Custodian accountability
A designated contact person, written policies, and an information-practices program for handling personal health information.
Frameworks · Canadian & regulatory
Ontario’s rules for protecting personal health information, and reporting when it’s compromised.
PHIPA is Ontario’s health-privacy law. It governs how "health information custodians" (the people and organizations that deliver health care) collect, use, disclose, and protect personal health information, and it gives patients rights over their own records.
For security teams, PHIPA’s significance is twofold: it requires custodians to protect personal health information with appropriate safeguards, and it requires them to notify affected individuals, and in defined circumstances the Information and Privacy Commissioner of Ontario, when that information is lost, stolen, or accessed without authority. Health data is among the most sensitive a breach can expose, so the bar is high.
Like other privacy laws, PHIPA is outcome-focused rather than prescriptive about technology. It requires "reasonable" safeguards proportionate to the sensitivity of health information, leaving custodians to choose how.
PHIPA frames its requirements around the custodian’s duties: collecting and using personal health information only as permitted, generally with the patient’s consent; safeguarding it against theft, loss, and unauthorized use or disclosure; giving patients access to and the ability to correct their records; and notifying individuals (and the IPC, where required) of breaches.
It also governs the agents and service providers who handle health information on a custodian’s behalf, including IT vendors, which makes third-party diligence part of compliance. The areas below group PHIPA’s expectations into what a custodian needs in place.
A designated contact person, written policies, and an information-practices program for handling personal health information.
Collect, use, and disclose personal health information within the rules: generally with consent, and limited to what care requires.
Reasonable physical, organizational, and technical measures to protect health information against theft, loss, and unauthorized access.
Oversight of staff and third parties (including IT and cloud providers) who handle personal health information on the custodian’s behalf.
Patients’ rights to access their records and request corrections.
Notify affected individuals at the first reasonable opportunity, and the IPC in circumstances defined by the Act, when health information is compromised.
PHIPA applies to health information custodians in Ontario (hospitals, clinics, physicians, pharmacies, long-term care and home-care providers, and many other health-care practitioners and organizations) as well as the agents and providers acting for them.
It is directly relevant to any technology or service provider that handles personal health information on a custodian’s behalf, since the custodian remains responsible for what its providers do with that data. Vendors selling into Ontario health care should expect PHIPA obligations to flow through their contracts.
For organizations outside Ontario health care, PHIPA does not apply, but its safeguarding expectations are a strong reference for any sensitive personal data. Outside health care, PIPEDA or another provincial law generally governs instead.
PHIPA defines the privacy outcomes an Ontario health custodian must achieve, and foundational frameworks like NIST CSF and the CIS Controls provide the safeguards and the detection and response capabilities that make those outcomes real and breach notification possible.
It is the health-specific counterpart to PIPEDA. Where PIPEDA governs commercial handling of personal information federally, PHIPA governs personal health information in Ontario. A custodian that also runs commercial activities may have both in scope, and a single well-designed security program can satisfy them together.
PHIPA is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Accountability
—Safeguards
—Agents & providers
—Audit & detection
—Breach notification
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: Information and Privacy Commissioner of Ontario: PHIPA (ipc.on.ca)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.