VPO · Clinical care providers
Virtual Privacy Officer for Dental Practices
A Virtual Privacy Officer becomes your dental practice's designated PHIPA contact person, the role someone on staff has to hold but rarely wants. The trigger is usually simple: no associate or office manager wants their name filed with the IPC as the point of contact, or the practice has no clear answer for how long a minor's chart must be kept. We take on that role, file what PHIPA requires, and keep your record rules aligned with RCDSO.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a dental office's privacy officer role actually covers
The designated contact person under PHIPA is a real job with real deadlines, not a title added to a business card.
Patient consent and access requests
Requests to see or correct a chart, or questions about what a patient consented to when treatment was recorded, route through the designated contact rather than whichever staff member happens to answer the phone.
Chart retention across the practice
RCDSO sets retention expectations that differ for adult and minor patients, and the VPO tracks which records in the PMS are approaching disposal eligibility versus which must be kept.
CDAnet and CDCP claims data
Insurance and federal eligibility information flowing through CDAnet, ITRANS and Sun Life Direct falls under the same custodial duties as the clinical chart, and the VPO treats it accordingly.
Associate and staff privacy questions
Associates working under the principal dentist's custodianship need clear answers about their own obligations, which the VPO documents rather than leaving to informal understanding.
Regulatory map
The obligations a dental practice's designated contact carries
PHIPA names specific duties for the contact person role, and RCDSO layers professional recordkeeping expectations on top.
The designated contact person duty
PHIPA section 15 lets a custodian name a contact person to receive complaints, respond to access requests and act on the custodian's behalf for privacy matters, a role that must be filled by someone.
Annual breach statistics to the IPC
Ontario health custodians report annual breach statistics to the Information and Privacy Commissioner by March 1 each year under section 6.4 of the regulation, whether or not the practice had an incident to report.
RCDSO's recordkeeping retention rules
RCDSO's recordkeeping guidance sets retention at ten years from the last entry, extended to age twenty-eight for records created while a patient was a minor, and addresses custodian duties on a practice's sale or closure.
Provincial rules outside Ontario
British Columbia clinics need a designated privacy officer under PIPA, and Quebec clinics need a person responsible for personal information under Law 25, each with its own notification framework.
What goes wrong
What a Virtual Privacy Officer catches before it becomes an incident
Most of what a VPO handles day to day is quiet prevention: the questions and small missteps that would otherwise turn into a complaint or an IPC finding.
Records kept past their retention window
Without an assigned owner, minor patient charts and old radiographs tend to sit indefinitely in the PMS, creating exposure that a retention schedule and periodic review are built to prevent.
Staff accessing charts out of curiosity
Curiosity-driven chart access, opening a colleague's or family member's file without a clinical reason, ranks as one of the most common self-reported privacy incidents at Ontario health custodians, and a VPO puts logging and real consequences in place before it turns into a complaint.
Records disposed of the wrong way
A patient file recovered from an office recycling bin was enough for the IPC to take enforcement action in one case, exactly the outcome a VPO's disposal checklist and periodic spot-checks are meant to rule out.
Gaps that surface only during turnover
When an associate leaves or a new hire starts, informal privacy knowledge often leaves with them; a VPO keeps the procedures documented so continuity does not depend on any one person's memory.
Our vpo for dental practices
What the Virtual Privacy Officer retainer includes for your practice
The retainer is built around the ongoing work a designated contact person actually has to do, month after month.

Acting as your designated contact person
We take the named role, handling patient inquiries, access requests and complaints so no one on staff has to carry that responsibility informally.
The March 1 IPC filing
We prepare and submit the annual breach statistics report, tracking incidents through the year so the filing is accurate rather than reconstructed at the deadline.
Retention and disposal oversight
A working retention schedule aligned to RCDSO's rules, with periodic review of what in the PMS is approaching disposal eligibility.
Policy and consent document upkeep
Ongoing review of your written information practices, consent language and patient-facing notices as the practice's systems and services change.
Vendor and CDAnet oversight
Periodic review of the PMS, imaging and recall vendors touching patient data, and how claims data moves through CDAnet, ITRANS and Sun Life Direct.
Staff training coordination
Scheduling and tracking the privacy training front desk, assistants and associates need, so the practice can show it happened rather than assuming it did.
How the engagement runs
How the VPO retainer starts and runs
Step 1
Baseline review
We review your current policies, PMS setup, retention practices and consent process to see what already meets PHIPA and RCDSO expectations.
Step 2
Take on the contact person role
We formally step into the designated contact role, updating your patient-facing notice and internal documentation to reflect it.
Step 3
Close the gaps
Retention schedules, disposal procedures and any missing policies are built or updated in the first months of the retainer.
Step 4
Run the ongoing calendar
Monthly coaching, training coordination and the March 1 filing run on a schedule, so nothing depends on someone remembering a deadline.
What it costs
What a Virtual Privacy Officer costs a dental practice
The Virtual Privacy Office retainer starts from $2,200 CAD per month, billed monthly on a 12-month term, and includes coaching hours, a designated privacy coach, incident management protocol, and training and human risk assessments for a set number of seats. For most single-location practices this replaces the need to build a privacy function in-house.
Where a group runs multiple locations or a more complex claims and imaging setup, scope and hours are adjusted accordingly. A short scoping call confirms what your practice needs before anything is billed.
Dental Practices: VPO questions, answered
PHIPA lets a custodian designate a contact person to act on their behalf, and there is no requirement that the role be filled internally. A Virtual Privacy Officer formally takes on that role, handling patient inquiries, complaints and access requests, so the practice satisfies the requirement without asking a reluctant associate or office manager to carry it alongside their clinical or administrative work.
As the health information custodian, the principal dentist carries ultimate accountability for the practice's PHIPA compliance, including breach response and the March 1 filing, even when associates are the ones treating patients day to day. Associates have their own duty of confidentiality and generally need clear, documented expectations rather than assuming custodial responsibility themselves. A VPO sets out this division explicitly so it isn't left to interpretation.
Ontario health information custodians must submit annual statistics on privacy breaches to the Information and Privacy Commissioner by March 1 each year, covering incidents from the prior year regardless of whether any were significant enough to require individual notification. A VPO tracks incidents through the year and prepares this filing so it isn't assembled from memory in February.
RCDSO's recordkeeping guidance sets retention for records created while a patient was a minor at until the patient turns twenty-eight, longer than the standard ten-year retention that applies to adult patient records. A VPO builds this distinction into your retention schedule so minor charts aren't disposed of on the same timeline as everything else in the PMS.
Yes. A practice operating in both provinces needs its Ontario PHIPA obligations and its Quebec Law 25 obligations tracked separately, since the notification triggers, filing requirements and incident-register duties differ between them. A VPO retainer covering both locations keeps each province's requirements current rather than applying an Ontario-only playbook to a Quebec clinic.
The request routes to the designated contact person, who confirms the patient's identity, coordinates with the practice to compile the relevant chart, radiographs and claims records, and responds within the timeline PHIPA expects. Documenting how the request was handled is part of the same process, so the practice has a record if the same patient or the IPC ever asks about it later.
More for dental practices
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.