A privacy breach involving personal health information is more than an internal compliance issue. For healthcare organizations, it can create legal obligations to notify the people affected, report the incident to the Information and Privacy Commissioner of Ontario (IPC), and take steps to prevent the breach from happening again.
Under Ontario's Personal Health Information Protection Act, 2004 (PHIPA), health information custodians have clear obligations when personal health information (PHI) is stolen, lost, or used or disclosed without authority. These obligations are intended to protect patient privacy, promote transparency and allow the IPC to oversee compliance.
One important distinction is that not every breach must be reported to the IPC immediately, but affected individuals generally must be notified when their PHI has been stolen, lost, or used or disclosed without authority. Understanding the difference is essential for clinics, hospitals, physicians and other health information custodians.
Notification to affected individuals
Section 12(2) of PHIPA requires a custodian to notify an individual at the first reasonable opportunity if that individual's PHI is stolen or lost, or is used or disclosed without authority. The notice must also inform the individual that they have the right to complain to the IPC.
PHIPA does not set a fixed calendar deadline for this notification. Instead, the standard is the “first reasonable opportunity” — notification should take place as soon as practicable after the custodian becomes aware of the breach, while allowing reasonable steps to contain and assess the incident.
There may be limited circumstances where a short delay is appropriate, such as where notifying an individual could interfere with a law-enforcement investigation. Where this arises, custodians should consult the appropriate authorities before postponing notification.
The notification should give the affected individual a clear understanding of what happened and what it means for them. Depending on the circumstances, this will generally include a description of the breach and relevant dates, the nature and extent of the PHI involved, the steps the organization has taken to contain the breach and reduce potential harm, and any practical steps the individual can take to protect themselves. The notice should also provide contact information for someone within the organization who can answer questions and confirm the individual's right to complain to the IPC.
Direct notification by letter, email, telephone or in person is the preferred approach. Indirect notification, such as through a website posting, media notice or other public communication, is generally reserved for exceptional circumstances — for example, where a very large number of individuals are affected and contacting each person directly is impractical, or where the affected individuals cannot be identified with certainty. Even then, the organization should take reasonable steps to ensure the notice reaches the people affected.
What happens when PHI is encrypted or temporarily inaccessible?
A privacy breach does not necessarily require evidence that someone viewed, copied or removed an individual's records. The IPC has clarified that ransomware or malware attacks that encrypt PHI and make it temporarily inaccessible can constitute a loss or unauthorized use of PHI. As a result, the duty to notify affected individuals may arise even where there is no evidence that individual files were actually viewed, accessed or exfiltrated.
Recovering the data does not, by itself, eliminate the notification obligation. This is an important distinction for healthcare organizations responding to ransomware and similar incidents — the fact that information has eventually been restored does not necessarily mean the privacy breach no longer requires a response.
When must a custodian notify the IPC?
The obligation to notify affected individuals is separate from the obligation to report a breach to the IPC. Under section 12(3) of PHIPA and section 6.3 of Ontario Regulation 329/04, custodians must notify the IPC at the first reasonable opportunity when a breach falls into one or more specified categories. These categories are not mutually exclusive — more than one may apply to the same incident.
- Unauthorized use or disclosure by a person who knew or ought to have known it was not permitted — including intentional snooping, such as an employee accessing a patient's health records for a non-work-related purpose
- Stolen PHI — including theft of paper records, devices or other storage media, as well as certain ransomware or malware attacks (de-identified or properly encrypted information is generally exempt from this category)
- A further unauthorized use or disclosure after an initial loss, theft or unauthorized use or disclosure
- A pattern of similar breaches — individual incidents may appear minor separately but indicate a broader or systemic issue viewed together
- Disciplinary action taken against an agent in connection with the breach, including certain action involving a regulated health professional or an agent outside a regulatory College
- A breach that is otherwise significant, considering the sensitivity of the information, the volume involved, the number of individuals affected, and whether more than one custodian or agent was involved
Importantly, not every accidental disclosure automatically requires notification to the IPC. For example, information accidentally sent to the wrong address may not, on its own, fall within one of the prescribed categories for mandatory IPC reporting. However, the affected individual may still need to be notified under PHIPA.
How is a breach reported to the IPC?
Where a breach falls within one of the categories requiring IPC notification, the custodian must report it at the first reasonable opportunity. Reports can be submitted online or by mail and should provide information about the circumstances of the breach, the number of individuals affected, the nature of the PHI involved and the steps taken to contain, investigate and remediate the incident. Information about whether and how affected individuals were notified may also be required. The IPC may request additional information or take further steps to review the incident.
The importance of timely reporting has also been reinforced by IPC decisions. The IPC expects custodians to report a reportable breach at the first reasonable opportunity, allowing the Commissioner's office to provide guidance on responding to the incident, including containment and notification.
Annual reporting is a separate obligation
Every custodian must submit an annual statistical report to the IPC by March 1 covering privacy breaches from the previous calendar year — including thefts, losses and unauthorized uses or disclosures, even where an individual breach did not meet the threshold for immediate notification to the IPC.
In other words, the fact that a particular incident did not require immediate IPC reporting does not mean it can simply be disregarded — it may still need to be included in the custodian's annual breach statistics.
Agents who handle PHI on behalf of a custodian also have responsibilities. Where an agent becomes aware of a breach, they must notify the custodian at the first reasonable opportunity. The custodian remains accountable for PHI handled by its agents and third-party service providers. Separate requirements may also apply where disciplinary action is taken against a member of a regulatory College, including a requirement in certain circumstances to notify the College within 30 days.
Responding to a privacy breach
The best time to prepare for a privacy breach is before one occurs. Custodians should have a written privacy breach protocol that clearly sets out how the organization will respond when an incident is identified. According to the IPC, the response should begin with immediate action to contain the breach, followed by an assessment of whether notification to the IPC is required, investigation and documentation, notification of affected individuals and any required notification to the IPC or regulatory Colleges, then remediation and measures to prevent recurrence.
Containment may involve retrieving and securing PHI that has been improperly disclosed, preventing further access, changing passwords or other access credentials, or temporarily shutting down an affected system where necessary. The organization should then investigate what happened, assess the adequacy of its existing privacy practices and document the steps taken to address the incident. Clear policies, appropriate staff training, strong access controls and regular audits can also help reduce both the likelihood and the potential impact of privacy breaches.
Building trust through compliance
A privacy breach can be difficult for both an organization and the individuals affected by it. How the organization responds matters. Timely and transparent notification demonstrates accountability and gives affected individuals an opportunity to understand what happened and take appropriate steps where necessary. It also helps position the custodian to respond effectively if the IPC reviews the incident.
The rules under PHIPA are designed to provide a structured approach to responding to privacy breaches while protecting sensitive health information. For custodians, understanding the distinction between notifying affected individuals and reporting a breach to the IPC is an important part of meeting their privacy obligations. Ultimately, responding properly to a breach is not only about complying with a legal requirement — it is also about maintaining the trust that patients place in healthcare organizations to protect their most sensitive information.
Need help navigating a PHIPA privacy breach?
A privacy breach can create important legal and compliance obligations, and the right response often depends on the specific circumstances. If your organization has experienced a privacy breach or needs help strengthening its privacy compliance practices, Ewan Legal Solutions can help you understand your obligations and determine the appropriate next steps.
This article provides general information only and does not constitute legal advice. Specific requirements will depend on the facts and circumstances of each incident. For official guidance, custodians should consult the Information and Privacy Commissioner of Ontario's publications, including Responding to a Health Privacy Breach: Guidelines for the Health Sector and Reporting a Privacy Breach to the IPC: Guidelines for the Health Sector, as well as the full text of PHIPA and its regulations. Qualified legal counsel should be consulted where appropriate.