What PHIPA Requires You to Do


Collect Only What You Need
Custodians may only collect personal health information that is reasonably necessary for a lawful purpose. Casting a wider net “just in case” is not permitted under PHIPA. If a piece of information is not needed for the care being provided, it should not be collected.Obtain Knowledgeable Consent
Consent under PHIPA must be knowledgeable — meaning the patient understands what information is being collected, why, and how it will be used. Within the circle of care (the team of providers directly involved in a patient’s treatment), consent to share information is generally assumed for care-related purposes. However, patients can always withdraw this assumed consent by expressly restricting how their information is shared.Safeguard the Information
Custodians must protect personal health information with reasonable administrative, technical, and physical safeguards. Administrative safeguards include written privacy policies, staff training, and access controls. Technical safeguards include encryption in transit and at rest, secure authentication, and audit logging. Physical safeguards include locked filing cabinets, restricted-access areas, and secure disposal of paper records. The Canadian Centre for Cyber Security’s baseline controls is a practical starting point for smaller custodians.Give Patients Access to Their Records
Individuals have the right to see their own personal health information and to request corrections if something is inaccurate. Custodians must respond within 30 days in most cases. Denial of access is only permitted in narrow circumstances — such as when disclosure would create a serious risk of harm.Maintain a Written Information Practices Statement
Every custodian must have a written statement describing their information practices — what they collect, how they use it, how it is protected, and how to contact them with questions. This must be made available to patients.PHIPA Breach Notification: What Happens When Something Goes Wrong
A privacy breach is any loss, theft, or unauthorized use or disclosure of personal health information. PHIPA has specific notification requirements when a breach happens. Custodians must notify the affected individual at the first reasonable opportunity. In practice, that means as soon as the scope of the breach is understood — not weeks or months later. Since 2019, custodians must also notify the Information and Privacy Commissioner of Ontario (IPC) when a breach meets one of several thresholds. These include:- The breach involved the use or disclosure of PHI without authority
- A pattern of similar breaches has emerged
- The custodian disciplined or dismissed a staff member because of the breach
- The breach was significant enough to require notification of a professional regulator
PHIPA vs. PIPEDA vs. HIPAA: How the Laws Compare
If you handle personal health information across borders or across sectors, you may find yourself asking how PHIPA stacks up against Canada’s federal privacy law and the American equivalent. Here is the short version.| PHIPA (Ontario) | PIPEDA (Canada) | HIPAA (United States) | |
|---|---|---|---|
| Jurisdiction | Ontario health sector | Federal — commercial activities | US health sector |
| Applies to | Health information custodians | Businesses in commercial activities | Covered entities and business associates |
| Information covered | Personal health information | Personal information | Protected health information |
| Consent model | Knowledgeable consent, circle-of-care assumption | Meaningful consent | Notice of Privacy Practices |
| Breach reporting | To individuals and the IPC (Ontario) | To the Privacy Commissioner and affected individuals | To individuals, HHS, and sometimes media |
| Maximum fines | Up to $200,000 (individual), $1M (organization) | Up to $100,000 per violation | Up to $1.5M per violation category, per year |
How to Share Patient Information Securely


Meeting PHIPA’s safeguard requirements is straightforward on paper: use reasonable administrative, technical, and physical measures. In practice, the technical piece — how you actually move a patient’s file from one custodian to another — is where most practices struggle.
Email is the default for a reason: it is easy and free. However, standard email was never designed with patient confidentiality in mind. Messages travel in plain text across multiple servers, and a single typo in an address can send a lab result to the wrong person entirely. This is why the IPC’s own guidance treats unencrypted email as inadequate for personal health information.
Fax is technically still permitted and is widely used in Ontario health care. However, faxing has real risks: a misdialed number, an unattended fax machine at the receiving end, or a shared fax line in a busy office can each expose a patient’s information. Consequently, fax-based transfers should be accompanied by a phone confirmation and a clear cover sheet indicating urgency and recipient.
Couriers and physical mail avoid the electronic risks but add cost, delay, and their own chain-of-custody problems. A misdelivered envelope is just as much a breach as a misdirected email.
Encrypted digital transfer tools address the core problems in one step. The file is encrypted in transit and at rest, the recipient is authenticated before they can access it, and every transfer leaves an audit trail. For most Ontario custodians, this is the safest and simplest way to share patient records with another provider, with a patient, or with a family member.
Common PHIPA Mistakes to Avoid
Even well-intentioned practices slip up on PHIPA. Here are the mistakes the IPC sees repeatedly:- Emailing patient records to another clinic without encryption. Convenience wins, and a routine referral goes out over unencrypted email.
- Faxing to a general fax number instead of a secure line. Fax machines shared across a large office are effectively broadcast tools.
- Sharing login credentials among staff. Shared accounts destroy the audit trail — a core PHIPA requirement.
- Failing to keep an access log. Custodians must be able to answer “who accessed what, when.” Many small practices cannot.
- Not training staff on PHIPA basics. A single untrained receptionist can expose a full patient list in an afternoon.
- Discarding paper records in unsecured recycling. Confidential shredding is not optional.
- Skipping the written information practices statement. Many small custodians assume it does not apply to them. It does.
- Ignoring the annual breach statistics report. Zero breaches is still a report the IPC expects to receive.
Frequently Asked Questions About PHIPA
Does PHIPA apply to my small clinic?
Yes. PHIPA applies to any health information custodian in Ontario, regardless of size. A one-physician family practice or a solo dental office is subject to the same core obligations as a large hospital. The specific safeguards can scale to your practice, but the legal duty to protect personal health information and respond to breaches applies equally.How is PHIPA different from PIPEDA?
PHIPA governs personal health information collected by Ontario health information custodians. PIPEDA governs personal information collected by businesses in commercial activities across Canada. Because Ontario’s PHIPA is deemed substantially similar to PIPEDA for personal health information, PHIPA takes precedence within Ontario’s health sector.What are the penalties for a PHIPA violation?
Individuals can face fines of up to $200,000 and imprisonment of up to one year for willful offences. Organizations face fines of up to $1,000,000. Beyond fines, custodians risk civil lawsuits, loss of professional licensing, and lasting damage to patient trust. The IPC also has order-making authority.How do I send patient records to another clinic in compliance with PHIPA?
You need a channel with strong safeguards — encryption in transit and at rest, recipient authentication, and an audit trail. Encrypted transfer platforms let you send records without printing, faxing, or mailing. Confirm the receiving clinic can access the file securely, log the transfer, and keep proof of delivery for your records.What is the circle of care under PHIPA?
The circle of care is the group of health care providers involved in providing care to a specific patient. Within the circle of care, consent to share personal health information is generally assumed for care-related purposes. However, patients can withhold or withdraw this assumed consent at any time.Do I have to notify the IPC of every privacy breach?
Not every breach. You must notify the IPC when the breach meets specific thresholds — unauthorized use or disclosure, a pattern of similar incidents, staff discipline related to the breach, or notification of a professional regulator. Since 2019, custodians must also submit annual statistics on all breaches, even minor ones.Sources
This article draws on the following sources.- Information and Privacy Commissioner of Ontario. Reporting a Privacy Breach to the IPC. ipc.on.ca
- Government of Ontario. Personal Health Information Protection Act, 2004. ontario.ca
- Office of the Privacy Commissioner of Canada. Substantially Similar Provincial Legislation. priv.gc.ca
- Canadian Centre for Cyber Security. Baseline Cyber Security Controls for Small and Medium Organizations. cyber.gc.ca



