Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Clinical care providers

Minimum Viable Privacy Program for Physiotherapy & Chiropractic Clinics

Minimum Viable Privacy gives a solo or small physiotherapy or chiropractic practice its privacy foundations in one packaged year: gap review, core policies, essential safeguards and training, for $5,499 CAD annually. It's built for the practitioner who is both the treating professional and the default PHIPA custodian, running on a single cloud EMR with no time for a sprawling consulting engagement. Clinics typically buy it when opening a new location, adding a second practitioner, or after realizing nobody has ever actually written down who owns privacy.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The essentials a small clinic must get right first

At one or two practitioners, the MVP concentrates on the handful of things where failure is existential.

The one EMR holding everything

A solo or two-practitioner clinic usually runs booking, charting and billing through a single cloud platform, so securing that one account delivers most of the available protection.

Insurer and WSIB submissions

Even a small practice treating motor-vehicle-accident or WSIB patients submits OCF forms through HCAI, and that workflow needs the same care as any larger clinic's.

Front-desk and treatment-area confidentiality

With few staff and an open gym or small waiting area, one careless conversation about a claim or diagnosis reaches every patient in earshot.

Payment terminal handling

Direct-billing co-payments running through a payment terminal need basic, correctly configured safeguards from day one, not an assumption that a small volume means low risk.

A named privacy owner

Even a solo practitioner needs a clear answer to who handles a records request or a suspected breach, rather than discovering the gap when one actually happens.

Regulatory map

Small clinic, full-size obligations

None of the duties that apply to a large rehab group are waived for a two-person practice.

Custodian status regardless of size

PHIPA's definition of a health information custodian applies to a solo physiotherapist or chiropractor exactly as it does to a 300-location group, with no size exemption.

Read our guide →

Breach reporting duties apply at any size

Notifying individuals at the first reasonable opportunity, reporting to the IPC where required, and filing annual breach counts by March 1 apply to a one-practitioner clinic the same as a larger one.

Read our guide →

College retention floors

The College of Physiotherapists' ten-year minimum, or CCO Standard S-002's seven-year minimum for chiropractic, applies from the very first chart a new practice opens.

Primary source →

HCAI applies from the first motor-vehicle-accident patient

Any clinic, regardless of size, treating a motor-vehicle-accident patient is expected to submit OCF forms through HCAI, the same system a national group uses.

Primary source →

What goes wrong

Why a small clinic can't wait to build this

Attackers and regulators don't filter by practitioner count, and a small practice has less room to absorb a mistake.

  • One compromised account exposes the whole practice

    In a two-practitioner clinic, a single compromised EMR login can expose nearly every patient the practice has ever seen, at once.

  • Nobody officially owns privacy

    When there's no named owner, a records request, a fee question or a suspected breach lands on whoever happens to answer the phone, with no established process behind them.

  • An insurer relationship stalls without documentation

    A new clinic trying to join an auto-insurer or WSIB program can find the relationship delayed by a security or privacy question it has no written answer for.

  • A first access request catches the clinic unprepared

    The first time a patient or their lawyer formally requests a copy of their file is the wrong moment to be figuring out the process and the fee for the first time.

Our mvp program for physiotherapy & chiropractic clinics

What the MVP year includes for your clinic

A fixed package, sequenced so the highest-impact items land first, built to run without hiring anyone new.

Senior man having chiropractic back adjustment. Osteopathy, Physiotherapy, pain relief concept
  1. Baseline privacy gap review

    A structured look at how the clinic's EMR use, HCAI submissions, front-desk habits and vendor relationships compare against College and PHIPA expectations, producing a short, ranked list.

  2. Prioritized control recommendations

    Directional guidance on what to fix first, typically EMR authentication, payment-terminal handling and the access-request process, chosen for impact within the practice's limited time.

  3. Core policy development

    The essential documents a small clinic needs: a patient-facing privacy policy covering insurer disclosures, a retention schedule matching the correct College standard, and a basic breach-response outline.

  4. Readiness assessment workshops

    Working sessions that prepare the practice for the situations that prompted the purchase, from an insurer's first security question to handling a records request correctly.

  5. Training with ten seats

    Role-appropriate privacy and security training with human-risk assessments for up to ten people, which covers the full staff roster of most clinics this size.

  6. Twelve hours of coaching

    Expert time to spend where the year takes you: a lock-box request, a vendor question, or help implementing a recommended safeguard.

How the engagement runs

A year of MVP in a small physio or chiro practice

  1. Step 1

    Review and rank

    The engagement opens with the gap review and a prioritized plan the practitioner can read in one sitting.

  2. Step 2

    Build the foundations

    The privacy policy, retention schedule and breach-response outline are drafted, and the first safeguards implemented with coaching support.

  3. Step 3

    Train and rehearse

    Staff complete training, and workshops rehearse the access-request process and an insurer security question the clinic is likely to face.

  4. Step 4

    Close the loop

    Remaining coaching hours handle whatever surfaced during the year, and the term ends with a clear picture of what to build next.

What it costs

MVP pricing for a small physiotherapy or chiropractic clinic

Minimum Viable Privacy is $5,499 CAD per year on a twelve-month term, covering the gap review, policy development, readiness assessment workshops, twelve hours of coaching and training with human-risk assessments for ten seats. There are no per-deliverable surprises; the package is the price.

Clinics that outgrow it, by adding practitioners, joining an insurer preferred-provider network or expanding to a second location, typically graduate to the Virtual Privacy Office retainer, and the MVP's outputs carry straight into it. Book a demo to see whether the package fits your practice.

Physiotherapy & Chiropractic Clinics: MVP program questions, answered

Five things: a named privacy owner, even if that's the practitioner themselves; a patient-facing policy that names your actual insurer and WSIB disclosures; a retention schedule matching your College's standard; MFA and basic access controls on the EMR; and trained staff who know the access-request process. That's exactly the scope the MVP builds in its opening months, sized for a clinic with no dedicated administrative staff.

You need a clear answer to who handles privacy, even as a solo practitioner, because PHIPA's custodian duties don't pause for a one-person operation. Many solo practitioners simply name themselves as the privacy contact and build a lightweight process around that, which is exactly what the MVP's gap review and policy development set up.

Yes. The foundations, gap review, policy drafting and first safeguards, are designed to land within the opening months of the term on a few hours a month from the practitioner or whoever runs the front desk, with no new headcount required. Training and workshops absorb the remaining time through the rest of the year.

Four components across the twelve-month term: the baseline privacy gap review with prioritized recommendations, development of the core policy set including your retention schedule, readiness assessment workshops, and privacy and security training with human-risk assessments for up to ten seats, plus twelve hours of coaching. It's a fixed, published price a practitioner can approve without a procurement process.

Yes, the policy work sets the retention schedule to match whichever College standard applies to each practitioner in the clinic, physiotherapy's ten-year floor or CCO Standard S-002's seven-year floor, rather than applying one number to a mixed-practice roster.

Most solo and small practices renew and use the year to deepen what exists, refreshed training, an updated policy, coaching on new questions. A practice that adds practitioners, opens a second location or starts fielding regular insurer security questions typically steps up to the Virtual Privacy Office instead, carrying every MVP deliverable forward into that retainer.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.