Back to Blog
Compliance
4 min read

PHIPA Compliance in Ontario: A Health Custodian's Checklist

Circle of care, the electronic audit requirement, and the snooping provisions that made Ontario the most enforced health privacy jurisdiction in Canada.

GuardsArm Team

Security Experts

September 25, 2026

PHIPA compliance for Ontario health information custodians

Ontario has prosecuted more health privacy cases than any other Canadian jurisdiction, and almost all of them share a shape: an employee looked at a record they had no reason to open. PHIPA's enforcement record means the practical compliance question in Ontario is less "do we have policies" than "would we detect it, and could we prove it".

Most enforced in Canada
Ontario prosecutes unauthorised access more than anywhere else
Patients can ask who looked
The audit log is a statutory deliverable
Annual breach return
Requires you to have been counting all year

Circle of care and implied consent

PHIPA permits health information custodians to assume implied consent to collect, use and disclose personal health information for the purpose of providing health care, among providers within the circle of care. This is what makes clinical practice workable — you are not obtaining written consent before each referral.

Two limits are routinely overstretched:

  • The circle covers care, not curiosity. It authorises access by those providing or assisting in providing care to that individual. It is not a general staff entitlement.
  • The lockbox. An individual may expressly withhold or withdraw consent for particular information to be shared. Your systems need to be able to honour that instruction, and your staff need to know when one is in force.

Implied consent does not extend to purposes outside health care. Research, fundraising, marketing and administration each need their own footing.


The electronic audit requirement

This is the provision that distinguishes PHIPA from most of its Canadian counterparts. Electronic systems used to maintain personal health information must be able to record and produce, for each access, who accessed it, when, and the record involved — and the custodian must be able to provide that log to the individual on request.

Shared logins break the statute, not just the policy
PHIPA requires an electronic record of who accessed personal health information. Where a ward account is shared between staff, no such record exists and the answer owed to a patient cannot be produced. This is a compliance defect, not only a security weakness.

Individuals can ask who has looked at their record. That is a powerful accountability mechanism and an uncomfortable one for organisations whose audit logging was configured for troubleshooting rather than for answering that question.

Getting this right requires more than switching logging on:

RequirementWhat it implies
Record every access, not every changeRead access is the event that matters
Identify the individual, not the roleShared accounts defeat the entire provision
Retain long enough to answer a requestShort retention makes the log useless
Be able to produce it in readable formA raw table is not an answer to a patient

Shared clinical logins are the fatal one. If three people use one account, the log cannot say who looked, and the statutory answer cannot be given. See privileged access for clinicians.


Breach reporting

Custodians must notify affected individuals at the first reasonable opportunity where personal health information is stolen, lost, or used or disclosed without authority. Notification must inform the individual of their right to complain to the Commissioner.

Reporting to the Information and Privacy Commissioner of Ontario is required in defined circumstances, and custodians must also file an annual statistical report of the previous year's breaches. That annual return is a quiet forcing function: it requires you to have been counting all year.

Where a member of a regulated health profession is terminated, suspended or resigns in connection with unauthorised access, there is a duty to notify their professional College as well.

The PHIPA response sequenceThe PHIPA response sequence1DetectDay 0Proactive audit, a complaint, or a report from a colleague.2Contain and investigateImmediateSuspend access, establish scope from the audit log.3Notify the individualFirst reasonable opportunityIncluding their right to complain to the Commissioner.4Report to the IPCWhere requiredPlus the professional College where a regulated member was involved.5Annual statistical reportYearlyThe count of the previous year, which assumes a register exists.
The College notification is the step organisations most often overlook.

Where custodians most often fail

  1. Audit logs that cannot identify a person because accounts are shared
  2. No proactive auditing — logs exist but nobody looks until a complaint arrives
  3. Lockbox instructions recorded on paper and invisible to the system
  4. Agents and service providers without the required written agreements
  5. Departed staff whose access was never revoked

Proactive auditing is the highest-value item on that list. Detecting inappropriate access yourself, and acting on it, is a materially different position from learning about it when the individual complains.


Where to start

Pick one VIP or staff-member record and ask your system who has accessed it in the last year. If you cannot produce a clean, person-level answer within a day, that is your first project — it is also exactly what the Commissioner would ask for.

GuardsArm helps Ontario custodians build audit capability and access governance. See Canadian compliance services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “PHIPA Compliance in Ontario: A Health Custodian's Checklist”

Talk to the GuardsArm team about how these services apply to your environment.