Back to Blog
Compliance
4 min read

Manitoba PHIA: Personal Health Information Obligations Explained

Manitoba was first in Canada with dedicated health privacy legislation. Trustee duties, the security requirements, and what a smaller clinic actually has to produce.

GuardsArm Team

Security Experts

September 25, 2026

Manitoba PHIA compliance for trustees

Manitoba's Personal Health Information Act was the first dedicated health privacy statute in Canada, and it uses vocabulary the rest of the country does not. Organisations holding personal health information in Manitoba are trustees, and the Act sets out their duties with unusual specificity about security in particular.

Trustees, not custodians
Manitoba uses its own vocabulary throughout
Written policies required
Sensible but informal practice is still non-compliant
Health services number counts
Billing and scheduling systems are in scope

Who is a trustee

The Act applies to health professionals, health care facilities, public bodies and health services agencies that collect or maintain personal health information. If you hold health information about identifiable individuals in Manitoba in one of those capacities, you are a trustee and the duties attach directly to you.

Personal health information covers health and health care history, the provision of health care, and the health services number — that last item catching administrative systems that hold no clinical content at all. Billing and scheduling systems are routinely scoped out of privacy programmes and routinely should not be.


The security duty is written out, not implied

Most Canadian privacy statutes say "reasonable safeguards" and leave the rest to interpretation. PHIA is more prescriptive: trustees must establish written policies and procedures for the protection of personal health information, and those policies must address a defined set of areas.

What the written security policy must coverAccess control, staff responsibilities and training, secure storage transfer and disposal, audit and monitoring of access, and breach response.Access controlWho may see what, and how that is enforcedStaff responsibilities and trainingDocumented, and deliveredSecure storage, transfer and disposalIncluding paper and portable mediaAudit and monitoring of accessThe ability to see who lookedBreach responseA written procedure, not an instinct
The Ombudsman asks for the document. Good practice without it still fails.

The requirement for written policies matters. A trustee operating sensibly but informally is non-compliant in a way that is trivially demonstrable — the Ombudsman asks for the policy and there isn't one.


The privacy officer, and what scales down

Trustees must designate a privacy officer. For a large regional health authority this is a role; for a two-physician clinic it is a hat somebody wears. The Act does not require the role to be full-time, and small trustees should not conclude that compliance is out of reach.

What genuinely scales down for a small clinic:

ObligationSmall-practice version
Written policiesA short set of documents, not a manual
Privacy officerA named person with the responsibility written down
Access controlsIndividual logins, no shared accounts, access removed on departure
Audit capabilityWhatever your EMR records — know how to run the report
Staff trainingDocumented, annual, and actually attended
Breach procedureA one-page plan naming who does what

That list is achievable in weeks, and it is most of what an investigation will ask for. The failure mode for small trustees is not partial compliance — it is concluding the whole thing is too big and doing none of it.


Access, correction and the individual's rights

Individuals have a right of access to their own personal health information, with limited exceptions, and a right to request correction. Where a correction is refused, the individual may file a statement of disagreement that must be attached to the record.

That last mechanism is often missed in system design. If your EMR has no way to attach a statement of disagreement to a record, you cannot satisfy the right.


What the Ombudsman tends to find

The recurring findings against Manitoba trustees are consistent and mostly cheap to prevent:

  1. No written policy, or a generic IT policy that never mentions health information
  2. Shared logins in clinics and at nursing stations, defeating any audit
  3. Access not revoked when staff, students or locums leave
  4. Information disclosed by fax or email to the wrong recipient, with no verification step
  5. No training records, even where training happened
  6. Paper records left accessible, or disposed of without secure destruction

Misdirected fax and email remain remarkably durable causes of breach. A verification step before sending to a new recipient, and a standing list of confirmed destinations, removes most of that category for almost no cost.


Breach notification and the Ombudsman

Manitoba's oversight runs through the Ombudsman rather than a Commissioner titled as such. Trustees must notify affected individuals where personal health information is stolen, lost, or subject to unauthorised access, use or disclosure, subject to the thresholds in the Act and regulations.

Build the register before you need the threshold
Whatever the precise notification trigger, every trustee needs an incident log, a consistent way of assessing harm, and a named person who decides. Organisations caught out by a breach are almost never missing the legal threshold — they are missing those three things.

Where to start

Ask for your written security policy. If it exists, check whether it addresses the specific areas the Act names rather than being a generic IT policy with "health information" substituted in. If it does not exist, that single document is the highest-value thing you can produce this quarter.

GuardsArm supports Manitoba trustees with PHIA policy development and security assessments. See Manitoba PHIA compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.