home / frameworks / phipa

// Canadian privacy and cyber law

Personal Health Information Protection Act, 2004 (Ontario)

PHIPA is Ontario's health privacy law for hospitals, clinicians, pharmacies, and other health information custodians. Custodians must notify patients of privacy breaches, report certain breaches to the IPC, and file annual breach statistics, and the IPC can impose administrative penalties.

Ontario

Overview

The Personal Health Information Protection Act, 2004 sets rules for how health information custodians collect, use, and disclose personal health information in Ontario. Consent is the starting point. Custodians may rely on assumed implied consent to share information within the circle of care, but most other disclosures need express consent or a specific authority in the Act. Each custodian must have information practices, name a contact person, take reasonable steps to protect records, and give patients access to and correction of their records.

Breach duties are specific. If personal health information is stolen, lost, or used or disclosed without authority, the custodian must notify the individual at the first reasonable opportunity. It must also notify the IPC in the situations listed in the regulation: unauthorized use or disclosure by someone who knew or should have known better, theft, further unauthorized use after a breach, a pattern of similar breaches, breaches that lead to disciplinary action, and significant breaches. Every breach counts toward an annual statistical report to the IPC, which custodians have filed by March 1 each year since 2019.

Enforcement has grown. Since January 1, 2024 the IPC can issue administrative monetary penalties of up to $50,000 for individuals and $500,000 for organizations, and more where someone profited from the contravention. Offences carry fines of up to $200,000 for individuals and $1,000,000 for organizations. Other provinces have their own health privacy laws, including Alberta's Health Information Act and the personal health information acts of New Brunswick, Nova Scotia, and Newfoundland and Labrador.

Who it applies to in Canada

Health information custodians in Ontario, such as physicians and other regulated health professionals, hospitals, long-term care homes, pharmacies, and laboratories, plus the agents who act for them. Some rules also reach people who receive personal health information from a custodian and providers of electronic health information services.

PHIPA is recognized as substantially similar to PIPEDA for health information, so it applies instead of the federal law to custodians in Ontario. Vendors, cloud providers, and IT service firms that handle health records for Ontario custodians work under its agent and service provider rules.

Controls at a glance

The main obligations are grouped below by the Act's parts on practices, consent, collection and use, disclosure, access, and enforcement.

Information practices and accountability

  • Adopt and follow information practices
  • Name a contact person for privacy
  • Publish a written public statement of practices
  • Stay responsible for agents acting on your behalf

Consent

  • Get knowledgeable consent tied to the purpose
  • Rely on implied consent within the circle of care
  • Get express consent for most outside disclosures
  • Respect consent directives that lock records

Collection, use, and disclosure

  • Collect and use no more than is necessary
  • Don't use health data if other data will do
  • Disclose without consent only where the Act allows

Security and retention

  • Protect records against theft, loss, and unauthorized use
  • Keep records accurate for their purpose
  • Retain and dispose of records securely

Breach notification

  • Notify individuals at the first reasonable opportunity
  • Tell individuals they can complain to the IPC
  • Report prescribed breach types to the IPC
  • Count every breach for the annual report

Annual breach statistics

  • Track breaches by calendar year
  • Submit statistics to the IPC by March 1
  • Use the IPC's online submission website

Access and correction

  • Give individuals access to their records
  • Respond to access requests within 30 days
  • Correct records shown to be inaccurate or incomplete

Enforcement

  • IPC reviews complaints and issues orders
  • Penalties up to $50,000 or $500,000
  • Offence fines up to $200,000 or $1,000,000

Certification and assessment

There is no certification. The IPC receives breach reports and annual statistics, reviews complaints, and can issue orders and administrative monetary penalties. Prosecutions need the consent of the Attorney General of Ontario.

Dates to know

2004
Personal Health Information Protection Act, 2004 enacted and in force
2018-01-01
Custodians begin tracking breach statistics for annual reporting
2019-03
First annual breach statistics reports due to the IPC
2024-01-01
IPC gains power to issue administrative monetary penalties

Resources

Official texts and free tools for PHIPA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Reporting a privacy breach to the IPC: guidelines for the health sector (March 2021), Information and Privacy Commissioner of Ontario
  2. Potential consequences of a breach under PHIPA, Information and Privacy Commissioner of Ontario
  3. Annual reporting of privacy breach statistics: requirements for the health sector, Information and Privacy Commissioner of Ontario
  4. Provincial laws that may apply instead of PIPEDA, Office of the Privacy Commissioner of Canada