previous calendar year, separate from individual incident notifications. Cooperation with any IPC investigation that follows, including providing requested documentation promptly, tends to influence how a matter is resolved.
Pro Tip: Write your breach protocol to cover the mundane cases, a misdirected fax or a lost phone, not just a worst-case ransomware scenario: most real incidents are the boring ones.
Handing IT, billing or transcription work to a third party does not transfer your legal accountability under PHIPA. Custodians remain responsible for personal health information even when an agent or vendor processes it on their behalf, a point the IPC has reinforced in published case guidance on third-party providers.
That means contracts matter as much as technology. Before signing with any vendor that will touch PHI, insist on clauses covering privacy obligations, breach notification timelines, audit rights and clear terms on data handling and residency.
Our overview of IT compliance requirements for technology vendors in Ontario walk through what these clauses typically look like in practice.
AI scribes and similar tools that transcribe or summarize clinical conversations introduce a new layer of PHIPA risk, and the IPC addressed it directly in its 2026 guidance, “AI Scribes: Key Considerations for the Health Sector”. The guidance treats privacy compliance as ongoing: procuring an AI system does not end your custody obligations, it starts a monitoring responsibility that continues for as long as the tool is in use.
Data residency claims deserve scrutiny beyond the marketing page. Even a vendor advertising Canadian hosting can route real-time audio or video through foreign relay servers during a call, a technical detail that can create cross-border transit most procurement teams never check.
Before deploying any AI scribe or similar tool, run a privacy impact assessment and a threat and risk assessment specifically scoped to that technology. A general resource on AI governance policy for employees is a useful companion for building internal rules alongside vendor due diligence, and background reading on secure transcription and PHI handling covers some of the technical tradeoffs involved.
Pro Tip: Ask your AI vendor to show you, not just tell you, where voice data travels during a session: a network diagram beats a privacy page every time.
Closing the gaps PHIPA expects doesn’t require a massive overhaul, but it does require sequencing. A practical rollout over 90 days looks like this:
| Phase | Focus | Outcome |
|---|---|---|
| Weeks 1 to 4 | Governance and inventory | Privacy contact named, public statement published, systems mapped |
| Weeks 5 to 9 | Technical controls | PIAs completed, encryption and access controls in place |
| Weeks 10 to 12 | Readiness and contracts | Breach protocol tested, vendor contracts reviewed, staff trained |
The underlying technical steps, encryption, multifactor authentication, logging, backups and device controls, are the same ones that get scrutinized in an IPC decision after an incident. Our PIPEDA compliance checklist covers complementary data-protection steps worth running alongside this roadmap.
A Kitchener-Waterloo organization working through overdue PHIPA gaps followed a similar 90-day path: naming a privacy contact, mapping vendor access, and closing technical gaps in sequence rather than all at once.
The full 90-day compliance project shows how the phased approach translates into a repeatable plan, whether handled internally or with an outside IT partner.
PHIPA gives the Information and Privacy Commissioner of Ontario authority to investigate complaints, issue orders and, in serious cases, refer matters for prosecution. The statute also provides for administrative monetary penalties, a financial consequence intended to be faster and more proportionate than a court prosecution for certain violations.
The IPC’s own decisions show that enforcement is measured against reasonableness rather than perfection. Custodians that lacked basic privacy practices, had never conducted an internal audit, or had no information-practices statement in place have faced formal findings, as documented in published IPC decisions. The pattern across these cases is consistent: organizations that could show a documented privacy impact assessment, a tested breach protocol and evidence of staff training fared better than those that could only point to good intentions.
This is worth internalizing because it reframes compliance from a legal checkbox into an operational habit. The IPC isn’t looking for flawless systems, it’s looking for evidence that an organization took its obligations seriously before something went wrong. A privacy impact assessment paired with remediation evidence is one of the stronger practical defences available when a new system or an incident draws scrutiny, as the IPC’s own PIA guidance outlines.
For smaller clinics and practices without a dedicated privacy officer, the gap between “we meant to do this” and “we can show we did this” is usually where an administrative penalty risk lives. Closing that gap costs far less than the penalty, the reputational damage, or the time spent responding to an investigation after the fact.

Most PHIPA gaps come from a handful of recurring patterns rather than exotic failures.
Over-collection is the most common. Intake forms accumulate fields over years of staff changes and system migrations, and nobody revisits whether each field is still necessary. The fix is the periodic audit described earlier: if a field’s clinical purpose can’t be stated in one sentence, it probably shouldn’t be there.
Weak breach readiness is the second. Many organizations have a breach policy document that nobody has actually tested. When ransomware encrypts PHI and makes it inaccessible, that counts as an unauthorized use or disclosure under PHIPA and can trigger notification duties even when no data was copied out, a point the IPC has confirmed in a ransomware decision. A protocol that only exists on paper fails exactly when it’s needed most.
Vendor blind spots are the third. Clinics often assume that once IT or billing is outsourced, the vendor carries the privacy risk. It doesn’t work that way: the custodian stays accountable, and a vendor’s security failure becomes the clinic’s reporting obligation.
Finally, inconsistent access controls, especially in multi-provider clinics where staff turnover is high, leave old accounts active long after someone has left. A quarterly access review closes this gap cheaply and catches problems before an audit does.
Electronic health records don’t operate under a separate set of rules from paper records, but PHIPA’s requirements translate into specific technical expectations once information moves online. Role-based access control becomes essential in a shared EHR, since multiple providers may touch the same record and each should see only what their role requires.
Audit logging is non-negotiable for digital systems because it’s the only practical way to answer the question every breach investigation eventually asks: who accessed this record, and when. Encryption, both at rest and in transit, protects records moving between providers, labs and pharmacies, a baseline expectation under the security requirements of section 12 of PHIPA.

HINPs, the entities that provide the technical infrastructure behind shared EHR systems, carry specific obligations around security and must support the custodians using their platform in meeting their own PHIPA duties. Any custodian relying on a HINP should confirm in writing what that support actually includes rather than assuming it covers everything.
Backup and disaster recovery planning matters just as much as access control. A ransomware event that encrypts a patient record system doesn’t just threaten data loss, it threatens continuity of care, which is why tested backups sit alongside encryption and access logging as core technical safeguards for any digital health system.
If you’re triaging where to start, fix breach readiness first: an untested protocol is the gap most likely to turn a small incident into a reportable one. Run a privacy impact assessment on your highest-risk system next, and audit vendor contracts before you audit anything else internal. The IPC’s guidance is free and current; use it before paying for anything else.
— Geeshan
Start with the PHIPA statute itself and Regulation 329/04 for reporting thresholds. The IPC publishes practical guidance on breach response, AI scribes and reporting breaches, plus published decisions covering real enforcement cases.
PHIPA compliance touches privacy policy, technical controls and vendor management all at once, and most clinics don’t have a full-time team dedicated to any of the three. An experienced managed IT provider can help small and mid-sized organizations across Ontario by putting encryption, multifactor authentication, access logging and backup systems in place as part of a managed IT setup, supported by a certified team and a 24/7 network operations center. That means having a unified approach to handling security, monitoring and Microsoft 365 management instead of juggling separate vendors and separate contracts for each piece.
Our cyber security and anti-virus services, including managed EDR and 24/7 SOC monitoring, support the technical safeguards covered throughout this guide, and our cloud backup and disaster recovery offering supports the containment and continuity side of breach response. If you want a straightforward look at what closing your PHIPA gaps would involve, get in touch through our managed IT services page to start the conversation.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
PHIPA, the Personal Health Information Protection Act, is Ontario’s health privacy law. It governs how health information custodians such as physicians, hospitals and clinics collect, use and disclose personal health information, and it gives patients rights to access and correct their records.
Compliance starts with naming a privacy contact, publishing a written public statement of your information practices, and limiting data collection to what’s necessary for care. From there, implement technical safeguards like encryption and multifactor authentication, test your breach response protocol, and confirm vendor contracts include audit and notification clauses, steps outlined in the IPC’s breach response guidance.
PIPEDA is Canada’s federal private-sector privacy law and generally applies where no substantially similar provincial law exists. PHIPA is Ontario-specific and governs personal health information handled by health information custodians, taking precedence over PIPEDA for that category of information within the province.
Custodians must report certain privacy breaches to the Information and Privacy Commissioner of Ontario at the first reasonable opportunity, based on criteria set out in Ontario Regulation 329/04. Custodians also file an annual statistical report of privacy breaches by March 1 each year covering the prior calendar year.
No. Custodians remain legally accountable for personal health information even when an agent, vendor or IT provider processes it on their behalf, a point the IPC has confirmed in published case guidance. Contracts with clear privacy, audit and breach notification clauses are the main tool for managing that risk.