New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Medical Imaging Clinics
Privacy Horizon builds PHIPA-aligned privacy and security programs for medical imaging clinics, covering the RIS/PACS environment, connected DICOM modalities and the ICHSC licence every community diagnostic centre now operates under. Work typically starts after a ransomware scare, ahead of an Accreditation Canada inspection, or when a new AI triage tool or teleradiology contract puts your data flows under scrutiny. We build programs radiologists, PACS administrators and clinic owners can actually run day to day.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with Ontario X-ray and ultrasound clinics of ten to fifty staff through multi-site groups running MRI and CT, all now licensed as integrated community health services centres under provincial law. Our usual contacts are the clinic owner or medical director, a general manager overseeing several sites, the PACS administrator, and whichever partner holds the ICHSC licence.
Engagements typically start after a ransomware incident, ahead of Accreditation Canada's four-year ICHSC inspection cycle, when a new MRI or CT licence is awarded through a ministry call for applications, or when the clinic connects to a regional Diagnostic Imaging repository for the first time.
Other engagements begin when a clinic deploys AI worklist-prioritization or CAD tools inside the reading workflow, or when a hospital's teleradiology contract asks for security attestations before referrals start flowing. Each of these moments puts a different part of the imaging environment under a magnifying glass.

Services
Privacy & security services for medical imaging clinics
Each service below is scoped for how medical imaging clinics actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Medical Imaging Clinics
Virtual CISO for medical imaging clinics: security leadership across RIS/PACS, modality networks and teleradiology links, built on PHIPA Decision 249.
Virtual Privacy Officer
Virtual Privacy Officer for Medical Imaging Clinics
Virtual Privacy Officer for medical imaging clinics: a named PHIPA lead handling ICHSC obligations, DI-repository access and the March 1 IPC filing.
Penetration Testing
Penetration Testing for Medical Imaging Clinics
Penetration testing for medical imaging clinics: safely probing PACS, DICOM ports and teleradiology VPNs for the exposure that leaks studies globally.
Incident Response Planning
Incident Response Planning for Medical Imaging Clinics
Incident response planning for medical imaging clinics: a ransomware playbook built on PHIPA Decision 249, covering downtime imaging and mass notification.
Privacy & Security Policy Development
Privacy & Security Policy Development for Medical Imaging Clinics
Privacy and security policy development for medical imaging clinics: PHIPA and ICHSC-aligned policies covering media handling, remote reading and access.
Privacy & Security Training
Privacy & Security Training for Medical Imaging Clinics
Privacy and security training for medical imaging clinics: role-specific sessions for technologists and booking staff on chaperoning, media and PACS access.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Medical Imaging Clinics
Vendor security reviews for medical imaging clinics: vetting cloud PACS, RIS, AI triage and modality remote-service vendors before they touch DICOM data.
ISO 27001 Readiness
ISO 27001 Readiness for Medical Imaging Clinics
ISO 27001 readiness for medical imaging clinics: certification prep scoped to PACS and RIS, built to win hospital teleradiology contracts.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Medical Imaging Clinics
AI-PIA for medical imaging clinics: documented review of worklist-prioritization and CAD tools before DICOM studies leave the PACS for AI inference.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Medical Imaging Clinics
Minimum Viable Privacy for medical imaging clinics: a $5,499 CAD/year foundation for a single X-ray or ultrasound clinic opening under its ICHSC licence.
What you hold
The imaging records and systems a program has to cover
A clinic's exposure runs from the requisition at the front desk to the DICOM study a radiologist reads at 2 a.m., and every system in between carries its own risk profile.
DICOM studies across every modality
X-ray, ultrasound, mammography and MRI or CT studies where the clinic is licensed, each a DICOM object tracked from acquisition through storage, viewing and any teleradiology transfer.
Radiologist reports and requisitions
Reports carry the clinical conclusion; requisitions carry the referring physician's clinical history, and both travel together through the RIS long before a patient sees either one.
OHIP billing tied to each study
Technical and professional fee records link a patient's identity to the exact procedure performed, sensitive on its own even before it's paired with the image.
Pregnancy and oncology-sensitive findings
Some findings carry consequences well beyond the clinical file if they reach the wrong person, which is why access to sensitive study categories deserves its own scrutiny rather than a blanket permission.
Priors imported from other sites
Comparison studies pulled in from a previous clinic or hospital sit in your PACS under your custodial responsibility the moment they land, whether or not your clinic originally acquired them.
RIS, PACS and VNA platforms carrying it all
Scheduling and workflow run through the RIS while images live in PACS or a vendor-neutral archive, and the two systems' access controls rarely line up automatically without deliberate work.
Regulatory map
Who regulates a medical imaging clinic, and under what licence
Ontario re-licensed the entire community diagnostic sector in 2023, and that new licence sits on top of, not instead of, everyday privacy law.
ICHSC status under PHIPA
An integrated community health services centre is a named custodian facility under PHIPA section 3(1) paragraph 4(i), so a clinic operating under the licence carries full custodian duties for the studies and reports it holds.
The 2023 licensing overhaul
The Independent Health Facilities Act was repealed and replaced by the Integrated Community Health Services Centres Act in September 2023; existing IHFs became ICHSCs automatically, and Patient Ombudsman jurisdiction now reaches them too.
Accreditation Canada's four-year inspection cycle
O. Reg. 215/23 names Accreditation Canada as the prescribed inspecting body for ICHSC facility standards, running a four-year cycle with a mid-cycle self-assessment your clinic has to be ready for.
PHIPA breach and audit-log duties
Section 12(2) and O. Reg. 329/04 section 6.3 set the breach-response and audit-log obligations every custodian carries, backed by fines reaching $200,000 for an individual and $1,000,000 for an organization.
Alberta, BC and Quebec for a multi-province group
A group operating across provinces layers Alberta HIA custodian duties, BC PIPA safeguards and Quebec's health-information rules plus Law 25 on top of whatever PHIPA already requires in Ontario.
What goes wrong
How medical imaging clinics actually lose control of data
The sector's own incident record, not a generic threat list, sets what this program has to prevent.
Ransomware with the ransom paid
PHIPA Decision 249 is the IPC's flagship community-sector case: a medical imaging clinic's December 2022 attack affected up to 550,000 patient records and 1.6 million case files, and the clinic paid to restore services.
Exposed PACS reachable from the internet
Investigative reporting has found unprotected PACS servers leaking studies across 52 countries, describing the failure as walking through an open door rather than a sophisticated hack.
Encryption-only incidents still count as loss
The IPC's 2024 decision trilogy confirmed that an attacker merely encrypting data, without proven exfiltration, is still a notifiable loss under PHIPA, closing a defence some organizations had leaned on.
Snooping across a connected repository
Unauthorized access remained Ontario's leading breach cause in 2024, and imaging staff with reach into a regional DI repository can browse priors belonging to patients well outside their own clinic's waiting room.
Unattended patients and mishandled media
IPC case files include a patient left alone in a diagnostic imaging room and imaging disks distributed improperly, reminders that physical workflow failures are breaches too.
When organisations call us
The moments that bring a clinic to us
Imaging clinics rarely call about privacy in the abstract; a licence renewal, an incident or a new deployment puts a date on the calendar.
A ransomware attack or a near-miss
An attack against the RIS or PACS, or a close call that shows how little stood in the way, moves security governance from someday to now.
An Accreditation Canada inspection is booked
The four-year ICHSC cycle or its mid-cycle self-assessment is approaching, and the clinic's privacy and security documentation needs to hold up alongside its facility standards.
A new MRI or CT licence is awarded
Winning a licence through a ministry call for applications brings new modalities, new data volumes and new scrutiny the existing program was never built for.
Connecting to a regional DI repository
Joining a Diagnostic Imaging Common Service feed or ConnectingOntario ClinicalViewer changes who can see your studies and who can see into your clinic from outside it.
Deploying AI triage or CAD tools
Adding AI worklist-prioritization to the reading workflow raises questions about vendor data flows and bias the clinic has not had to answer before.
A teleradiology contract requests attestations
A hospital or reading group asks for proof of safeguards before referrals start flowing, and the clinic discovers how much of its posture was never actually documented.
Medical Imaging Clinics: privacy & security questions, answered
Yes. An integrated community health services centre is named directly in PHIPA as a health information custodian facility, which means the full set of custodian duties, safeguards, breach notification, access rights and audit logs, applies to the clinic itself rather than only to the individual radiologists working inside it.
The licence and PHIPA cover different ground that happens to overlap. The Integrated Community Health Services Centres Act and O. Reg. 215/23 govern facility standards inspected by Accreditation Canada, staffing, equipment and quality of care, while PHIPA governs how personal health information is collected, used, protected and disclosed. A clinic needs to satisfy both, and the documentation for one rarely covers the other automatically.
The underlying obligations are identical; what changes is scale. A five-person ultrasound clinic and a five-site MRI and CT group are both ICHSC-licensed custodians under the same statute, facing the same breach duties and the same inspection cycle, but the group has more PACS instances, more staff to train and more vendor relationships to govern.
Because a DICOM study is not a generic file. Modalities, PACS and viewers speak a protocol with its own ports, its own vendor conventions and its own history of misconfigured servers being found openly reachable on the internet. A general IT security review built for office file shares and email will miss the specific ways a PACS or a modality gets exposed.
The inspection is built around ICHSC facility standards, but a program that cannot produce current policies, access logs or evidence of staff training tends to raise questions during the broader review, and mid-cycle self-assessments increasingly expect that documentation to exist. Treating privacy and security as separate from facility readiness is a gap worth closing before the inspector arrives.
It creates new questions worth answering formally rather than a new statute to comply with. Where studies leave your environment for AI inference, you need to know where they go, under what agreement and whether the tool's outputs have been checked for bias across the patient populations you serve, work an AI privacy impact assessment is built to document.
Related industries
Answers & guides
- What should I do after a data breach?
- Do you need an incident response plan, and what should it include?
- When do you need an AI Privacy Impact Assessment (AI-PIA)?
- VPO vs vCISO: do you need one, the other, or both?
- What is a cybersecurity risk assessment, and how often should we do one?
- What is multi-factor authentication, and do I need it?
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.