Skip to content
FioSec Consulting

Frameworks · Canadian & regulatory

Personal Health Information Protection Act (Ontario)

Ontario’s rules for protecting personal health information, and reporting when it’s compromised.

Maintained by
Information and Privacy Commissioner of Ontario (IPC)
Origin
Ontario, Canada · PHIPA, 2004
Certifiable?
No certificate. It is a provincial legal obligation overseen by Ontario’s IPC.

What it is

PHIPA is Ontario’s health-privacy law. It governs how "health information custodians" (the people and organizations that deliver health care) collect, use, disclose, and protect personal health information, and it gives patients rights over their own records.

For security teams, PHIPA’s significance is twofold: it requires custodians to protect personal health information with appropriate safeguards, and it requires them to notify affected individuals, and in defined circumstances the Information and Privacy Commissioner of Ontario, when that information is lost, stolen, or accessed without authority. Health data is among the most sensitive a breach can expose, so the bar is high.

Like other privacy laws, PHIPA is outcome-focused rather than prescriptive about technology. It requires "reasonable" safeguards proportionate to the sensitivity of health information, leaving custodians to choose how.

How it's structured

PHIPA frames its requirements around the custodian’s duties: collecting and using personal health information only as permitted, generally with the patient’s consent; safeguarding it against theft, loss, and unauthorized use or disclosure; giving patients access to and the ability to correct their records; and notifying individuals (and the IPC, where required) of breaches.

It also governs the agents and service providers who handle health information on a custodian’s behalf, including IT vendors, which makes third-party diligence part of compliance. The areas below group PHIPA’s expectations into what a custodian needs in place.

Custodian accountability

A designated contact person, written policies, and an information-practices program for handling personal health information.

Consent & permitted use

Collect, use, and disclose personal health information within the rules: generally with consent, and limited to what care requires.

Safeguards

Reasonable physical, organizational, and technical measures to protect health information against theft, loss, and unauthorized access.

Agents & service providers

Oversight of staff and third parties (including IT and cloud providers) who handle personal health information on the custodian’s behalf.

Patient access & correction

Patients’ rights to access their records and request corrections.

Breach notification

Notify affected individuals at the first reasonable opportunity, and the IPC in circumstances defined by the Act, when health information is compromised.

Who it's for

PHIPA applies to health information custodians in Ontario (hospitals, clinics, physicians, pharmacies, long-term care and home-care providers, and many other health-care practitioners and organizations) as well as the agents and providers acting for them.

It is directly relevant to any technology or service provider that handles personal health information on a custodian’s behalf, since the custodian remains responsible for what its providers do with that data. Vendors selling into Ontario health care should expect PHIPA obligations to flow through their contracts.

For organizations outside Ontario health care, PHIPA does not apply, but its safeguarding expectations are a strong reference for any sensitive personal data. Outside health care, PIPEDA or another provincial law generally governs instead.

How it compares

PHIPA defines the privacy outcomes an Ontario health custodian must achieve, and foundational frameworks like NIST CSF and the CIS Controls provide the safeguards and the detection and response capabilities that make those outcomes real and breach notification possible.

It is the health-specific counterpart to PIPEDA. Where PIPEDA governs commercial handling of personal information federally, PHIPA governs personal health information in Ontario. A custodian that also runs commercial activities may have both in scope, and a single well-designed security program can satisfy them together.

How it maps to a Layered Defence

PHIPA is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.

Free readiness checklist

How ready are you for PHIPA?

Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.

Accountability

Custodian responsibilities.

Have you designated a contact person and written information-practice policies for health information?
Do you know where personal health information is stored and who can reach it?

Safeguards

Protecting the records.

Is access to health records limited to authorized staff and protected with strong authentication?
Is personal health information encrypted on devices and in transit?

Agents & providers

Everyone who touches the data.

Do your agreements with IT and cloud providers bind them to protect health information appropriately?

Audit & detection

Catching misuse.

Do you log and review access to patient records so unauthorized access (snooping) would be detected?

Breach notification

When something goes wrong.

Do you have a process to notify affected individuals, and the IPC where required, after a breach?

PHIPA requires notification when health information is compromised.

No email required; scored in your browser, never sent anywhere.

Authoritative source: Information and Privacy Commissioner of Ontario: PHIPA (ipc.on.ca)

Explore other frameworks

Need help putting PHIPA into practice?

FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.