
PHIPA Compliance in Ontario: A Health Custodian's Checklist
Circle of care, the electronic audit requirement, and the snooping provisions that made Ontario the most enforced health privacy jurisdiction in Canada.
GuardsArm Team
Security Experts

Ontario has prosecuted more health privacy cases than any other Canadian jurisdiction, and almost all of them share a shape: an employee looked at a record they had no reason to open. PHIPA's enforcement record means the practical compliance question in Ontario is less "do we have policies" than "would we detect it, and could we prove it".
Circle of care and implied consent
PHIPA permits health information custodians to assume implied consent to collect, use and disclose personal health information for the purpose of providing health care, among providers within the circle of care. This is what makes clinical practice workable — you are not obtaining written consent before each referral.
Two limits are routinely overstretched:
- The circle covers care, not curiosity. It authorises access by those providing or assisting in providing care to that individual. It is not a general staff entitlement.
- The lockbox. An individual may expressly withhold or withdraw consent for particular information to be shared. Your systems need to be able to honour that instruction, and your staff need to know when one is in force.
Implied consent does not extend to purposes outside health care. Research, fundraising, marketing and administration each need their own footing.
The electronic audit requirement
This is the provision that distinguishes PHIPA from most of its Canadian counterparts. Electronic systems used to maintain personal health information must be able to record and produce, for each access, who accessed it, when, and the record involved — and the custodian must be able to provide that log to the individual on request.
Individuals can ask who has looked at their record. That is a powerful accountability mechanism and an uncomfortable one for organisations whose audit logging was configured for troubleshooting rather than for answering that question.
Getting this right requires more than switching logging on:
| Requirement | What it implies |
|---|---|
| Record every access, not every change | Read access is the event that matters |
| Identify the individual, not the role | Shared accounts defeat the entire provision |
| Retain long enough to answer a request | Short retention makes the log useless |
| Be able to produce it in readable form | A raw table is not an answer to a patient |
Shared clinical logins are the fatal one. If three people use one account, the log cannot say who looked, and the statutory answer cannot be given. See privileged access for clinicians.
Breach reporting
Custodians must notify affected individuals at the first reasonable opportunity where personal health information is stolen, lost, or used or disclosed without authority. Notification must inform the individual of their right to complain to the Commissioner.
Reporting to the Information and Privacy Commissioner of Ontario is required in defined circumstances, and custodians must also file an annual statistical report of the previous year's breaches. That annual return is a quiet forcing function: it requires you to have been counting all year.
Where a member of a regulated health profession is terminated, suspended or resigns in connection with unauthorised access, there is a duty to notify their professional College as well.
Where custodians most often fail
- Audit logs that cannot identify a person because accounts are shared
- No proactive auditing — logs exist but nobody looks until a complaint arrives
- Lockbox instructions recorded on paper and invisible to the system
- Agents and service providers without the required written agreements
- Departed staff whose access was never revoked
Proactive auditing is the highest-value item on that list. Detecting inappropriate access yourself, and acting on it, is a materially different position from learning about it when the individual complains.
Where to start
Pick one VIP or staff-member record and ask your system who has accessed it in the last year. If you cannot produce a clean, person-level answer within a day, that is your first project — it is also exactly what the Commissioner would ask for.
GuardsArm helps Ontario custodians build audit capability and access governance. See Canadian compliance services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “PHIPA Compliance in Ontario: A Health Custodian's Checklist”
Talk to the GuardsArm team about how these services apply to your environment.


