Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Clinical care providers

Privacy & Security for Home & Community Care Agencies

Privacy Horizon builds privacy and security programs for the service provider organizations that deliver nursing, personal support and therapy visits under Ontario Health atHome and Ontario Health Team contracts. The work has to fit a business where personal health information leaves the building by design, riding along on a personal support worker's phone into a client's kitchen. We start wherever the pressure actually lands, a contract renewal, a vendor breach notice, a mobile app rollout, then build outward into a program that holds up against a funding-statute custodian test.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Executive directors, directors of quality and risk, and whoever currently holds the privacy-officer function at SPOs ranging from fifty-person community non-profits to national providers coordinating thousands of mobile care workers across Ontario, Alberta, BC and Quebec.

Agencies renewing or bidding on an Ontario Health atHome or Ontario Health Team contract, where the embedded security schedule now sets a bar that a generic policy binder from a few years ago will not clear.

Organizations rolling out a caregiver mobile app, an AlayaCare-class scheduling and care-management platform, or electronic visit verification, and want the BYOD and field-device controls settled before go-live instead of patched in afterward.

Boards and leadership teams who watched a vendor-origin breach ripple through the province's shared coordination chain and want a documented answer for what happens if their own supply chain is next.

Female Doctor Accompany Senior Couple Walking while Talking outside Nursing Home's Garden

Services

Privacy & security services for home & community care agencies

Each service below is scoped for how home & community care agencies actually operate — their systems, their regulators and the reviews they face.

What you hold

What a home-care privacy and security program has to reach

The environment this program has to cover is unusual: most of the risk sits outside any office, on a device or a kitchen table hundreds of kilometres from head office.

Field devices carrying PHI between visits

Personal or agency-issued phones holding care plans, wound photos, medication lists and lockbox codes, often the personal support worker's own device rather than one the agency configured.

The shared coordination system

Referral and assessment data flowing through CHRIS and the Health Partner Gateway between the agency and Ontario Health atHome, a single system that hundreds of organizations rely on and depend on being governed correctly.

Paper and consent conversations in the home

Visit notes, signature sheets and family discussions happening at a client's kitchen table, a setting no office access-control policy was ever written to cover.

A workforce with no licensing college

Personal support workers are the primary hands-on-data role in the sector, and confidentiality obligations for that role exist only because an employer wrote them down and trained to them.

Vendor and supply-chain access

Equipment suppliers, payroll processors and care-management platform vendors that can become the entry point into patient data even when the agency's own network is well defended.

Worker location and scheduling data

Travel logs, visit-verification records and check-in data that carry their own sensitivity, distinct from the client records the program is usually built to protect first.

Regulatory map

Why custodianship here starts with a funding statute, not a building

The regulatory position for home and community care is set by how a visit gets funded, not by whether the agency owns a facility.

PHIPA custodianship through Connecting Care Act funding

An agency delivering home and community care under Connecting Care Act, 2019 s.21 funding is a health information custodian under PHIPA s.3(1) para 3, a definition tied to the funding relationship rather than any physical premises.

Read our guide →

Breach notice and IPC reporting deadlines

PHIPA s.12(2) requires notice to affected individuals at the first reasonable opportunity, and O. Reg. 329/04 s.6.3 sets out mandatory IPC reporting, including the annual statistics filing due each March 1.

Primary source →

Vicarious liability for agents under s.17

A custodian remains responsible for personal support workers and other agents acting within the scope of their duties, which is what makes employer policy and training the load-bearing control for an unregulated workforce.

Read our guide →

Alberta's HIA custodianship for continuing care

Continuing-care operators in Alberta are custodians under HIA s.1(1)(f)(ii), with mandatory breach notice under s.60.1 and penalties under s.107 for organizations that get the response wrong.

Primary source →

BC PIPA for private and non-profit agencies

A private or non-profit home-care agency operating in BC needs a designated privacy officer and documented safeguards under PIPA, obligations that apply regardless of whether the agency also holds an Ontario contract.

Read our guide →

What goes wrong

The breach patterns this sector has already lived through

Home and community care has two defining incidents on record, and both reached patients through a coordination or supply chain rather than a single stolen laptop.

  • A supply-chain vendor becoming the entry point

    A ransomware attack on a medical-equipment vendor connected into Ontario's home-care network showed how a single supplier compromise can expose patients across many agencies at once, with disclosure delayed for weeks.

    Source →

  • Direct agency compromise and extortion

    A prior attack on a national home-care provider exposed care plans and health-card numbers directly, with attackers attempting to pressure the organization through media outreach before a class action followed.

    Source →

  • Snooping inside the shared coordination system

    Unauthorized look-ups by staff inside large shared health systems remain the most common breach cause the IPC records province-wide, and a system serving hundreds of SPOs multiplies the number of people who could look.

    Source →

  • Lost paper and devices between visits

    Case files or unlocked phones left in a car, a client's home or on transit are a recurring cause behind Ontario's mobile-workforce breach reports, distinct from any system-level intrusion.

  • Disputes over what a worker's identity discloses

    The IPC has ordered disclosure of visiting workers' names to a client requesting access to their own record, a reminder that the record includes information about the worker as well as the client.

When organisations call us

When home and community care agencies actually call

The moments that start this work tend to be contractual or operational, not a calendar date picked in advance.

  • An Ontario Health atHome or OHT contract is up for renewal

    The security and privacy schedule attached to a new or renewed SPO contract asks for evidence the agency has never had to produce before.

  • A vendor or platform in the supply chain is breached

    A supplier, payroll processor or software vendor discloses an incident, and leadership needs to know within hours what the agency's own notification duty looks like.

  • A caregiver mobile app or EVV tool is being rolled out

    A new AlayaCare-class platform or electronic visit verification tool is going live on staff phones, and BYOD rules need to exist before the first login, not after.

  • Cyber-insurance renewal asks harder questions

    A renewal questionnaire now asks for evidence of MFA, device management and vendor oversight that used to be assumed rather than documented.

  • A union or HR matter touches worker data

    A grievance or investigation raises questions about who can see a worker's schedule, location history or personnel file, and the answer needs a policy behind it.

  • The board wants assurance before an incident forces the issue

    Leadership has watched a sector peer manage a vendor-origin breach in public and wants a program in place before their own agency is the one explaining a delay.

Home & Community Care Agencies: privacy & security questions, answered

Almost certainly yes if you deliver home and community care under Connecting Care Act funding. PHIPA's custodian definition for this sector is tied to the funding relationship, not to owning or operating a facility, so an SPO with no fixed clinical site still carries full custodian obligations for the visits it performs.

Most agencies without an existing program start with either a Minimum Viable Privacy baseline or a Virtual Privacy Officer engagement, since both settle the custodian question and produce the policies a contract review will ask for. Pen testing, incident response planning and vendor review typically follow once that foundation and a specific trigger, like a platform rollout, make them relevant.

An Ontario Health atHome or OHT contract typically embeds its own privacy and security schedule, which can specify expectations around access logging, incident notification timelines and subcontractor oversight beyond PHIPA's baseline. The program needs to be built against the actual contract language, not a generic compliance checklist.

Yes, because PSWs have no licensing college holding them to a professional code, while regulated staff like nurses answer to their own college in addition to the agency. That gap means PSW confidentiality has to be built entirely through employer policy, screening and training rather than assumed as a professional given.

The 2024 amalgamation consolidated the former regional home and community care support services organizations into a single Crown agency, which changed who an SPO reports incidents to and how contracts and the shared CHRIS system are administered. Agencies with older contracts or policies written before the amalgamation should confirm those documents still reflect the current structure.

Yes. Using AlayaCare-class software or a similar platform reduces some technical risk but does not transfer custodian responsibility, notification duties or agent oversight to the vendor. The agency still owns the PHIPA obligations, and a vendor contract needs its own review rather than being treated as a substitute for one.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.