Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

VPO · Digital health & life sciences

Virtual Privacy Officer for Health Charities & Patient Organizations

A Virtual Privacy Officer answers the question most health charities never resolve on their own: which parts of your data fall under PIPEDA, which fall under PHIPA, and which run purely on consent. The VPO documents that split for your donor file, your helpline and any registry, then builds the policies, training and vendor oversight each side actually needs. Work typically starts when a registry launch, a hospital-foundation relationship or a funder's clause forces the question.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The two files a VPO keeps straight for you

Almost every mistake in this sector comes from treating donor data and patient-facing data as one file governed by one rule, when they usually are not.

The donor and prospect file

Giving history, wealth-screening notes and payment tokens generally sit outside PIPEDA as non-commercial activity, until a list is sold, bartered or leased, at which point the file becomes commercial data with consent and safeguard duties attached.

The consent basis behind helpline intake

Health-condition details shared by callers are governed by the consent given at first contact and the applicable private-sector statute, whether or not your organization meets the custodian threshold under PHIPA.

What a registry's consent has to promise

Diagnosis, treatment history or genetic information collected for a registry needs consent language built for research sharing from day one, particularly where extracts will reach a partner institution.

Hospital-foundation contact data

Where a hospital foundation receives donor-contact information from its hospital, that inbound file carries the hospital's own PHIPA obligations, not just the foundation's usual fundraising rules.

Volunteer-held information

Application forms, vulnerable-sector check results and the notes a peer-support volunteer keeps between shifts all need a documented owner, even though volunteers sit outside standard employment policies.

Regulatory map

The regulatory map a VPO builds for your organization

No single statute governs a health charity, and getting the map wrong in either direction creates real risk: overclaiming coverage wastes effort, underclaiming it misses a duty.

PIPEDA's commercial-activity test

The OPC states non-profits are usually not subject to PIPEDA because core activities like fundraising and newsletters are non-commercial, but selling, bartering or leasing a donor list is commercial activity the Act does reach.

Primary source →

Custodian status under PHIPA

A charity that actually delivers health care, some CMHA branches, hospices and community health programs among them, becomes a health information custodian, carrying consent, access and safeguard duties the donor office never faces.

Read our guide →

PHIPA's hospital-to-foundation pathway

PHIPA's fundraising provision and its regulation let a custodian hospital give a foundation limited patient contact information for solicitation purposes, subject to conditions and a mandatory opt-out the foundation must honour.

Read our guide →

Registries feeding research

Where a registry shares records with a research partner, TCPS 2 and REB review shape what the data-sharing agreement can promise about identifiability and secondary use.

Primary source →

CASL's narrow fundraising exemption

A commercial electronic message sent by or on behalf of a registered charity is exempt from CASL consent requirements when raising funds is its primary purpose, a narrower exemption than many fundraising teams assume.

Primary source →

HIPAA's narrow cross-border reach

A Canadian health charity does not become a HIPAA covered entity or business associate simply by fundraising, but HIPAA's fundraising rule binds a US institutionally related foundation and requires an opt-out in every US solicitation.

Primary source →

What goes wrong

Where the dual-regime confusion actually causes damage

The organizations that get hurt are rarely the ones ignoring privacy altogether; they are the ones applying the wrong regime to the wrong file.

  • Assuming PIPEDA covers everything, or nothing

    Teams that assume blanket PIPEDA coverage over-build controls for ordinary fundraising, while teams that assume total exemption miss the moment a list rental or program fee turns an activity commercial.

  • Treating helpline notes like general correspondence

    Health-condition disclosures made to a peer-support volunteer deserve tighter handling than a donor thank-you email, yet both often sit in the same shared inbox with the same retention habits.

  • Registry extracts without the promised safeguards

    A research partner receiving a supposedly de-identified extract that was not properly de-identified breaks both the consent participants gave and the data-sharing agreement that authorized the transfer.

  • A hospital-foundation feed with no audit trail

    Contact information flowing from a custodian hospital to its foundation without documented handling can turn a lawful fundraising exception into a PHIPA contravention if questioned.

Our vpo for health charities & patient organizations

What the VPO delivers for a dual-regime organization

The deliverables map onto both sides of the organization rather than treating either as an afterthought.

Skilled team of developers using modern technologies for testing application online showing to leader, multiracial young crew of students concentrated on working process watching v
  1. The applicability determination

    A documented answer to which statutes and consent regimes govern your donor file, your program data and any hospital-foundation feed, revisited whenever a program or activity changes.

  2. Custodian-status assessment

    A clear finding on whether your organization is a health information custodian, with the specific duties that follow if it is.

  3. Registry and research-consent design

    Consent language and data-sharing agreement terms for registries feeding research, sized to what participants were actually told at intake.

  4. Compliance monitoring and privacy audits

    Recurring checks across the donor and program sides, each measured against the regime that actually applies to it.

  5. Vendor and hospital-partner oversight

    Ongoing review of donor CRM vendors, registry platforms and any hospital-foundation data flow against the terms they were built on.

  6. Training tied to the determination

    Privacy and security training for staff and volunteers, differentiated by whether their role touches donor data, program data, or both.

How the engagement runs

How a VPO engagement starts and continues

  1. Step 1

    Discovery across both files

    We map your donor systems, program systems and every point where hospital, research or volunteer data enters, before applying a single rule.

  2. Step 2

    The regime determination

    A documented finding on PIPEDA, provincial private-sector law, PHIPA custodian status and any hospital-foundation flow, reviewed with your leadership.

  3. Step 3

    Building the program around the finding

    Policies, consent language, training and vendor terms are drafted to match the determination rather than a generic template.

  4. Step 4

    Ongoing coaching

    Monthly hours available for whatever the determination did not anticipate: a new program, a funder question, or a registry partner's request.

What it costs

What shapes VPO pricing for this sector

Scope depends on how many distinct data regimes actually apply, whether a patient registry or hospital-foundation relationship exists, how many provinces you operate in, and how many systems and vendors need ongoing oversight. A standalone helpline charity in one province is a narrower engagement than a hospital foundation coordinating around custodian obligations.

The Virtual Privacy Office runs from $2,200 CAD a month on a 12-month term, with a designated privacy coach, monthly coaching hours, and ongoing policy and vendor review built in. We confirm the right tier after a short intake call that walks through your programs and data flows.

Health Charities & Patient Organizations: VPO questions, answered

For most core activity, likely not: the OPC treats fundraising, newsletters and donations as non-commercial, so PIPEDA generally does not reach your donor file. Selling, bartering or leasing that list is commercial activity and brings PIPEDA's consent, safeguard and breach-reporting duties into play for that specific dealing. Program revenue such as paid courses can also tip an activity into commercial territory, which is why we document the determination rather than assume it.

Only if you are actually delivering health care as part of that program, which some CMHA branches, hospices and community health services do and most peer-support and helpline programs do not. Running a support line, a navigation service or a peer group does not by itself make an organization a custodian; the test is whether health care is being provided, not whether health information is being discussed.

Participants need clear consent covering what is collected, how it may be used, and specifically whether identifiable or de-identified data will reach research partners, since those are separate promises. Where the registry feeds research, the receiving side's REB review and TCPS 2 expectations shape what your data-sharing agreement can lawfully commit to, so the consent language and the agreement need drafting together, not separately.

PHIPA's fundraising provision lets a custodian hospital share limited patient contact information, generally name and mailing details rather than clinical information, with its foundation for solicitation purposes, and the regulation requires a clear opt-out for recipients. The exact scope depends on your foundation's specific relationship with the hospital, which is why we document the actual flow rather than assume the general rule applies unchanged.

No. A registry or helpline that collects health information directly from participants on consent operates under that consent and the applicable statute, not under a vendor or business-associate relationship with any hospital or health system. The distinction matters because it means you are not negotiating a business associate agreement or a sponsor's vendor audit; you are managing consent and custodian-status questions on your own terms.

Not automatically. A Canadian charity is not a HIPAA covered entity or business associate by fundraising or by sharing registry data with a US research partner under a proper data-sharing agreement. HIPAA's fundraising provision specifically binds US covered entities disclosing limited information to their own institutionally related foundations, a different relationship than a Canadian charity's research partnership, though the agreement should still be reviewed.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.