What Is PHIPA? Ontario’s Health Privacy Law Explained

July 14, 2026

Medical folder with stethoscope and a glowing green padlock representing PHIPA-protected patient information
Under PHIPA, every patient record is protected by law.
Every prescription refill, every referral letter, and every lab result you handle in Ontario is governed by a single provincial law. Yet many family clinics, dentists, and allied health professionals remain fuzzy on what it actually requires — and where the real risks lie. PHIPA — Ontario’s Personal Health Information Protection Act — sets the rules for how personal health information can be collected, used, disclosed, and disposed of. It applies to health information custodians such as hospitals, family physicians, dentists, pharmacies, and long-term care homes. Compliance is not optional; it is provincial law. The full statute is published on the Government of Ontario’s legislation portal.

Who Does PHIPA Apply To?

A modern medical clinic reception area representing the wide range of Ontario health information custodians PHIPA covers
PHIPA covers hospitals, family practices, dental offices, pharmacies, and their agents.
PHIPA applies to health information custodians in Ontario — the individuals and organizations that collect and hold personal health information in the course of providing health care. This includes hospitals, family physicians, dentists, pharmacies, long-term care homes, chiropractors, psychologists, and the Ministry of Health itself. It also captures their agents. A health information custodian is a defined term under PHIPA, and the definition is broad. Anyone providing a covered health care service is generally captured. However, the coverage does not stop at licensed practitioners. PHIPA also applies to agents of a custodian — anyone acting on behalf of the custodian with respect to personal health information. This includes clinic staff, billing companies, transcription services, and IT vendors. Consequently, if you handle patient information for a doctor’s office, PHIPA obligations extend to you too. Specifically, custodians include:
  • Hospitals and independent health facilities
  • Family physicians, specialists, and their offices
  • Dentists, denturists, and dental hygienists
  • Pharmacies and pharmacists
  • Long-term care homes, retirement homes, and homes for special care
  • Chiropractors, physiotherapists, occupational therapists, and psychologists
  • Community care access centres and home-care agencies
  • Ambulance services and paramedics
  • Laboratories and diagnostic imaging facilities
  • The Ministry of Health and Long-Term Care
Not every organization that handles health information is a custodian. Employers, for example, are generally not custodians under PHIPA — even if they hold employee health information — because they are not providing health care. Insurers, likewise, sit outside PHIPA in most contexts.

What Counts as Personal Health Information Under PHIPA?

Personal health information (PHI) under PHIPA is defined broadly. It covers any identifying information about an individual that relates to their physical or mental health, the health care they have received, or their eligibility for coverage. Specifically, PHI includes:
  • Physical or mental health information — diagnoses, symptoms, treatment records
  • Health care received — visit notes, procedures, prescriptions
  • Payment for health care — billing records, OHIP claims, insurance information
  • Health card numbers — including any part of a health card number
  • Substitute decision-maker information — the identity and contact details of anyone authorized to act on the patient’s behalf
  • Family health history — where it appears in the patient’s own record
  • Body parts or bodily substances — including samples taken for testing
  • Genetic information — any information derived from testing genetic material
A single referral letter can contain most of these categories at once. A pharmacy prescription form contains at least four. The point is that PHIPA does not distinguish between a “sensitive” file and an “administrative” one — if it can identify a patient and relates to their care, it is protected.

What PHIPA Requires You to Do

A glowing green PHIPA compliance checklist representing the core obligations custodians must meet
PHIPA obligations scale with the size of your practice, but every custodian meets all of them.
PHIPA is built around a small number of core obligations. Every custodian — from a solo dental practice to a regional hospital — is expected to meet all of them, at a level of rigor that fits the size and complexity of the practice.

Collect Only What You Need

Custodians may only collect personal health information that is reasonably necessary for a lawful purpose. Casting a wider net “just in case” is not permitted under PHIPA. If a piece of information is not needed for the care being provided, it should not be collected.

Obtain Knowledgeable Consent

Consent under PHIPA must be knowledgeable — meaning the patient understands what information is being collected, why, and how it will be used. Within the circle of care (the team of providers directly involved in a patient’s treatment), consent to share information is generally assumed for care-related purposes. However, patients can always withdraw this assumed consent by expressly restricting how their information is shared.

Safeguard the Information

Custodians must protect personal health information with reasonable administrative, technical, and physical safeguards. Administrative safeguards include written privacy policies, staff training, and access controls. Technical safeguards include encryption in transit and at rest, secure authentication, and audit logging. Physical safeguards include locked filing cabinets, restricted-access areas, and secure disposal of paper records. The Canadian Centre for Cyber Security’s baseline controls is a practical starting point for smaller custodians.

Give Patients Access to Their Records

Individuals have the right to see their own personal health information and to request corrections if something is inaccurate. Custodians must respond within 30 days in most cases. Denial of access is only permitted in narrow circumstances — such as when disclosure would create a serious risk of harm.

Maintain a Written Information Practices Statement

Every custodian must have a written statement describing their information practices — what they collect, how they use it, how it is protected, and how to contact them with questions. This must be made available to patients.

PHIPA Breach Notification: What Happens When Something Goes Wrong

A privacy breach is any loss, theft, or unauthorized use or disclosure of personal health information. PHIPA has specific notification requirements when a breach happens. Custodians must notify the affected individual at the first reasonable opportunity. In practice, that means as soon as the scope of the breach is understood — not weeks or months later. Since 2019, custodians must also notify the Information and Privacy Commissioner of Ontario (IPC) when a breach meets one of several thresholds. These include:
  • The breach involved the use or disclosure of PHI without authority
  • A pattern of similar breaches has emerged
  • The custodian disciplined or dismissed a staff member because of the breach
  • The breach was significant enough to require notification of a professional regulator
In addition to individual breach reporting, custodians must submit annual statistics on all privacy breaches to the IPC — not just the ones that triggered individual notification. This applies even to a solo practice with a small number of incidents. Consequently, keeping a running breach log throughout the year has become a practical necessity.

PHIPA vs. PIPEDA vs. HIPAA: How the Laws Compare

If you handle personal health information across borders or across sectors, you may find yourself asking how PHIPA stacks up against Canada’s federal privacy law and the American equivalent. Here is the short version.
PHIPA (Ontario) PIPEDA (Canada) HIPAA (United States)
Jurisdiction Ontario health sector Federal — commercial activities US health sector
Applies to Health information custodians Businesses in commercial activities Covered entities and business associates
Information covered Personal health information Personal information Protected health information
Consent model Knowledgeable consent, circle-of-care assumption Meaningful consent Notice of Privacy Practices
Breach reporting To individuals and the IPC (Ontario) To the Privacy Commissioner and affected individuals To individuals, HHS, and sometimes media
Maximum fines Up to $200,000 (individual), $1M (organization) Up to $100,000 per violation Up to $1.5M per violation category, per year
Ontario is deemed to have a substantially similar law to PIPEDA for personal health information. Consequently, within the Ontario health sector, PHIPA takes precedence over PIPEDA. The Office of the Privacy Commissioner of Canada maintains the current list of substantially similar provincial laws. Cross-border transfers to the United States — for example, sharing records with an American specialist — still trigger PHIPA obligations, and the receiving party is expected to meet comparable safeguards.

How to Share Patient Information Securely

A medical document with a green padlock icon on a laptop screen representing encrypted patient record transfer under PHIPA
Encrypted digital transfer addresses PHIPA’s safeguard requirements in one step.

Meeting PHIPA’s safeguard requirements is straightforward on paper: use reasonable administrative, technical, and physical measures. In practice, the technical piece — how you actually move a patient’s file from one custodian to another — is where most practices struggle.

Email is the default for a reason: it is easy and free. However, standard email was never designed with patient confidentiality in mind. Messages travel in plain text across multiple servers, and a single typo in an address can send a lab result to the wrong person entirely. This is why the IPC’s own guidance treats unencrypted email as inadequate for personal health information.

Fax is technically still permitted and is widely used in Ontario health care. However, faxing has real risks: a misdialed number, an unattended fax machine at the receiving end, or a shared fax line in a busy office can each expose a patient’s information. Consequently, fax-based transfers should be accompanied by a phone confirmation and a clear cover sheet indicating urgency and recipient.

Couriers and physical mail avoid the electronic risks but add cost, delay, and their own chain-of-custody problems. A misdelivered envelope is just as much a breach as a misdirected email.

Encrypted digital transfer tools address the core problems in one step. The file is encrypted in transit and at rest, the recipient is authenticated before they can access it, and every transfer leaves an audit trail. For most Ontario custodians, this is the safest and simplest way to share patient records with another provider, with a patient, or with a family member.

Common PHIPA Mistakes to Avoid

Even well-intentioned practices slip up on PHIPA. Here are the mistakes the IPC sees repeatedly:
  • Emailing patient records to another clinic without encryption. Convenience wins, and a routine referral goes out over unencrypted email.
  • Faxing to a general fax number instead of a secure line. Fax machines shared across a large office are effectively broadcast tools.
  • Sharing login credentials among staff. Shared accounts destroy the audit trail — a core PHIPA requirement.
  • Failing to keep an access log. Custodians must be able to answer “who accessed what, when.” Many small practices cannot.
  • Not training staff on PHIPA basics. A single untrained receptionist can expose a full patient list in an afternoon.
  • Discarding paper records in unsecured recycling. Confidential shredding is not optional.
  • Skipping the written information practices statement. Many small custodians assume it does not apply to them. It does.
  • Ignoring the annual breach statistics report. Zero breaches is still a report the IPC expects to receive.

Frequently Asked Questions About PHIPA

Does PHIPA apply to my small clinic?

Yes. PHIPA applies to any health information custodian in Ontario, regardless of size. A one-physician family practice or a solo dental office is subject to the same core obligations as a large hospital. The specific safeguards can scale to your practice, but the legal duty to protect personal health information and respond to breaches applies equally.

How is PHIPA different from PIPEDA?

PHIPA governs personal health information collected by Ontario health information custodians. PIPEDA governs personal information collected by businesses in commercial activities across Canada. Because Ontario’s PHIPA is deemed substantially similar to PIPEDA for personal health information, PHIPA takes precedence within Ontario’s health sector.

What are the penalties for a PHIPA violation?

Individuals can face fines of up to $200,000 and imprisonment of up to one year for willful offences. Organizations face fines of up to $1,000,000. Beyond fines, custodians risk civil lawsuits, loss of professional licensing, and lasting damage to patient trust. The IPC also has order-making authority.

How do I send patient records to another clinic in compliance with PHIPA?

You need a channel with strong safeguards — encryption in transit and at rest, recipient authentication, and an audit trail. Encrypted transfer platforms let you send records without printing, faxing, or mailing. Confirm the receiving clinic can access the file securely, log the transfer, and keep proof of delivery for your records.

What is the circle of care under PHIPA?

The circle of care is the group of health care providers involved in providing care to a specific patient. Within the circle of care, consent to share personal health information is generally assumed for care-related purposes. However, patients can withhold or withdraw this assumed consent at any time.

Do I have to notify the IPC of every privacy breach?

Not every breach. You must notify the IPC when the breach meets specific thresholds — unauthorized use or disclosure, a pattern of similar incidents, staff discipline related to the breach, or notification of a professional regulator. Since 2019, custodians must also submit annual statistics on all breaches, even minor ones.

Sources

This article draws on the following sources.
  • Information and Privacy Commissioner of Ontario. Reporting a Privacy Breach to the IPC. ipc.on.ca
  • Government of Ontario. Personal Health Information Protection Act, 2004. ontario.ca
  • Office of the Privacy Commissioner of Canada. Substantially Similar Provincial Legislation. priv.gc.ca
  • Canadian Centre for Cyber Security. Baseline Cyber Security Controls for Small and Medium Organizations. cyber.gc.ca
Knowing that a patient’s file is protected by strong encryption and delivered only to the recipient you named — no misrouted fax, no lost courier package, no unencrypted email inbox — is the kind of certainty that turns a routine referral into a compliance non-issue. This is where SureSend comes into the picture: a simple way to send patient records to another custodian, a patient, or a family member with encryption in transit and at rest, recipient authentication, and a full audit trail.

Related Posts