VPO · Digital health & life sciences
Virtual Privacy Officer for Health Charities & Patient Organizations
A Virtual Privacy Officer answers the question most health charities never resolve on their own: which parts of your data fall under PIPEDA, which fall under PHIPA, and which run purely on consent. The VPO documents that split for your donor file, your helpline and any registry, then builds the policies, training and vendor oversight each side actually needs. Work typically starts when a registry launch, a hospital-foundation relationship or a funder's clause forces the question.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The two files a VPO keeps straight for you
Almost every mistake in this sector comes from treating donor data and patient-facing data as one file governed by one rule, when they usually are not.
The donor and prospect file
Giving history, wealth-screening notes and payment tokens generally sit outside PIPEDA as non-commercial activity, until a list is sold, bartered or leased, at which point the file becomes commercial data with consent and safeguard duties attached.
The consent basis behind helpline intake
Health-condition details shared by callers are governed by the consent given at first contact and the applicable private-sector statute, whether or not your organization meets the custodian threshold under PHIPA.
What a registry's consent has to promise
Diagnosis, treatment history or genetic information collected for a registry needs consent language built for research sharing from day one, particularly where extracts will reach a partner institution.
Hospital-foundation contact data
Where a hospital foundation receives donor-contact information from its hospital, that inbound file carries the hospital's own PHIPA obligations, not just the foundation's usual fundraising rules.
Volunteer-held information
Application forms, vulnerable-sector check results and the notes a peer-support volunteer keeps between shifts all need a documented owner, even though volunteers sit outside standard employment policies.
Regulatory map
The regulatory map a VPO builds for your organization
No single statute governs a health charity, and getting the map wrong in either direction creates real risk: overclaiming coverage wastes effort, underclaiming it misses a duty.
PIPEDA's commercial-activity test
The OPC states non-profits are usually not subject to PIPEDA because core activities like fundraising and newsletters are non-commercial, but selling, bartering or leasing a donor list is commercial activity the Act does reach.
Custodian status under PHIPA
A charity that actually delivers health care, some CMHA branches, hospices and community health programs among them, becomes a health information custodian, carrying consent, access and safeguard duties the donor office never faces.
PHIPA's hospital-to-foundation pathway
PHIPA's fundraising provision and its regulation let a custodian hospital give a foundation limited patient contact information for solicitation purposes, subject to conditions and a mandatory opt-out the foundation must honour.
Registries feeding research
Where a registry shares records with a research partner, TCPS 2 and REB review shape what the data-sharing agreement can promise about identifiability and secondary use.
CASL's narrow fundraising exemption
A commercial electronic message sent by or on behalf of a registered charity is exempt from CASL consent requirements when raising funds is its primary purpose, a narrower exemption than many fundraising teams assume.
HIPAA's narrow cross-border reach
A Canadian health charity does not become a HIPAA covered entity or business associate simply by fundraising, but HIPAA's fundraising rule binds a US institutionally related foundation and requires an opt-out in every US solicitation.
What goes wrong
Where the dual-regime confusion actually causes damage
The organizations that get hurt are rarely the ones ignoring privacy altogether; they are the ones applying the wrong regime to the wrong file.
Assuming PIPEDA covers everything, or nothing
Teams that assume blanket PIPEDA coverage over-build controls for ordinary fundraising, while teams that assume total exemption miss the moment a list rental or program fee turns an activity commercial.
Treating helpline notes like general correspondence
Health-condition disclosures made to a peer-support volunteer deserve tighter handling than a donor thank-you email, yet both often sit in the same shared inbox with the same retention habits.
Registry extracts without the promised safeguards
A research partner receiving a supposedly de-identified extract that was not properly de-identified breaks both the consent participants gave and the data-sharing agreement that authorized the transfer.
A hospital-foundation feed with no audit trail
Contact information flowing from a custodian hospital to its foundation without documented handling can turn a lawful fundraising exception into a PHIPA contravention if questioned.
Our vpo for health charities & patient organizations
What the VPO delivers for a dual-regime organization
The deliverables map onto both sides of the organization rather than treating either as an afterthought.

The applicability determination
A documented answer to which statutes and consent regimes govern your donor file, your program data and any hospital-foundation feed, revisited whenever a program or activity changes.
Custodian-status assessment
A clear finding on whether your organization is a health information custodian, with the specific duties that follow if it is.
Registry and research-consent design
Consent language and data-sharing agreement terms for registries feeding research, sized to what participants were actually told at intake.
Compliance monitoring and privacy audits
Recurring checks across the donor and program sides, each measured against the regime that actually applies to it.
Vendor and hospital-partner oversight
Ongoing review of donor CRM vendors, registry platforms and any hospital-foundation data flow against the terms they were built on.
Training tied to the determination
Privacy and security training for staff and volunteers, differentiated by whether their role touches donor data, program data, or both.
How the engagement runs
How a VPO engagement starts and continues
Step 1
Discovery across both files
We map your donor systems, program systems and every point where hospital, research or volunteer data enters, before applying a single rule.
Step 2
The regime determination
A documented finding on PIPEDA, provincial private-sector law, PHIPA custodian status and any hospital-foundation flow, reviewed with your leadership.
Step 3
Building the program around the finding
Policies, consent language, training and vendor terms are drafted to match the determination rather than a generic template.
Step 4
Ongoing coaching
Monthly hours available for whatever the determination did not anticipate: a new program, a funder question, or a registry partner's request.
What it costs
What shapes VPO pricing for this sector
Scope depends on how many distinct data regimes actually apply, whether a patient registry or hospital-foundation relationship exists, how many provinces you operate in, and how many systems and vendors need ongoing oversight. A standalone helpline charity in one province is a narrower engagement than a hospital foundation coordinating around custodian obligations.
The Virtual Privacy Office runs from $2,200 CAD a month on a 12-month term, with a designated privacy coach, monthly coaching hours, and ongoing policy and vendor review built in. We confirm the right tier after a short intake call that walks through your programs and data flows.
Health Charities & Patient Organizations: VPO questions, answered
For most core activity, likely not: the OPC treats fundraising, newsletters and donations as non-commercial, so PIPEDA generally does not reach your donor file. Selling, bartering or leasing that list is commercial activity and brings PIPEDA's consent, safeguard and breach-reporting duties into play for that specific dealing. Program revenue such as paid courses can also tip an activity into commercial territory, which is why we document the determination rather than assume it.
Only if you are actually delivering health care as part of that program, which some CMHA branches, hospices and community health services do and most peer-support and helpline programs do not. Running a support line, a navigation service or a peer group does not by itself make an organization a custodian; the test is whether health care is being provided, not whether health information is being discussed.
Participants need clear consent covering what is collected, how it may be used, and specifically whether identifiable or de-identified data will reach research partners, since those are separate promises. Where the registry feeds research, the receiving side's REB review and TCPS 2 expectations shape what your data-sharing agreement can lawfully commit to, so the consent language and the agreement need drafting together, not separately.
PHIPA's fundraising provision lets a custodian hospital share limited patient contact information, generally name and mailing details rather than clinical information, with its foundation for solicitation purposes, and the regulation requires a clear opt-out for recipients. The exact scope depends on your foundation's specific relationship with the hospital, which is why we document the actual flow rather than assume the general rule applies unchanged.
No. A registry or helpline that collects health information directly from participants on consent operates under that consent and the applicable statute, not under a vendor or business-associate relationship with any hospital or health system. The distinction matters because it means you are not negotiating a business associate agreement or a sponsor's vendor audit; you are managing consent and custodian-status questions on your own terms.
Not automatically. A Canadian charity is not a HIPAA covered entity or business associate by fundraising or by sharing registry data with a US research partner under a proper data-sharing agreement. HIPAA's fundraising provision specifically binds US covered entities disclosing limited information to their own institutionally related foundations, a different relationship than a Canadian charity's research partnership, though the agreement should still be reviewed.
More for health charities & patient organizations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.