A cyberattack on a shared technology provider can disrupt care across several organizations at once. Ontario's PHIPA Decision 284, arising from a ransomware attack affecting five hospitals and a clinic, is a useful reminder: outsourcing technology does not outsource a clinic's accountability for personal health information.
Privacy compliance is therefore not a binder on a shelf. It is an operating system for how a clinic collects, uses, discloses, safeguards, retains and disposes of personal health information — and how it responds when something goes wrong.
The compliance illusion
Most clinics do not ignore privacy deliberately. The gap is usually practical: a policy copied years ago, an office manager informally treated as the privacy lead, confidentiality language buried in onboarding paperwork, or a vendor contract signed without a privacy review. Each item may look reassuring on its own, but PHIPA compliance depends on whether the clinic's actual information practices meet the law and are followed consistently.
Ontario's Information and Privacy Commissioner (IPC) may investigate complaints and initiate reviews, issue orders, and, since January 1, 2024, impose administrative monetary penalties in appropriate cases. The better question is not simply, “Do we have a privacy policy?” It is, “Can we demonstrate that our privacy program works?”
Which privacy laws apply?
For most Ontario clinics, the Personal Health Information Protection Act, 2004 (PHIPA) is the primary privacy law governing personal health information. PHIPA applies to health information custodians and their agents. Whether a particular professional is the custodian or an agent depends on the custody-or-control and working arrangements, not only on job title.
PHIPA regulates the collection, use and disclosure of personal health information; requires reasonable safeguards; provides rights of access and correction; and establishes duties following theft, loss or unauthorized use or disclosure.
Federal law may still matter in limited situations. Ontario's PHIPA has been declared substantially similar to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) for health information handled within Ontario. PIPEDA can nevertheless apply to certain interprovincial or international commercial flows of personal information and to federally regulated organizations. Clinics may also hold non-health personal information that requires a separate legal analysis. The applicable framework should be confirmed whenever information crosses borders or the clinic uses a national platform.
What PHIPA requires in practice
1. Current information practices and a public statement — a clinic should maintain written, clinic-specific information practices describing when, how and for what purposes it routinely collects, uses, modifies, discloses, retains or disposes of personal health information, together with its administrative, technical and physical safeguards. It must also make available a written public statement explaining its practices, how to contact the clinic, how to request access or correction, and how to complain to the clinic and the IPC. PHIPA does not prescribe a universal annual review cycle, but an annual review is a sound governance practice, and an earlier review is appropriate whenever services, systems, vendors, locations or information flows change.
2. A clearly assigned privacy contact — a health information custodian that is not a natural person must designate a contact person. The role should be documented and supported with sufficient authority and time. Core functions include facilitating compliance, responding to inquiries and complaints, handling access and correction requests, and receiving public complaints about the clinic's information practices.
3. Workforce controls and documented training — agents may handle personal health information only as permitted by the custodian and in accordance with PHIPA. Clinics should use confidentiality obligations, role-based access, onboarding and offboarding controls, and recurring training tailored to actual workflows. Keep records of attendance, content and follow-up.
4. A written breach-response process — when personal health information is stolen, lost, or used or disclosed without authority, the custodian must notify the affected individual at the first reasonable opportunity and advise them of the right to complain to the IPC. The custodian must also notify the IPC immediately in circumstances prescribed by regulation. The response plan should cover containment, preservation of evidence, investigation, risk assessment, patient notification, regulatory reporting, documentation, remediation and lessons learned. PHIPA Decision 253 confirms that ransomware encryption can amount to unauthorized use and loss even where there is no evidence the attacker viewed or exfiltrated the information.
5. Retention, transfer and secure disposal — PHIPA does not establish one retention period that applies to every clinical record. Clinics must maintain retention, transfer and disposal practices that comply with PHIPA and with any applicable professional-college, funding, contractual or other legal requirements. Records must be retained securely and remain accessible during the applicable retention period, subject to lawful exceptions. Disposal must be secure and documented.
6. Reasonable technical and physical safeguards — PHIPA requires reasonable steps to protect personal health information against theft, loss and unauthorized use, disclosure, copying, modification or disposal. For most modern clinics, the following controls will often be expected as part of a reasonable security program:
- Multi-factor authentication for remote access, email, administrator accounts and cloud services
- Encryption for portable devices, backups and information transmitted over public networks
- Unique user accounts, least-privilege access and prompt removal of access when roles change
- Secure, tested backups that are appropriately separated from production systems
- Logging and periodic review of access to electronic records
- Patch management, endpoint protection, physical security and secure disposal controls
No single control guarantees compliance. The clinic should be able to explain why its safeguards are reasonable for its circumstances and how their effectiveness is monitored.
7. Vendor and service-provider oversight — a clinic remains accountable for personal health information in its custody or control when vendors process or store it on the clinic's behalf. Before engaging an EMR provider, cloud platform, billing company, IT support firm, transcription service or AI tool, the clinic should assess privacy and security risks and document clear contractual requirements covering permitted uses, safeguards, subcontractors, data location, access and audit support, incident reporting, retention and secure return or destruction. Contract terms do not replace due diligence or ongoing oversight.
Common compliance traps
- Template policies that do not match the clinic's actual systems and workflows
- Shared logins that prevent meaningful access control and audit review
- Informal training with no record of what staff were taught or whether contractors were included
- Assuming an IT vendor “handles privacy” without confirming roles, safeguards and breach obligations
- Treating every cyber event the same instead of assessing the legal triggers for patient and IPC notice
- Applying a generic retention period without checking the rules of the relevant professional college and other legal requirements
Twelve actions for a stronger privacy program
- Confirm whether the clinic, an individual professional, or another organization is the health information custodian for each record system
- Document the privacy contact and publish accurate contact information in the clinic's public privacy statement
- Map where personal health information is collected, stored, accessed, transferred and disposed of
- Review policies against actual workflows and update them when practices change
- Confirm that staff, contractors and affiliates have appropriate confidentiality obligations and role-based access
- Deliver recurring, role-specific privacy and cybersecurity training and retain evidence of completion
- Maintain and test a breach-response plan with clear escalation and decision-making responsibilities
- Enable multi-factor authentication and encryption where appropriate, especially for remote and privileged access
- Review user access and audit logs, and remove unnecessary or former-user access promptly
- Align retention and secure-destruction schedules with PHIPA and applicable professional requirements
- Review vendor due diligence and contracts, including incident-notification and subcontractor terms
- Track breaches throughout the year and confirm the clinic's annual IPC reporting obligation
Where to start
If this checklist surfaced uncertainty, begin with evidence: the clinic's policies, public statement, system and vendor inventory, access lists, training records, breach log, retention schedule and key contracts. A focused gap assessment can then separate legal requirements from recommended controls and prioritize the most significant risks.
Ewan Legal Solutions helps Ontario healthcare providers develop practical, legally grounded privacy programs tailored to their operations. A PHIPA Compliance Assessment can identify gaps, clarify responsibilities and produce a prioritized action plan.
Key legal and regulatory sources
- Personal Health Information Protection Act, 2004
- Ontario Regulation 329/04 (General)
- IPC: Report a health privacy breach
- IPC: Health Privacy Breach Statistical Report FAQ
- IPC PHIPA Decision 253 (ransomware encryption)
- IPC PHIPA Decision 284 (shared-service ransomware attack)
- OPC: PIPEDA requirements in brief
This article provides general information as of September 9, 2026. It is not legal advice. Legal obligations depend on the clinic's structure, records, systems, professional rules and circumstances.