Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Ontario Health Privacy

PHIPA Compliance for Ontario Health Custodians

The Personal Health Information Protection Act sets the rules for every hospital, clinic, pharmacy, lab and health-tech vendor that handles personal health information in Ontario. We help you meet them, prove it, and keep patient trust.

The Basics

What PHIPA is and who it applies to

PHIPA — Ontario’s Personal Health Information Protection Act, 2004 — governs how personal health information (PHI) is collected, used, disclosed, retained and protected in the province. It is overseen by the Information and Privacy Commissioner of Ontario (IPC), which investigates complaints and breaches, issues orders and, since 2024, can impose administrative penalties directly.

The Act applies to health information custodians — hospitals, long-term care homes, pharmacies, laboratories, physicians and other regulated health professionals, and community care providers. It follows PHI to the custodian’s agents (employees, contractors and vendors acting on its behalf) and imposes duties on electronic service providers that host or process PHI. If you build software for Ontario clinics, you are inside PHIPA’s scope even though you are not a custodian.

Our explainer What is PHIPA?covers the fundamentals, andthe Canadian privacy law landscapeshows how PHIPA sits alongsidePIPEDA and, for teams serving US customers,HIPAA.

Health Information Custodians

Hospitals, long-term care homes, pharmacies, laboratories, physicians and other regulated health professionals, and community care providers — the organizations PHIPA holds accountable.

Agents

Employees, contractors and vendors who handle personal health information on a custodian’s behalf. The custodian stays responsible; the agent inherits the rules.

Electronic Service Providers

Health-tech vendors that host, process or transmit PHI for custodians have their own PHIPA duties, even though they are not custodians themselves.

Key Requirements

What PHIPA requires of a custodian

Clinician reviewing patient records on a tablet — personal health information protected under Ontario’s PHIPA
  1. A designated contact person

    Every custodian must designate someone responsible for its information practices, for handling complaints and access requests, and for ensuring agents know the rules.

  2. A written statement of information practices

    A plain-language public statement describing what personal health information you collect, why, how it is protected, and how patients can exercise their rights.

  3. Knowledgeable consent

    Consent that may be implied within the circle of care and must be express outside it, with the ability for patients to withhold or withdraw it (the “lockbox”).

  4. Reasonable safeguards

    Administrative, technical and physical measures against theft, loss and unauthorized access — including audit logs, role-based access and written agreements with agents.

  5. Access and correction rights

    Patients can request their records and ask for corrections; custodians must respond within the timelines the Act sets out.

  6. Breach notification and reporting

    Notify affected individuals at the first reasonable opportunity, report prescribed breaches to the Information and Privacy Commissioner, and file annual breach statistics with the IPC.

Our Services

Our PHIPA compliance services

A complete approach to health-information privacy, from the first PIA to the annual IPC statistics filing.

Privacy Impact Assessments (PIA)

A systematic evaluation of how a new system, program or vendor collects, uses and discloses personal health information, so risks surface before go-live rather than after.

Policy & Procedure Development

The mandatory information-practices statement, privacy and security policies, breach protocols, consent language and agent agreements, written for your setting.

Staff Privacy Training

Role-based training so clinicians, administrators and vendors understand their PHIPA obligations — the single biggest reducer of snooping and human-error breaches.

Breach Response Management

Containment, harm assessment, patient notification and IPC reporting handled with you in the moment, plus the annual statistics filing.

Vendor & Agent Reviews

Due diligence on the electronic service providers and agents that touch PHI, and the agreements that make their obligations enforceable.

Ongoing Privacy Office

A Virtual Privacy Officer who acts as, or supports, your designated contact person and keeps the program current as the IPC’s expectations evolve.

Start with aPrivacy Impact Assessmentor aThreat and Risk Assessment, addpolicy development andcustom training, and keep it running with aVirtual Privacy Officer. For a fixed-scope starting point, seeMinimum Viable Privacy.

Why It Matters

Why PHIPA compliance matters

Compliance isn’t only about avoiding fines — it’s about patient trust. In a digital health system, demonstrably good privacy practice is a competitive advantage.

Avoid Prosecution and Penalties

Since the 2020 amendments, offences carry fines of up to $200,000 and/or a year in prison for individuals and up to $1,000,000 for organizations — and since January 2024 the IPC can impose administrative penalties of up to $50,000 and $500,000 without a prosecution.

Secure Funding and Partnerships

Ontario Health Teams, hospital procurement and government funding programs increasingly require demonstrable PHIPA compliance before they will work with you.

Build Patient Confidence

Patients share more, and more accurately, when they trust that their health information is handled with care — and that trust is what a breach destroys.

How We Work

From scope to a sustained privacy program in four steps

  1. Scope

    Confirm whether you are a custodian, an agent or an electronic service provider, and map every place personal health information flows.

  2. Assess

    Measure your information practices, safeguards and agreements against the Act and the IPC’s guidance; run PIAs on anything new.

  3. Remediate

    Close the gaps in priority order — contact person, public statement, policies, training, vendor agreements, breach playbook.

  4. Sustain

    Keep the program alive with annual reviews, IPC statistics filing and a privacy officer who answers the phone when something goes wrong.

FAQ

PHIPA compliance questions, answered

Short answers to what Ontario custodians and health-tech vendors ask us most.

A health information custodian is a person or organization that has custody or control of personal health information because of its work: hospitals, long-term care homes, pharmacies, laboratories, physicians and other regulated health professionals, community care providers and similar bodies. Custodians carry the Act’s core obligations, and they remain accountable for the agents and vendors they allow to handle that information.

Yes, in two ways. If you handle personal health information on a custodian’s behalf you are its agent and must follow the custodian’s rules and the Act’s limits. If you supply services that enable a custodian to collect, use, store or transmit PHI electronically, you are an electronic service provider with your own duties, such as not using the information for your own purposes and supporting the custodian’s safeguards. Either way, expect procurement teams to ask for a PIA and evidence of controls.

Since the 2020 amendments, a person convicted of an offence under PHIPA can be fined up to $200,000 and/or imprisoned for up to a year, and an organization can be fined up to $1,000,000. Since January 1, 2024 the Information and Privacy Commissioner can also impose administrative monetary penalties directly — up to $50,000 for individuals and $500,000 for organizations — without a prosecution. Orders, public reports and the cost of notifying patients come on top.

Affected individuals must be notified at the first reasonable opportunity whenever their personal health information is stolen, lost, or used or disclosed without authority. Certain categories of breach — for example, deliberate snooping, breaches involving a pattern or a large number of people, or those reported to a regulatory college — must also be reported to the IPC, and every custodian files annual breach statistics with the Commissioner regardless of whether any single breach met the reporting threshold.

A PIA is the recognized way to show you identified and managed the privacy risks of a new system, program or vendor before it went live, and Ontario Health, hospitals and the IPC routinely expect one for anything that touches personal health information. Beyond the paperwork, it is the exercise that catches unnecessary collection, weak access controls and vendor gaps while they are still cheap to fix.

PHIPA has been declared substantially similar to the federal PIPEDA for health information custodians, so within Ontario it is PHIPA, not PIPEDA, that governs their handling of personal health information. PIPEDA can still apply to the same organization’s other commercial activity and to information that crosses provincial or national borders, which is why many health-tech companies answer to both.

The contact person is the custodian’s accountable privacy lead: they make sure the organization complies with the Act, ensure agents are informed of their duties, handle access and correction requests, respond to inquiries and complaints, and act as the point of contact for the IPC. Smaller custodians often fill the role with an outsourced privacy officer rather than a full-time hire.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

What do you need a quote for? (select all that apply)

We only use your details to respond to this request.