New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Home & Community Care Agencies
Privacy Horizon builds privacy and security programs for the service provider organizations that deliver nursing, personal support and therapy visits under Ontario Health atHome and Ontario Health Team contracts. The work has to fit a business where personal health information leaves the building by design, riding along on a personal support worker's phone into a client's kitchen. We start wherever the pressure actually lands, a contract renewal, a vendor breach notice, a mobile app rollout, then build outward into a program that holds up against a funding-statute custodian test.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Executive directors, directors of quality and risk, and whoever currently holds the privacy-officer function at SPOs ranging from fifty-person community non-profits to national providers coordinating thousands of mobile care workers across Ontario, Alberta, BC and Quebec.
Agencies renewing or bidding on an Ontario Health atHome or Ontario Health Team contract, where the embedded security schedule now sets a bar that a generic policy binder from a few years ago will not clear.
Organizations rolling out a caregiver mobile app, an AlayaCare-class scheduling and care-management platform, or electronic visit verification, and want the BYOD and field-device controls settled before go-live instead of patched in afterward.
Boards and leadership teams who watched a vendor-origin breach ripple through the province's shared coordination chain and want a documented answer for what happens if their own supply chain is next.

Services
Privacy & security services for home & community care agencies
Each service below is scoped for how home & community care agencies actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Home & Community Care Agencies
A vCISO for home and community care agencies: security leadership for a mobile PSW fleet, SPO contract schedules, and vendor oversight after the OMS breach.
Virtual Privacy Officer
Virtual Privacy Officer for Home & Community Care Agencies
A Virtual Privacy Officer for home care agencies: custodian-vs-agent status under atHome contracts, multi-party breach notification, and March 1 IPC filing.
Penetration Testing
Penetration Testing for Home & Community Care Agencies
Penetration testing for home and community care agencies: caregiver mobile apps, EVV tools, scheduler remote access, and what a SaaS-hosted core allows.
Incident Response Planning
Incident Response Planning for Home & Community Care Agencies
An incident response plan for home and community care agencies: keeping tomorrow's visits running, and coordinating notification across atHome, OHTs, vendors.
Privacy & Security Policy Development
Privacy & Security Policy Development for Home & Community Care Agencies
Privacy and security policies for home care agencies: mobile-device and BYOD rules for PSWs, wound-photo handling, and paper and lockbox-code procedures.
Privacy & Security Training
Privacy & Security Training for Home & Community Care Agencies
Privacy and security training for home care agencies: confidentiality training for PSWs with no licensing college, plus schedulers and field nurses.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Home & Community Care Agencies
Vendor security review for home care agencies: assessing AlayaCare-class platforms, EVV tools, and medical-supply partners after the OMS vendor breach.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Home & Community Care Agencies
AI-PIA for home care agencies: assessing route-optimization AI on patient addresses, acuity prediction on interRAI data, and caregiver documentation assistants.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Home & Community Care Agencies
Minimum Viable Privacy for home care agencies: a $5,499 CAD/year baseline that helps a small community SPO win its first Ontario Health atHome contract.
What you hold
What a home-care privacy and security program has to reach
The environment this program has to cover is unusual: most of the risk sits outside any office, on a device or a kitchen table hundreds of kilometres from head office.
Field devices carrying PHI between visits
Personal or agency-issued phones holding care plans, wound photos, medication lists and lockbox codes, often the personal support worker's own device rather than one the agency configured.
The shared coordination system
Referral and assessment data flowing through CHRIS and the Health Partner Gateway between the agency and Ontario Health atHome, a single system that hundreds of organizations rely on and depend on being governed correctly.
Paper and consent conversations in the home
Visit notes, signature sheets and family discussions happening at a client's kitchen table, a setting no office access-control policy was ever written to cover.
A workforce with no licensing college
Personal support workers are the primary hands-on-data role in the sector, and confidentiality obligations for that role exist only because an employer wrote them down and trained to them.
Vendor and supply-chain access
Equipment suppliers, payroll processors and care-management platform vendors that can become the entry point into patient data even when the agency's own network is well defended.
Worker location and scheduling data
Travel logs, visit-verification records and check-in data that carry their own sensitivity, distinct from the client records the program is usually built to protect first.
Regulatory map
Why custodianship here starts with a funding statute, not a building
The regulatory position for home and community care is set by how a visit gets funded, not by whether the agency owns a facility.
PHIPA custodianship through Connecting Care Act funding
An agency delivering home and community care under Connecting Care Act, 2019 s.21 funding is a health information custodian under PHIPA s.3(1) para 3, a definition tied to the funding relationship rather than any physical premises.
Breach notice and IPC reporting deadlines
PHIPA s.12(2) requires notice to affected individuals at the first reasonable opportunity, and O. Reg. 329/04 s.6.3 sets out mandatory IPC reporting, including the annual statistics filing due each March 1.
Vicarious liability for agents under s.17
A custodian remains responsible for personal support workers and other agents acting within the scope of their duties, which is what makes employer policy and training the load-bearing control for an unregulated workforce.
Alberta's HIA custodianship for continuing care
Continuing-care operators in Alberta are custodians under HIA s.1(1)(f)(ii), with mandatory breach notice under s.60.1 and penalties under s.107 for organizations that get the response wrong.
BC PIPA for private and non-profit agencies
A private or non-profit home-care agency operating in BC needs a designated privacy officer and documented safeguards under PIPA, obligations that apply regardless of whether the agency also holds an Ontario contract.
What goes wrong
The breach patterns this sector has already lived through
Home and community care has two defining incidents on record, and both reached patients through a coordination or supply chain rather than a single stolen laptop.
A supply-chain vendor becoming the entry point
A ransomware attack on a medical-equipment vendor connected into Ontario's home-care network showed how a single supplier compromise can expose patients across many agencies at once, with disclosure delayed for weeks.
Direct agency compromise and extortion
A prior attack on a national home-care provider exposed care plans and health-card numbers directly, with attackers attempting to pressure the organization through media outreach before a class action followed.
Snooping inside the shared coordination system
Unauthorized look-ups by staff inside large shared health systems remain the most common breach cause the IPC records province-wide, and a system serving hundreds of SPOs multiplies the number of people who could look.
Lost paper and devices between visits
Case files or unlocked phones left in a car, a client's home or on transit are a recurring cause behind Ontario's mobile-workforce breach reports, distinct from any system-level intrusion.
Disputes over what a worker's identity discloses
The IPC has ordered disclosure of visiting workers' names to a client requesting access to their own record, a reminder that the record includes information about the worker as well as the client.
When organisations call us
When home and community care agencies actually call
The moments that start this work tend to be contractual or operational, not a calendar date picked in advance.
An Ontario Health atHome or OHT contract is up for renewal
The security and privacy schedule attached to a new or renewed SPO contract asks for evidence the agency has never had to produce before.
A vendor or platform in the supply chain is breached
A supplier, payroll processor or software vendor discloses an incident, and leadership needs to know within hours what the agency's own notification duty looks like.
A caregiver mobile app or EVV tool is being rolled out
A new AlayaCare-class platform or electronic visit verification tool is going live on staff phones, and BYOD rules need to exist before the first login, not after.
Cyber-insurance renewal asks harder questions
A renewal questionnaire now asks for evidence of MFA, device management and vendor oversight that used to be assumed rather than documented.
A union or HR matter touches worker data
A grievance or investigation raises questions about who can see a worker's schedule, location history or personnel file, and the answer needs a policy behind it.
The board wants assurance before an incident forces the issue
Leadership has watched a sector peer manage a vendor-origin breach in public and wants a program in place before their own agency is the one explaining a delay.
Home & Community Care Agencies: privacy & security questions, answered
Almost certainly yes if you deliver home and community care under Connecting Care Act funding. PHIPA's custodian definition for this sector is tied to the funding relationship, not to owning or operating a facility, so an SPO with no fixed clinical site still carries full custodian obligations for the visits it performs.
Most agencies without an existing program start with either a Minimum Viable Privacy baseline or a Virtual Privacy Officer engagement, since both settle the custodian question and produce the policies a contract review will ask for. Pen testing, incident response planning and vendor review typically follow once that foundation and a specific trigger, like a platform rollout, make them relevant.
An Ontario Health atHome or OHT contract typically embeds its own privacy and security schedule, which can specify expectations around access logging, incident notification timelines and subcontractor oversight beyond PHIPA's baseline. The program needs to be built against the actual contract language, not a generic compliance checklist.
Yes, because PSWs have no licensing college holding them to a professional code, while regulated staff like nurses answer to their own college in addition to the agency. That gap means PSW confidentiality has to be built entirely through employer policy, screening and training rather than assumed as a professional given.
The 2024 amalgamation consolidated the former regional home and community care support services organizations into a single Crown agency, which changed who an SPO reports incidents to and how contracts and the shared CHRIS system are administered. Agencies with older contracts or policies written before the amalgamation should confirm those documents still reflect the current structure.
Yes. Using AlayaCare-class software or a similar platform reduces some technical risk but does not transfer custodian responsibility, notification duties or agent oversight to the vendor. The agency still owns the PHIPA obligations, and a vendor contract needs its own review rather than being treated as a substitute for one.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What should I do after a data breach?
- VPO vs vCISO: do you need one, the other, or both?
- What is a vCISO, and when do you need one?
- How do you assess the privacy and security risk of an AI vendor?
- Do you need an incident response plan, and what should it include?
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- Writing an Incident Response Plan Your Team Will Actually Use
- VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.