MVP program · Clinical care providers
Minimum Viable Privacy Program for Medical Imaging Clinics
Minimum Viable Privacy packages the privacy foundations a single X-ray or ultrasound clinic needs into one twelve-month program for $5,499 CAD annually: a gap review, core policies, readiness workshops and staff training. It exists for the clinic opening or operating under its ICHSC licence with no appetite for a sprawling consulting engagement, whether that's a newly licensed site or an established practice that has never formalized what PHIPA already expects of it.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The essentials a single-site clinic must get right first
At ten staff or fewer there's no room for a program that covers everything thinly. The MVP concentrates on the handful of assets where a gap is existential.
The RIS and PACS, and nothing else
A small clinic typically runs on one RIS/PACS platform plus email and billing. Securing that one archive properly delivers most of the available protection for the least effort.
Requisitions and reports at the front desk
Referral forms carrying clinical history and printed reports awaiting pickup are personal health information the moment they arrive, and they deserve better than an unlocked tray.
A handful of technologists and booking staff
With two to ten people, one person's mistake is the clinic's breach. The included training seats cover everyone who touches a study, front desk included.
Whatever media requests actually come in
Even a small ultrasound clinic gets calls for CDs and printed copies, and a documented, consistent process for those requests is one of the fastest wins the MVP delivers.
Regulatory map
Small clinic, full-size ICHSC and PHIPA obligations
None of the duties that apply to a five-site MRI and CT group are waived for a single ultrasound clinic. The MVP is scoped so a small practice can meet them without a compliance department.
Custodian status from day one under the ICHSC licence
An integrated community health services centre is a named PHIPA custodian facility the moment it's licensed, regardless of staff count or how many modalities it runs.
PHIPA breach duties with no size threshold
Notifying affected individuals at the first reasonable opportunity, reporting to the IPC where required, and keeping audit logs apply to a two-technologist ultrasound clinic exactly as written.
Accreditation Canada's inspection, regardless of size
O. Reg. 215/23's inspection cycle applies to every licensed clinic regardless of size, and the gap review checks whether basic documentation exists before an inspector asks for it.
Decision 249's prevention expectations, at any scale
The IPC's guidance on privileged access, MFA and backups following the province's flagship ransomware case applies to the size of clinic that was actually breached, not just large groups.
What goes wrong
Why a small clinic cannot wait for a mature program
Attackers do not filter targets by patient volume; automated attacks and the same misconfigurations affect a two-room clinic exactly as much as a large group.
One PACS login equals the whole clinic
In a small practice, a single compromised credential can reach every study the clinic has ever stored. Concentration, not sophistication, is the defining risk at this scale.
Nobody officially owns privacy
When responsibility belongs to everyone it belongs to no one, and a patient's access request or a media request from a lawyer lands on whoever happens to answer the phone.
A licence renewal or inspection with no documentation
Arriving at an Accreditation Canada review with no written policies or evidence of training is a foundations problem the MVP is built to close before it becomes a finding.
The PACS left exposed by default settings
A small clinic's PACS installed without dedicated IT oversight can end up reachable from the internet the way exposed-DICOM cases were found globally, an easy gap the MVP's baseline review catches.
Our mvp program for medical imaging clinics
What the MVP year includes for a single-site clinic
A fixed package, sequenced so the highest-impact items land first and nothing depends on the clinic hiring anyone.

Baseline gap review
A structured look at how your RIS, PACS, front-desk workflow and vendor connections compare against PHIPA and ICHSC facility expectations, producing a short, ranked list.
Prioritized control recommendations
Directional guidance on what to fix first, typically authentication on the PACS, backup verification and access review, chosen for impact per hour of the clinic's limited time.
Core policy development
The essential documents a small clinic needs: access and confidentiality, media-handling for CDs and USB copies, retention basics and a breach-response outline, drafted for your actual systems.
Readiness assessment workshops
Working sessions that prepare the clinic for the situations that prompted the purchase, from an inspection walkthrough to handling a suspected access incident.
Training with ten seats
Role-appropriate privacy and security training with human-risk assessments for up to ten people, covering the full roster of most single-site clinics.
Twelve hours of coaching
Expert time to spend where the year takes you: a vendor question, a media-request judgment call, or help implementing a recommended control.
How the engagement runs
A year of MVP inside a single imaging clinic
Step 1
Review and rank
The engagement opens with the gap review and a prioritized plan the clinic owner or medical director can read in one sitting.
Step 2
Build the foundations
Policies are drafted and the first controls implemented with coaching support, usually landing within the opening months of the term.
Step 3
Train and rehearse
Staff complete training, and workshops rehearse the inspection and incident scenarios that matter most to a clinic of your size.
Step 4
Close the loop
Remaining coaching hours handle what surfaced during the year, and the term ends with a clear picture of what maturity looks like next.
What it costs
MVP pricing for a single medical imaging clinic
Minimum Viable Privacy is $5,499 CAD per year on a twelve-month term, covering the gap review, policy development, readiness assessment workshops, twelve hours of coaching and training with human-risk assessments for ten seats. There are no per-deliverable surprises; the package is the price.
Clinics that outgrow it, by opening a second site, adding MRI or CT, or signing a teleradiology contract, typically graduate to the Virtual Privacy Office retainer, and the MVP's outputs carry straight into it. Book a demo to see whether the package fits your clinic.
Medical Imaging Clinics: MVP program questions, answered
Five things, done properly: a named person accountable for privacy; a simple map of where studies and reports live across your RIS and PACS; core policies covering access, media-handling and breach response; baseline safeguards, meaning MFA on the PACS, encrypted devices and verified backups; and trained staff. That set satisfies what a custodian is expected to demonstrate and holds up when Accreditation Canada or a patient asks what protects their study. It's exactly the scope the MVP delivers in its first months.
You need the essentials in place before day one, a privacy officer designation, core policies and basic safeguards, but not every document a large multi-site group eventually accumulates. The MVP is built for exactly this moment, sequencing the gap review and core policy development so a newly licensed clinic has the required foundations without a lengthy pre-opening compliance project.
At minimum: documented privacy and security policies, evidence that staff have been trained, an access log for the PACS, and a defensible retention schedule. The MVP's gap review checks each of these against your actual setup and the readiness workshops rehearse the walkthrough itself, so the inspection doesn't surface gaps nobody had noticed.
Yes, the foundations are designed to land inside the opening quarter of the term on a few hours a month from the clinic owner or office manager, with no new headcount. Training embeds over the following months, workshops rehearse scenarios as they arise, and the coaching hours absorb whatever a real year of running a licensed clinic throws at you.
Four components across the twelve-month term: the baseline privacy gap review with prioritized recommendations; development of the core policy set; readiness assessment workshops; and privacy and security training with human-risk assessments for up to ten seats, plus twelve hours of expert coaching. It's deliberately a fixed, published price so a clinic owner can approve it without a procurement exercise.
Three honest options. A clinic with a stable, single-site footprint often renews and deepens what exists, refreshed training, updated policies. A clinic that added a site, a new modality or a teleradiology contract typically steps up to the Virtual Privacy Office, where a designated privacy lead and monthly hours take over. And a clinic that built internal capability can carry the program forward itself, since every deliverable and policy belongs to you.
More for medical imaging clinics
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.