Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Digital health & life sciences

Privacy & Security for Health Charities & Patient Organizations

A health charity or patient organization runs two data regimes under one roof: a donor file mostly outside PIPEDA, and a program side, helplines, peer support, registries, that can make the organization a health information custodian. Privacy Horizon builds a program that keeps both halves straight, sized for a five-to-two-hundred-person team where volunteers do much of the sensitive work. Work usually starts after a vendor breach notice, a funder's clause, or a new registry needing consent.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

We work with Canadian disease charities, hospital foundations and patient organizations running peer support, helplines, navigation or registries alongside fundraising. Staff typically number five to two hundred, with volunteers handling much of the caller contact.

Our contacts are the Executive Director, a VP of Finance & Operations who inherited IT, a Director of Development who owns the donor CRM, and a Director of Programs who owns the health side. Larger organizations add a Director of IT; foundations often see a board member call after an incident.

Hospital foundations sit in a particular spot: they raise money for a hospital they do not operate, and sometimes receive limited patient contact information from that hospital, a flow with its own statutory conditions. Disease charities and patient groups instead build health data directly from participants through registries and consented programs.

General charities and foundations without a patient-facing program, and companies that sell software or clinical services into healthcare, are served elsewhere. Here the defining fact is a health-condition data set built through direct service or research participation, sitting beside, not inside, the donor file.

Group of volunteers in community donation center, food bank and coronavirus concept

Services

Privacy & security services for health charities & patient organizations

Each service below is scoped for how health charities & patient organizations actually operate — their systems, their regulators and the reviews they face.

What you hold

What a health charity's program actually has to cover

A donor file and a program file rarely share an owner, a system or a risk profile, so the safeguards each one needs have to be scoped separately before anyone can call the organization covered.

The donor CRM and its exports

Constituent records, giving history, wealth-screening notes and payment tokens sit in Raiser's Edge NXT, Salesforce Nonprofit Cloud, DonorPerfect, Keela or CanadaHelps, plus every spreadsheet extract anyone pulled from it.

Helpline and peer-support intake

Callers describe diagnoses, treatment decisions and family situations to volunteers who take notes by hand or in a shared inbox, often with no case-management tool built for the purpose.

Patient registry records

Some organizations run registries collecting diagnosis, treatment history or genetic information under participant consent, frequently in a REDCap-type tool, feeding research partners under data-sharing agreements.

Volunteer files and vulnerable-sector checks

Police check results and emergency contacts for the volunteers who staff helplines and support groups need the same locked storage and retention limits as employee files, even without an employment contract.

Payment and event platforms

iATS, Stripe and peer-to-peer event tools each hold card data or tokens for a season, and each is a separate surface a skimming attempt or misconfiguration can expose.

Hospital-foundation contact feeds

Where a hospital shares limited patient contact information with its foundation for fundraising, that feed needs the same access controls and audit trail as anything else PHIPA reaches.

Regulatory map

Which regime governs which half of your organization

The donor side and the program side answer to different tests, and most of the confusion in this sector comes from applying one regime's logic to the other's data.

PIPEDA's non-commercial carve-out for fundraising

The OPC treats core fundraising activity as generally outside PIPEDA, but selling, bartering or leasing a donor or membership list is commercial activity and pulls the Act back in for that dealing.

Read our guide →

Custodian status turns on what you actually do

A charity that itself delivers care, some CMHA branches, hospices and community health programs among them, becomes a health information custodian under PHIPA, with duties the fundraising office never carries.

Read our guide →

The hospital-foundation fundraising flow

PHIPA's fundraising provision and its regulation let a hospital hand a foundation limited patient contact details for solicitation, subject to conditions and a mandatory opt-out, a pathway unique to institutionally linked charities.

Read our guide →

Consent governs registries where custodian status does not apply

A registry built directly from participants runs on intake consent and the applicable statute, and where records feed research, TCPS 2 and REB review shape the data-sharing agreement.

Primary source →

CASL's charity fundraising exemption

A commercial message sent by or on behalf of a registered charity is exempt from CASL's consent rules when raising funds is its primary purpose, though other messages still need consent.

Primary source →

PHIPA penalties now have teeth

Ontario's Information and Privacy Commissioner can issue administrative monetary penalties reaching fifty thousand dollars for an individual and five hundred thousand for an organization for PHIPA contraventions, a live risk for any custodian-status charity.

Primary source →

What goes wrong

How incidents actually happen in this sector

The Canadian sector's clearest incident pattern is a vendor failure rather than a direct attack on any single charity, though smaller, everyday lapses cause just as much damage.

  • A fundraising-platform vendor gets ransomed

    Blackbaud's 2020 ransomware incident touched CAMH, Western and, by sector reporting, roughly two dozen Canadian organizations, and Sunnybrook Foundation had to notify donors whose names, addresses and donation details were exposed.

    Source →

  • Gift-redirection fraud around campaign season

    Business email compromise targeting finance or development staff tends to cluster around major campaigns, when a fraudulent banking-change request is more likely to slip past a rushed approval.

  • Shared CRM logins with no MFA

    Small development teams often share one login across staff and volunteers, the same credential-hygiene gap that recent OPC findings on an unrelated consumer platform described as a recurring failure mode.

    Source →

  • Helpline notes leaking outside the system

    A volunteer forwarding a caller's story to a personal email, or keeping notes in an unlocked spreadsheet, turns a confidential conversation into an exposed record with no audit trail.

  • Registry extracts sent without the promised de-identification

    A research partner receiving what was meant to be an anonymized extract, but was not quite, breaks both the consent participants gave and the data-sharing agreement that authorized the transfer.

  • Skimming on the donation page

    A compromised script on a donation form can capture card details before a payment processor like iATS or Stripe ever sees them, a risk that grows with every plugin added to the page.

When organisations call us

The moments this sector actually calls us

Purchases rarely happen on schedule. A specific event puts privacy or security on the agenda, and the resulting work gets planned around the giving calendar.

  • A vendor breach notice names your organization

    A CRM or platform provider reports an incident, and someone has to work out within days what your organization owes its own donors, separate from the vendor's own response.

  • A funder or hospital partner adds conditions

    A grant agreement or hospital-partnership renewal arrives with security or privacy clauses attached, and the program office needs an honest answer before signing.

  • Launching or migrating a patient registry

    Standing up a new registry, or moving one off spreadsheets into a proper tool, is the one chance to build consent and access controls in from the outset.

  • A cyber-insurance renewal gets specific

    Underwriters now ask about MFA, endpoint detection and a written incident response plan by name, and a blank answer can shrink coverage or raise premiums.

  • Giving Tuesday and December hardening

    Traffic and transaction volume on the donation stack peaks in late fall, and organizations want defenses checked before, not during, the busiest weeks of the year.

  • A board asks what happens if we're next

    Once a director reads about a peer organization's vendor breach, the board wants a straight answer about exposure and response before its next meeting.

Health Charities & Patient Organizations: privacy & security questions, answered

Usually not for the core of what you do. The OPC treats donations, newsletters and fundraising as non-commercial, so PIPEDA typically does not reach your donor file. That changes once you sell, barter or lease a donor or membership list, which is commercial activity carrying the Act's consent, safeguard and breach-reporting duties. Paid courses or merchandise can tip you into commercial territory too.

It showed that one fundraising-platform vendor's failure becomes every client's problem at once. Canadian hospital foundations, Sunnybrook's among them, had to notify their own donors about names, addresses and donation details exposed in the vendor's systems, on a timeline they did not control. The vendor was later charged by the SEC over its disclosures.

Only if your organization actually delivers health care, which some community programs, hospices and CMHA-type branches do and most disease charities and standalone helplines do not. If you are not a custodian, the helpline data is still governed by the consent you gave callers and the applicable statute, just not PHIPA's custodian rules.

Most organizations at this stage start with Minimum Viable Privacy or a Virtual Privacy Officer engagement, because the first task is almost always working out which laws apply to your donor file versus your program data. Once that answer exists, policy, training and technical work follow in sensible order instead of guessing at everything at once.

Yes, a confidentiality undertaking separate from any employment paperwork, because volunteers usually field the most sensitive health conversations your organization has. It should cover what they can discuss outside the call, how notes get stored, and what happens if they suspect a caller is at risk, alongside the vulnerable-sector screening most programs require.

A hospital foundation can lawfully receive limited patient contact information from the hospital it supports, under PHIPA's fundraising provision and a required opt-out, a pathway no standalone charity has. A disease charity instead builds its own health data through a registry or program a participant joins directly, putting it under consent and the private-sector statute.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.