Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Clinical care providers

Privacy & Security for Physiotherapy & Chiropractic Clinics

Physiotherapy and chiropractic clinics hold clinical charts that constantly leave the building: auto insurers, WSIB, lawyers and family doctors receive OCF treatment plans, IMEs and invoices as routine business, not as an exception. Privacy Horizon builds programs around that third-party-payer reality, an unambiguous custodian, safeguards sized to a Jane-class practice-software footprint, and retention schedules that track physiotherapy's ten-year College standard separately from chiropractic's seven-year floor. Work usually starts around an HCAI-linked billing change, a clinic acquisition, or a records-access complaint.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Solo and small clinic owners who are also the treating physiotherapist or chiropractor and the default PHIPA custodian, plus the office manager who runs scheduling, billing and HCAI submissions day to day.

Multi-site rehab groups and consolidators absorbing acquired clinics, where an operations or compliance lead has to reconcile different EMRs, different vendor contracts and inherited user accounts under one program.

Clinics negotiating auto-insurer or WSIB preferred-provider status, where a vendor security review of the practice-management platform becomes a condition of the referral relationship rather than a courtesy.

Practices moving paper charts into cloud practice software such as Jane, or renewing cyber insurance, both of which surface gaps a busy front desk and treatment schedule never had time to notice.

Physiotherapist, people and band for stretching legs at clinic, helping and recovery on table. Men, flexibility exercise and chiropractor for rehabilitation treatment, support and

Services

Privacy & security services for physiotherapy & chiropractic clinics

Each service below is scoped for how physiotherapy & chiropractic clinics actually operate — their systems, their regulators and the reviews they face.

What you hold

What a physiotherapy or chiropractic privacy program has to cover

The record set spans clinical notes, insurer paperwork and payment data, and it moves through systems most clinics never built themselves.

SOAP notes and functional assessments

Subjective and objective assessment notes, injury history, treatment plans and outcome measures form the clinical core of the chart and carry the same sensitivity as any other health record.

OCF forms and insurer correspondence

OCF-18 treatment plans, OCF-23 and OCF-21 invoices, adjuster emails and independent examination reports travel outside the clinic constantly as part of routine auto-insurance billing.

WSIB and extended-health claim data

Program-of-care documentation for WSIB claims and direct-billing submissions to extended-health insurers add claim numbers and employer-linked information to the same patient file.

Cloud practice-management and EMR accounts

Booking, charting and billing typically run through one cloud platform such as Jane, so the account permissions inside that single system largely determine who can see what.

Payment terminals and credit card data

Direct-billing co-payments and private-pay treatment plans run through payment terminals that need their own PCI-aware handling separate from the clinical record.

The open gym and treatment areas

Whiteboards, appointment screens and conversations at the front desk or in an open gym expose patient names and appointment types to other patients in ways a private office does not.

Regulatory map

The regulatory layer built around treatment and insurance

Ontario physiotherapists and chiropractors carry PHIPA custodian duties directly, and a second layer of College and insurer rules sits on top.

Custodian status under PHIPA s.3(1)

A physiotherapist or chiropractor who holds patient records is a health information custodian under PHIPA, with clinic staff and contractors acting as agents under section 17.

Read our guide →

Breach notice and March 1 statistics

Individuals must be notified at the first reasonable opportunity, the IPC notified per O. Reg. 329/04 s.6.3, and annual breach counts reported to the IPC by March 1 under s.6.4.

Read our guide →

College of Physiotherapists' ten-year retention floor

The College's Record Keeping Standard sets a minimum ten-year retention period, or to age 28 for a minor, along with unique user IDs and traceable corrections in the EMR.

Primary source →

CCO Standard S-002's seven-year floor

The College of Chiropractors of Ontario's Standard S-002 requires PHIPA-compliant electronic systems with cyber security protections and at least seven years of retention, or seven years past age 18.

Primary source →

Mandatory HCAI submission for auto claims

Ontario health facilities treating motor-vehicle-accident patients must submit OCF treatment plans and invoices through HCAI, the insurer-built electronic system, making a third-party portal part of clinical workflow.

Primary source →

PIPEDA and provincial private-sector law outside Ontario

Clinics in Alberta, BC and Quebec answer to PIPA or Law 25 instead of PHIPA, each with its own privacy-officer, safeguard and breach-notice requirements.

Read our guide →

What goes wrong

Where physiotherapy and chiropractic privacy actually breaks down

The niche's defining incidents are about who gets to see a chart and on what terms, not sophisticated hacking.

  • Access-request and fee disputes

    The IPC's PHIPA Decision 185 reviewed a physiotherapy clinic's fee and record format after a patient sought their own file, a dispute pattern this niche sees more than most.

    Source →

  • Reasonable-search complaints

    PHIPA Decision 55 involved a chiropractor challenged over an allegedly incomplete records production, another access dispute rather than a security breach.

    Source →

  • Referral and lead-generation abuse around MVA patients

    One IPC file traced a physician referral into a physiotherapy clinic where the patient was then solicited by a related personal-injury practice, a pattern specific to motor-vehicle-accident referrals.

    Source →

  • Snooping and misdirected reports

    Ontario's 2024 breach statistics show snooping and misdirected or lost records as the two leading causes, and rehab clinics send a high volume of reports to insurers, lawyers and family doctors.

    Source →

  • Ransomware without confirmed exfiltration

    Recent IPC decisions treat a ransomware encryption event as notifiable even without proof data left the network, a standard clinics relying on cloud EMRs still need to plan around.

    Source →

  • Inherited accounts after an acquisition

    Consolidator roll-ups the scale of Lifemark's 300-plus clinics routinely bring forward legacy user accounts and permissions that outlive the staff who needed them.

    Source →

When organisations call us

When a clinic actually calls

The purchase moment is usually external, not an internal decision to get ahead of things.

  • Joining an insurer's preferred-provider network

    Auto insurers and WSIB program-of-care relationships increasingly require a documented security posture before referrals start flowing to a clinic.

  • An access-request or fee complaint

    A patient or their lawyer disputing records format or a copy fee, and threatening or filing an IPC complaint, forces a fast review of how requests are actually handled.

  • Acquisition by a consolidator

    Being bought by, or buying into, a Lifemark- or CBI-scale group puts chart custody, legacy systems and inherited accounts on the table at once.

  • Moving off paper into cloud practice software

    Migrating charting and billing into Jane or a comparable platform is the moment most clinics first ask what the vendor actually secures versus what stays the clinic's job.

  • Cyber-insurance renewal

    Insurers renewing a policy for a clinic holding insurer files, credit card data and health records ask sharper questions than a generic small-business renewal.

  • A College QA or audit touching record keeping

    A College of Physiotherapists or College of Chiropractors quality-assurance review that flags record-keeping gaps often becomes the reason the privacy program finally gets written down.

Physiotherapy & Chiropractic Clinics: privacy & security questions, answered

Yes. Both professions hold patient records directly and meet the definition of a health information custodian under PHIPA section 3(1), with clinic staff, contractors and students acting as agents under section 17. That status applies identically whether the clinic is a single treatment room or one location inside a national group, and it does not shift just because a third party such as an insurer requested the record.

The defining difference is disclosure pattern: the single biggest recipient of a physiotherapy or chiropractic record is usually an auto insurer, WSIB or an employer benefits plan rather than another treating clinician. HCAI submission of OCF forms, adjuster correspondence and independent examination reports make third-party-payer handling the core of the privacy program, not an afterthought bolted onto a generic clinical policy.

They can share infrastructure and policy documents, but the retention schedule has to track each College's own floor: physiotherapy assessment notes for at least ten years under the College of Physiotherapists' standard, and chiropractic records for at least seven years under CCO Standard S-002. One program can hold both rules; it just cannot apply a single retention number to everyone.

No. HCAI is the insurer-built system health facilities are required to use for OCF submissions, and using it does not transfer the clinic's custodian obligations to the insurer or to HCAI itself. The clinic remains responsible for what it sends, how long it keeps a copy, and how patients are told their treatment-plan data flows through that portal.

A solo or two-practitioner clinic without an existing program usually starts with Minimum Viable Privacy, which builds the policies, safeguards and training a small practice needs in one package. A multi-site group already handling insurer network reviews or an acquisition typically starts with a Virtual Privacy Officer engagement instead, since the custodian and disclosure questions are more involved from day one.

Three moments dominate: an auto insurer or WSIB program asking about security before referrals continue, a records-access dispute that could reach the IPC, and an acquisition where chart custody and legacy systems need sorting out. Few clinics start a review purely out of routine schedule; something external usually starts the clock.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.