Privacy Compliance

PHIPA Decision 341: Access Is Not Authorization

A $3,000 penalty, and what Ontario healthcare employers should do to prevent incidents like it.

Sep 10, 20264 min readBy Ihinosen Alufohai
Back to Blog

A privacy breach in healthcare does not always begin with a hacker. Sometimes, it begins when an employee opens a patient record they have no work-related reason to see.

In PHIPA Decision 341, a hospital clerk accessed the personal health information of 675 patients on more than 1,600 occasions. The Information and Privacy Commissioner of Ontario imposed a $3,000 administrative monetary penalty on the employee. The hospital was found generally compliant with its privacy obligations, but the IPC still identified a significant gap: patient notification took too long.

The lesson for every clinic and hospital is simple: technical access is not authorization, and having privacy policies is not the same as being able to demonstrate that they work.

Why This Decision Matters

Individual staff can now face direct financial consequences for unauthorized access. But custodians still need to demonstrate reasonable safeguards, a disciplined breach response, and the ability to notify affected patients at the first reasonable opportunity.

PHIPA does not require organizations to prevent every act of misconduct. It requires reasonableness and demonstrable accountability. Decision 341 is useful because it shows what that standard looks like in practice, including where a generally compliant organization still had room to improve.

Need-to-know Is The Rule. Access Is Not Permission.

Under section 17(2) of PHIPA, an agent may handle personal health information only if the custodian permits it and it is necessary to that person’s duties.

The employee had system access. That was not a licence to browse emergency lists, reasons for visit, or charts of patients not in her circle of care. An argument by the employee that training “never specifically said not to look at the ED list” did not succeed. The hospital had already communicated the need-to-know principle. The IPC held that any reasonable employee in that role should have understood the limit.

For employers, the operational message is narrow: say the rule in plain language, repeat it, and keep the proof: signed confidentiality terms, training records, and dated policies.

Safeguards Can Be Reasonable And Notification Can Still Fail

The IPC did not order the hospital to take further action. The hospital could produce dated privacy and breach-response policies, signed confidentiality agreements, training records, access controls, a fast internal response, and post-incident improvements. That is what “demonstrable accountability” looks like.

Notification was the weak point identified by the IPC. The hospital reported to the IPC the day after the employee was terminated. Letters did not go out for about five months. Only patients with recent, confirmed contact details received mail; others were flagged in the chart for notice at the next visit.

The IPC accepted that a large investigation takes time. It still flagged the delay and recommended better tools for generating patient contact information and stronger audit capability. The practical lesson remains that if you cannot identify affected patients and reach them without a long manual process, the response plan is incomplete.

What This Hospital Case Means for Clinics

Family practices, specialist clinics, dental offices, and pharmacies do not need a hospital’s staffing model, but they do need safeguards that fit their size and a response they can actually run.

Before an incident, you should be able to answer:

  • Who can open which records, and for what work purpose?
  • Can we show training and signed confidentiality commitments?
  • Would unusual access be noticed before a patient or coworker complains?
  • Who leads the response, preserves evidence, and decides on notification?
  • Can we produce a current contact list without months of manual work?

The only question Decision 341 leaves you with

If a staff member opened charts without a work reason tonight, could you show the need-to-know rule they were trained on, prove what safeguards were actually in place, detect the access before a complaint, name the affected patients, and notify them without a drawn-out scramble?

That is the question a consult answers against your agreements, training log, and breach protocol, not a public checklist.

Book A PHIPA Readiness Review

Ewan Legal Solutions helps Ontario healthcare providers turn PHIPA obligations into practical processes that hold up when something goes wrong.

A focused review examines your access controls, staff confidentiality agreements, training records, audit and detection practices, breach-response roles, and ability to notify affected patients without avoidable delay.

We’ll identify the gaps, explain what needs attention, and help you strengthen your privacy program before you have to test it under pressure.

The test: If an employee opened records without a care purpose tonight, could you detect it, prove your safeguards, identify every affected patient, and notify them without avoidable delay?

Source: Information and Privacy Commissioner of Ontario, PHIPA Decision 341 (July 16, 2026; revised August 25, 2026).

This article is general information for Ontario health information custodians. It is not legal advice and does not create a client relationship.

Booking

Move from clutter
to clarity

The clearest first step is a conversation — book one and you’ll leave knowing exactly what your next power move is: what your matter needs, and how we’d handle it. Free to start, no obligation.

01

Book a consult

A free 15-minute intro, or a focused paid session — your choice.

02

Get a fixed-scope plan

Defined deliverables and a fixed fee, in writing, before any work begins.

03

We implement & defend

Working systems and a defensible record — not just advice you act on alone.

Location10225 Yonge St, Unit R270, Richmond Hill, ON L4C 3B2Meetings at our office are by appointment only — no walk-ins. Please book ahead, and we’ll be ready for you.

Book a consultation

Choose a length, then pick a time on our booking page. Paid sessions are confirmed once payment clears our secure checkout — no card details touch this site.

Book my consultation

Opens our secure booking page in a new tab.