Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Clinical care providers

Minimum Viable Privacy Program for Pharmacies

Minimum Viable Privacy gives a single independent pharmacy the essential PHI policies, staff training and breach basics required to run defensibly, sized for an owner who is also the Designated Manager and does not have room for a full privacy department. It is the fastest honest path to a program you can point to when the College, an insurer or a patient asks how the store handles their information.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the baseline program has to cover for one store

A single-owner pharmacy still carries every core PHIPA duty a large banner does; MVP identifies the essentials that matter most at store scale.

A working PHI policy

One clear document covering collection, access, disclosure and retention that the Designated Manager can point to and staff can actually follow day to day.

Lookup and disclosure ground rules

A plain statement that unauthorized lookups are breaches on their own, matched to how OCP actually treats these cases in discipline.

A basic breach log

A simple, consistent way to record incidents as they happen, so the store has a real history to draw on if a pattern emerges or a regulator asks.

Front-store coverage under PIPEDA

Baseline handling for loyalty and e-commerce data that sits alongside, but is legally distinct from, the dispensary's PHIPA obligations.

A retention starting point

A documented approach to the ten-year prescription-record retention duty, even in simple form, rather than an assumption that it is being handled correctly.

Regulatory map

The baseline every single-store pharmacy has to meet

None of these obligations shrink because the pharmacy is small; MVP is about meeting them efficiently, not about meeting fewer of them.

PHIPA custodian status applies at any size

A one-location pharmacy is a health information custodian under PHIPA exactly as a large banner is, with the same notice and safeguard duties attached.

Primary source →

The Designated Manager carries the accountability

In a small store, the owner is often also the Designated Manager, meaning PHI policy accountability and business ownership sit in the same person without a delegate to share the load.

Primary source →

IPC reporting duties don't scale down

A reportable breach at a single independent triggers the same O. Reg. 329/04 obligations as it would at a large chain, on the same timeline.

Primary source →

PIPEDA for the front of the store

Federal privacy law governs loyalty and e-commerce data even at a single location, a second, separate obligation layered on top of PHIPA.

Read our guide →

What goes wrong

What a single independent is actually exposed to

Small stores are not too small to be caught by the same incident patterns hitting larger operators.

  • A staff lookup with no policy backstop

    Without a documented standard, a single lookup incident at a small store can escalate straight into a College and IPC matter with no prior training on record to show due diligence.

  • A claims-processing disruption

    A single independent depends on the same real-time claims networks a chain does, and an upstream outage stops dispensing just as completely at one store as at eighty.

  • Over-collection at the counter

    IPC PHIPA Decision 180 involved staff demanding health-card numbers without explaining it was voluntary, a script issue as likely at a small independent as anywhere else.

  • No plan if the store has to close or sell

    An owner nearing retirement or a sale without a documented retention plan risks losing track of the ten-year record duty during the transition.

Our mvp program for pharmacies

What the MVP engagement delivers

The program is deliberately scoped to what a single independent needs first, with a clear path to expand as the store grows.

Doctors or nurses walking in hospital hallway, blurred motion
  1. Baseline gap review

    A focused assessment of where the store currently stands against PHIPA, OCP guidance and PIPEDA, without the overhead of a full enterprise-scale audit.

  2. Core policy set

    The essential PHI policy, a lookup and disclosure standard, and a basic breach-response procedure, written for a store your size to actually use.

  3. Staff training session

    A single, practical training session covering lookups, disclosure and counter privacy for your current staff, sized to a small team.

  4. Breach log and reporting guidance

    A simple template and guidance for logging incidents and knowing when they cross the threshold for IPC or College reporting.

How the engagement runs

How the baseline program comes together

  1. Step 1

    Quick assessment

    A short review of your current practices, systems and any past incidents establishes exactly what the store needs first.

  2. Step 2

    Build the core documents

    We draft the essential PHI policy, lookup standard and breach-log template, sized for a single-location team to actually maintain.

  3. Step 3

    Train your team

    A focused session brings your staff up to speed on the policy and the standard OCP applies to lookups and disclosure.

  4. Step 4

    Set a path to grow

    We outline what to add as the store expands services or considers a VPO retainer, so the baseline is a foundation rather than a dead end.

What it costs

Pricing Minimum Viable Privacy for a pharmacy

Minimum Viable Privacy is available at $5,499 CAD per year for a single independent pharmacy, covering the baseline gap review, core policy set, staff training session and breach-log guidance described above. This is designed as a fixed, predictable cost for a one-location store that needs a defensible program without a large upfront project.

Stores that add clinical services, a second location, or a delivery integration typically outgrow the baseline and move to a Virtual Privacy Office retainer, which covers ongoing questions the fixed MVP scope does not. A short scoping call confirms MVP is the right fit before you commit.

Pharmacies: MVP program questions, answered

At minimum, a single store needs a documented PHI policy covering access and disclosure, a clear standard telling staff that unauthorized lookups are breaches on their own, a basic breach log, staff training that has actually been delivered, and a documented approach to the ten-year prescription-retention duty. MVP packages exactly these pieces into one fixed-cost engagement rather than leaving an owner to assemble them piecemeal.

It is designed for exactly that situation. A single person wearing both hats needs the accountability translated into concrete documents and a trained team, since informal knowledge in one person's head does not satisfy PHIPA's notice and safeguard expectations and disappears entirely if that person is unavailable. MVP produces the documentation your role already requires you to have.

MVP is a fixed-scope, fixed-cost baseline: a gap review, core policies, one training session and breach-log guidance. A VPO retainer adds ongoing access to a privacy advisor for the questions that come up month to month, recurring training, and continuous monitoring against regulatory change. Many independents start with MVP and move to a VPO retainer once services or staff count grow.

Yes. Even a baseline program needs to account for PIPEDA's coverage of loyalty accounts and e-commerce data, since that information sits under different rules than the dispensary's PHIPA obligations. MVP includes this as part of the core policy work rather than treating it as a separate, optional add-on.

The baseline is built to expand rather than be replaced. As you add clinical services, a second location or new vendor integrations, the core policy set becomes the foundation for deeper work rather than something you start over from, and moving to a VPO retainer at that point is a natural next step rather than a full restart.

Yes, though a recent incident with active regulatory involvement may need incident response support first. Once the immediate matter is handled, MVP is a sound way to put the missing baseline in place so the store is not exposed to the same gap again, and having a documented program in place afterward is also something regulators tend to view favourably.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.