New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Physiotherapy & Chiropractic Clinics
Physiotherapy and chiropractic clinics hold clinical charts that constantly leave the building: auto insurers, WSIB, lawyers and family doctors receive OCF treatment plans, IMEs and invoices as routine business, not as an exception. Privacy Horizon builds programs around that third-party-payer reality, an unambiguous custodian, safeguards sized to a Jane-class practice-software footprint, and retention schedules that track physiotherapy's ten-year College standard separately from chiropractic's seven-year floor. Work usually starts around an HCAI-linked billing change, a clinic acquisition, or a records-access complaint.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Solo and small clinic owners who are also the treating physiotherapist or chiropractor and the default PHIPA custodian, plus the office manager who runs scheduling, billing and HCAI submissions day to day.
Multi-site rehab groups and consolidators absorbing acquired clinics, where an operations or compliance lead has to reconcile different EMRs, different vendor contracts and inherited user accounts under one program.
Clinics negotiating auto-insurer or WSIB preferred-provider status, where a vendor security review of the practice-management platform becomes a condition of the referral relationship rather than a courtesy.
Practices moving paper charts into cloud practice software such as Jane, or renewing cyber insurance, both of which surface gaps a busy front desk and treatment schedule never had time to notice.

Services
Privacy & security services for physiotherapy & chiropractic clinics
Each service below is scoped for how physiotherapy & chiropractic clinics actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Physiotherapy & Chiropractic Clinics
Virtual CISO for multi-clinic physiotherapy and chiropractic groups: security leadership across mixed EMRs, insurer networks and clinic acquisitions.
Virtual Privacy Officer
Virtual Privacy Officer for Physiotherapy & Chiropractic Clinics
Virtual Privacy Officer for physiotherapy and chiropractic clinics: custodian duties, HCAI/insurer disclosures, lock-box requests and March 1 IPC reporting.
Incident Response Planning
Incident Response Planning for Physiotherapy & Chiropractic Clinics
Incident response planning for physiotherapy and chiropractic clinics: who owns a breach when your EMR is cloud-hosted and HCAI-bound OCF data is exposed.
Privacy & Security Policy Development
Privacy & Security Policy Development for Physiotherapy & Chiropractic Clinics
Privacy policy development for physiotherapy and chiropractic clinics: consent language for direct billing, insurer disclosures, and retention schedules.
Privacy & Security Training
Privacy & Security Training for Physiotherapy & Chiropractic Clinics
Privacy and security training for physiotherapy and chiropractic clinics: open-gym confidentiality, insurer paperwork handling, and student charting rules.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Physiotherapy & Chiropractic Clinics
Vendor security review for physiotherapy and chiropractic clinics: assessing Jane-class EMRs, telerehab apps and IME transcription vendors.
M&A Privacy & Security Due Diligence
M&A Privacy & Security Due Diligence for Physiotherapy & Chiropractic Clinics
M&A privacy due diligence for physiotherapy and chiropractic clinic acquisitions: chart custody, inherited accounts, and insurer file transfer risk.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Physiotherapy & Chiropractic Clinics
Minimum Viable Privacy for physiotherapy and chiropractic clinics: a $5,499 CAD/year foundation for solo and small practices starting from zero.
What you hold
What a physiotherapy or chiropractic privacy program has to cover
The record set spans clinical notes, insurer paperwork and payment data, and it moves through systems most clinics never built themselves.
SOAP notes and functional assessments
Subjective and objective assessment notes, injury history, treatment plans and outcome measures form the clinical core of the chart and carry the same sensitivity as any other health record.
OCF forms and insurer correspondence
OCF-18 treatment plans, OCF-23 and OCF-21 invoices, adjuster emails and independent examination reports travel outside the clinic constantly as part of routine auto-insurance billing.
WSIB and extended-health claim data
Program-of-care documentation for WSIB claims and direct-billing submissions to extended-health insurers add claim numbers and employer-linked information to the same patient file.
Cloud practice-management and EMR accounts
Booking, charting and billing typically run through one cloud platform such as Jane, so the account permissions inside that single system largely determine who can see what.
Payment terminals and credit card data
Direct-billing co-payments and private-pay treatment plans run through payment terminals that need their own PCI-aware handling separate from the clinical record.
The open gym and treatment areas
Whiteboards, appointment screens and conversations at the front desk or in an open gym expose patient names and appointment types to other patients in ways a private office does not.
Regulatory map
The regulatory layer built around treatment and insurance
Ontario physiotherapists and chiropractors carry PHIPA custodian duties directly, and a second layer of College and insurer rules sits on top.
Custodian status under PHIPA s.3(1)
A physiotherapist or chiropractor who holds patient records is a health information custodian under PHIPA, with clinic staff and contractors acting as agents under section 17.
Breach notice and March 1 statistics
Individuals must be notified at the first reasonable opportunity, the IPC notified per O. Reg. 329/04 s.6.3, and annual breach counts reported to the IPC by March 1 under s.6.4.
College of Physiotherapists' ten-year retention floor
The College's Record Keeping Standard sets a minimum ten-year retention period, or to age 28 for a minor, along with unique user IDs and traceable corrections in the EMR.
CCO Standard S-002's seven-year floor
The College of Chiropractors of Ontario's Standard S-002 requires PHIPA-compliant electronic systems with cyber security protections and at least seven years of retention, or seven years past age 18.
Mandatory HCAI submission for auto claims
Ontario health facilities treating motor-vehicle-accident patients must submit OCF treatment plans and invoices through HCAI, the insurer-built electronic system, making a third-party portal part of clinical workflow.
PIPEDA and provincial private-sector law outside Ontario
Clinics in Alberta, BC and Quebec answer to PIPA or Law 25 instead of PHIPA, each with its own privacy-officer, safeguard and breach-notice requirements.
What goes wrong
Where physiotherapy and chiropractic privacy actually breaks down
The niche's defining incidents are about who gets to see a chart and on what terms, not sophisticated hacking.
Access-request and fee disputes
The IPC's PHIPA Decision 185 reviewed a physiotherapy clinic's fee and record format after a patient sought their own file, a dispute pattern this niche sees more than most.
Reasonable-search complaints
PHIPA Decision 55 involved a chiropractor challenged over an allegedly incomplete records production, another access dispute rather than a security breach.
Referral and lead-generation abuse around MVA patients
One IPC file traced a physician referral into a physiotherapy clinic where the patient was then solicited by a related personal-injury practice, a pattern specific to motor-vehicle-accident referrals.
Snooping and misdirected reports
Ontario's 2024 breach statistics show snooping and misdirected or lost records as the two leading causes, and rehab clinics send a high volume of reports to insurers, lawyers and family doctors.
Ransomware without confirmed exfiltration
Recent IPC decisions treat a ransomware encryption event as notifiable even without proof data left the network, a standard clinics relying on cloud EMRs still need to plan around.
Inherited accounts after an acquisition
Consolidator roll-ups the scale of Lifemark's 300-plus clinics routinely bring forward legacy user accounts and permissions that outlive the staff who needed them.
When organisations call us
When a clinic actually calls
The purchase moment is usually external, not an internal decision to get ahead of things.
Joining an insurer's preferred-provider network
Auto insurers and WSIB program-of-care relationships increasingly require a documented security posture before referrals start flowing to a clinic.
An access-request or fee complaint
A patient or their lawyer disputing records format or a copy fee, and threatening or filing an IPC complaint, forces a fast review of how requests are actually handled.
Acquisition by a consolidator
Being bought by, or buying into, a Lifemark- or CBI-scale group puts chart custody, legacy systems and inherited accounts on the table at once.
Moving off paper into cloud practice software
Migrating charting and billing into Jane or a comparable platform is the moment most clinics first ask what the vendor actually secures versus what stays the clinic's job.
Cyber-insurance renewal
Insurers renewing a policy for a clinic holding insurer files, credit card data and health records ask sharper questions than a generic small-business renewal.
A College QA or audit touching record keeping
A College of Physiotherapists or College of Chiropractors quality-assurance review that flags record-keeping gaps often becomes the reason the privacy program finally gets written down.
Physiotherapy & Chiropractic Clinics: privacy & security questions, answered
Yes. Both professions hold patient records directly and meet the definition of a health information custodian under PHIPA section 3(1), with clinic staff, contractors and students acting as agents under section 17. That status applies identically whether the clinic is a single treatment room or one location inside a national group, and it does not shift just because a third party such as an insurer requested the record.
The defining difference is disclosure pattern: the single biggest recipient of a physiotherapy or chiropractic record is usually an auto insurer, WSIB or an employer benefits plan rather than another treating clinician. HCAI submission of OCF forms, adjuster correspondence and independent examination reports make third-party-payer handling the core of the privacy program, not an afterthought bolted onto a generic clinical policy.
They can share infrastructure and policy documents, but the retention schedule has to track each College's own floor: physiotherapy assessment notes for at least ten years under the College of Physiotherapists' standard, and chiropractic records for at least seven years under CCO Standard S-002. One program can hold both rules; it just cannot apply a single retention number to everyone.
No. HCAI is the insurer-built system health facilities are required to use for OCF submissions, and using it does not transfer the clinic's custodian obligations to the insurer or to HCAI itself. The clinic remains responsible for what it sends, how long it keeps a copy, and how patients are told their treatment-plan data flows through that portal.
A solo or two-practitioner clinic without an existing program usually starts with Minimum Viable Privacy, which builds the policies, safeguards and training a small practice needs in one package. A multi-site group already handling insurer network reviews or an acquisition typically starts with a Virtual Privacy Officer engagement instead, since the custodian and disclosure questions are more involved from day one.
Three moments dominate: an auto insurer or WSIB program asking about security before referrals continue, a records-access dispute that could reach the IPC, and an acquisition where chart custody and legacy systems need sorting out. Few clinics start a review purely out of routine schedule; something external usually starts the clock.
Related industries
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.