Healthcare Cybersecurity & PHIPA/HIA Compliance (Canada)
Achieve PHIPA compliance for your healthcare clinic with practical access controls, breach-reporting steps, and vendor due diligence that stops IPC penalties.

Healthcare Cybersecurity & PHIPA/HIA Compliance (Canada)
A family medicine clinic in Mississauga runs a cloud-based EMR, a fax machine that still receives half its referrals, three receptionists who share one login because provisioning a new user "takes too long," and a front-desk PC that hasn't been patched since a Windows update broke the billing plugin. None of that is hypothetical — it's the median state of a 4-to-12-physician clinic we've walked into for a PHIPA readiness assessment. Nothing about it is illegal on its own. What makes it a liability is that nobody can tell you who accessed which patient's chart last Tuesday, and that gap is exactly what Ontario's Information and Privacy Commissioner (IPC) prosecutes.
Personal health information (PHI) is worth more on resale than a credit card number precisely because it doesn't expire — you can't cancel a diagnosis the way you cancel a Visa. That's why clinics, labs, and digital health platforms are targeted disproportionately, and why the failure mode in Canadian healthcare is rarely a nation-state attacker. It's an employee looking up a neighbour's chart, a vendor with standing access nobody revoked, or a ransomware operator who got in through an unpatched remote-desktop port on a legacy imaging workstation. The IBM Cost of a Data Breach Report 2025 puts the average cost of a healthcare breach at USD 7.42 million globally — the highest of any industry for the fourteenth consecutive year, though down from USD 9.77 million in 2024 — against a global cross-industry average of USD 4.44 million, with 279 days average time to identify and contain, the longest of any sector measured.
This article is a working reference for clinic owners, practice managers, and digital health engineering leads operating under Ontario's Personal Health Information Protection Act (PHIPA), Alberta's Health Information Act (HIA), or the equivalent statutes in other provinces. We wrote it after running PHIPA readiness reviews and incident responses for regulated Canadian healthcare organizations — the patterns repeat regardless of clinic size.
Key Takeaways
- PHIPA compliance for your healthcare clinic starts with knowing who your "agents" are (staff, contractors, EMR vendors) and documenting that relationship — not with buying another security product.
- Ontario mandates IPC reporting for seven specific breach categories under O. Reg. 329/04, separate from the broader duty to notify affected patients "at the first reasonable opportunity" under PHIPA s.12(2).
- Snooping — an employee or affiliated clinician looking up a chart without a clinical reason — is the single most common real-world PHIPA violation, and it is a mandatory IPC-reportable event even when no harm occurs.
- Alberta's HIA uses a lower notification trigger ("risk of harm," HIA s.60.1(2)) than Ontario and requires notifying the Minister of Health in addition to the Commissioner and the patient — the two regimes are not interchangeable.
- Access governance — least-privilege provisioning, deprovisioning on termination, and audit log review — fixes more real risk than most incremental security tool purchases, because most healthcare breaches are authorized users doing unauthorized things.
- Fax is still legally and operationally embedded in Canadian healthcare referral workflows; pretending it's gone is a worse compliance posture than securing it properly.
PHIPA vs. Alberta HIA vs. Other Provincial Health Privacy Statutes
Canada has no single federal health privacy law that binds clinics directly. Provincial statutes govern health information custodians (HICs); PIPEDA applies as a backstop where no substantially similar provincial law exists. If you operate in more than one province, you comply with each province's statute for the data collected there — there's no single national PHIPA-equivalent to point to.
| Jurisdiction | Statute | Regulator | Mandatory breach notice to regulator | Notice to patients | Distinguishing feature |
|---|---|---|---|---|---|
| Ontario | Personal Health Information Protection Act (PHIPA), 2004 | Information and Privacy Commissioner of Ontario (IPC) | Mandatory for 7 defined categories under O. Reg. 329/04 (s.6.3), including snooping, theft, and "significant" breaches | Mandatory for essentially all breaches, "at the first reasonable opportunity" (PHIPA s.12(2)) | Explicit college-notification duty when a regulated health professional is disciplined for a breach (PHIPA s.17.1) |
| Alberta | Health Information Act (HIA) | Office of the Information and Privacy Commissioner of Alberta (OIPC AB) | Mandatory whenever custodian determines "risk of harm" (HIA s.60.1(2)) — a lower bar than Ontario's category list | Mandatory alongside regulator notice (HIA s.60.1(3)) | Also requires notifying the Minister of Health — unique among the provinces compared here; first province to mandate health-sector breach notice (2018) |
| British Columbia | E-Health (Personal Health Information Access and Protection of Privacy) Act applies to designated provincial health information banks; most private clinics fall under the Personal Information Protection Act (PIPA BC) | Office of the Information and Privacy Commissioner for BC | PIPA BC breach notice duties apply to clinics outside the designated e-health systems | Per PIPA BC's general breach provisions | Splits obligations between a narrow health-specific statute (large provincial data banks) and the general private-sector PIPA for most clinics |
| Manitoba | Personal Health Information Act (PHIA) | Manitoba Ombudsman | Provincial health-specific breach duties apply; verify current regulatory text before relying on specifics | Notification duties apply to affected individuals | Oversight sits with the Ombudsman rather than a dedicated privacy commissioner |
| Saskatchewan | Health Information Protection Act (HIPA) | Saskatchewan Information and Privacy Commissioner (advisory; not order-making for HIPA) | Health-specific breach duties apply | Notification duties apply | Commissioner's HIPA role is recommendation-based rather than binding-order-based |
| Newfoundland and Labrador | Personal Health Information Act (PHIA) | Office of the Information and Privacy Commissioner (NL) | Health-specific breach duties apply | Notification duties apply | Closely modelled on Ontario's PHIPA structure |
If your clinic group operates across Ontario and Alberta, do not assume one incident-response runbook covers both — the trigger thresholds, the recipients of notice, and the timelines differ. For the four smaller provincial statutes above, confirm current regulatory text and any recent amendments with counsel before finalizing a multi-province breach playbook; we're flagging the comparison level deliberately rather than asserting thresholds we haven't pulled from current statute text.
Health Information Custodian Obligations and Agent Relationships
Under PHIPA s.3, a health information custodian (HIC) is a person or organization that has custody or control of PHI as a result of providing health care — physicians, clinics, hospitals, pharmacies, and most allied health practices. The HIC is the accountable party, full stop. You cannot contract your way out of custodial responsibility.
Most of the actual work in a clinic is done by "agents" — PHIPA s.2 defines an agent as a person who acts for or on behalf of the custodian for purposes related to the custodian's own purposes, whether or not they're paid, and whether the custodian has the right to control their actions. That includes:
- Employees (receptionists, nurses, billers)
- Contracted IT support and MSPs with system access
- The EMR vendor's support staff who can view PHI during a support ticket
- Locum physicians and cross-covering clinicians
Every agent relationship needs a written agreement specifying: the purposes for which the agent may access PHI, the agent's obligation to notify the custodian immediately of any actual or suspected breach, the agent's obligation to comply with PHIPA and your policies, and your right to audit. This isn't paperwork theatre — when the IPC investigates a breach involving a vendor, the first document requested is the agent agreement, and "we assumed the vendor had it covered" is not a defence.
EMR/EHR Vendor Due Diligence: What to Demand in the Contract
Most Canadian clinics don't build their own EMR — they buy one. That makes vendor due diligence your primary control, not a secondary one. Before signing, demand the following in writing, not in a sales deck:
- Data residency — confirm where PHI is stored and processed, and get it in the contract, not just the marketing page. Cross-border storage doesn't automatically breach PHIPA, but you need to know and disclose it.
- Sub-processor disclosure — a list of every third party (cloud host, backup provider, analytics tool, AI transcription service) that touches PHI, with the same contractual obligations flowed down.
- Audit log access — you must be able to pull a full access log for any patient record, by user, by timestamp, without opening a support ticket and waiting a week. If the vendor can't produce this on demand, that's a hard no.
- Breach notification SLA — a contractual commitment to notify you within a specific number of hours of a confirmed or suspected incident, not "promptly."
- Encryption specification — AES-256 (or equivalent) at rest, TLS 1.2 or higher in transit, named explicitly, not "industry-standard encryption."
- Data return and deletion on termination — a defined process and timeline for exporting your data and confirming deletion when you switch vendors.
- SOC 2 Type II report or equivalent independent audit — request the actual report, not a compliance badge on the website.
- Right to audit or request a penetration test summary — even annually, even a redacted summary.
If a vendor won't put items 3 and 4 in writing, that alone tells you how they'd handle an actual incident.
Access Controls, Audit Logging, and the Snooping Problem
This is the section that matters most, because snooping is the most common real-world PHIPA violation — not ransomware, not a hacked website, an employee or clinician looking up a record they had no clinical reason to view. The IPC's own guidance names this explicitly: an employee looking at the record of a neighbour, a friend's child, or a public figure "out of curiosity or concern" is still a reportable breach, and it is one of the seven mandatory-notification categories under O. Reg. 329/04 regardless of motive or harm.
The reason this keeps happening isn't malice — it's architecture. Shared logins, EMRs configured with role-based access that grants clinical staff org-wide record visibility "for coverage flexibility," and audit logs nobody reviews until a patient complains. Fix the mechanism, not the individual:
- Named, individual logins only. If two staff share a login because provisioning is slow, that's a process failure, not a staffing shortage — fix the provisioning SLA, not the login policy.
- Role-based access control (RBAC) scoped to caseload, not clinic-wide. A physiotherapist doesn't need read access to psychiatric intake notes for patients they've never treated.
- Break-glass access with mandatory justification for legitimate emergency access outside normal scope — logged, time-boxed, and reviewed within 24 hours.
- Automated audit log review, not manual spot-checks. Most EMRs (OSCAR, Accuro, Telus PS Suite, Epic) support flagging "self-access," "VIP flag access," and "same-surname access" patterns. Turn these on; most clinics never do.
- Quarterly access recertification — a manager confirms each user's access level still matches their role. This alone catches most stale-permission risk.
A minimal audit log entry that would satisfy an IPC investigation needs, at minimum: user ID, patient record ID, timestamp, action (view/edit/print/export), and the accessing workstation or session ID. If your EMR can't produce that five-field record for any access event on demand, you have a gap that predates any conversation about firewalls.
-- Minimum viable audit query for a PHIPA snooping investigation
SELECT user_id, patient_id, action_type, accessed_at, workstation_id
FROM emr_access_log
WHERE patient_id = :patient_in_question
ORDER BY accessed_at DESC;
-- Flag same-surname / same-address access as a standing detective control
SELECT a.user_id, a.patient_id, a.accessed_at
FROM emr_access_log a
JOIN staff s ON a.user_id = s.user_id
JOIN patients p ON a.patient_id = p.patient_id
WHERE s.last_name = p.last_name
AND a.action_type = 'view'
AND a.clinical_relationship = FALSE;
Encryption at Rest and in Transit
This is table stakes, and PHIPA's own breach-reporting rules reflect it: under O. Reg. 329/04, stolen PHI does not trigger mandatory IPC notification if the information was encrypted or de-identified. That's a direct regulatory incentive to encrypt, not just a best practice.
Minimum bar for a clinic environment:
- At rest: AES-256 for databases, file storage, and backups. Full-disk encryption (BitLocker/FileVault) on every workstation and laptop that can access PHI — including reception desktops.
- In transit: TLS 1.2 minimum, TLS 1.3 where the EMR and browser support it, for every PHI-carrying connection — patient portals, EMR-to-lab interfaces, and remote access.
- Backups: encrypted independently of the production database, with keys stored separately from the backup medium. A stolen encrypted backup tape is a non-event under PHIPA's breach test; an unencrypted one is a mandatory report.
- Key management: don't store encryption keys in the same environment as the encrypted data. This is the detail that turns "we encrypt everything" into a real control versus a checkbox.
Medical IoT and Legacy Device Segmentation
Clinics run infusion pumps, imaging workstations, and lab analyzers that were purchased on a 10-to-15-year depreciation cycle and are running operating systems the vendor stopped patching years ago. You cannot patch a DICOM imaging workstation running an unsupported OS out of a ransomware exposure — but you can stop it from being reachable from the machine where a receptionist opens email attachments.
- Network-segment clinical devices onto a separate VLAN with no direct internet route and no direct path to admin/reception systems.
- Firewall rules that allow only the specific ports and destinations the device needs (e.g., DICOM to the PACS server, nothing else).
- Inventory every network-connected device — most clinics can name their EMR vendor but not the fact that their glucose analyzer has a network card. You cannot segment what you haven't inventoried.
- Compensating controls for devices that can't be patched or replaced: network isolation, strict access control lists, and monitoring for anomalous outbound traffic, since the device-level fix isn't available.
Secure Messaging and the Fax Reality
Fax is still the default referral and lab-result transport mechanism across large parts of Canadian healthcare, and pretending otherwise doesn't make it go away — it just means nobody secures it properly. Two honest points:
First, fax-to-fax transmission over the traditional phone network is not "unencrypted PHI in transit" in the way an unencrypted email is — it's a point-to-point circuit-switched call, which carries different (and generally lower) interception risk than routing PHI over the open internet. That's not an endorsement of fax as a design choice; it's an acknowledgement that ripping it out entirely, right now, isn't realistic for most referral networks that depend on it.
Second, the actual risk with fax in clinics is almost never the transmission — it's the machine sitting in an unlocked hallway printing PHI onto a tray anyone can walk past, and the misdirected fax caused by a mistyped number (which, notably, does not trigger mandatory IPC notification if it's a single isolated incident, per IPC guidance — but does if it becomes a pattern).
Practical controls:
- Move to a secure fax-to-email or fax-server solution that logs delivery and eliminates the physical printout, where budget allows.
- If physical fax machines remain, place them in access-controlled areas, not open reception areas.
- Use pre-programmed, verified numbers for regular referral partners instead of manual dialing, to cut misdirection risk.
- For net-new secure messaging, prioritize encrypted, PHIPA-compliant clinical messaging platforms over SMS or consumer chat apps for any clinician-to-clinician PHI discussion — this is a much larger real risk than fax at this point.
Ransomware in Clinical Settings and Continuity Planning
Ransomware in a clinic isn't just a data problem — it's a patient safety problem when it takes the EMR offline during clinic hours. Under O. Reg. 329/04, PHI subject to a ransomware attack is explicitly listed by the IPC as an example of "stolen" information requiring mandatory notification, whether or not the attacker exfiltrated data before encrypting it.
A minimal clinical continuity plan needs:
- Offline, immutable backups tested with an actual restore, not just a backup-completed notification, on a defined schedule (weekly restore tests are realistic for a small clinic).
- A documented "EMR down" workflow — paper charting templates, a defined process for verifying patient identity and allergies without system access, and a plan for re-entering paper records once systems are restored.
- Network segmentation so a single compromised workstation can't reach the EMR database server directly.
- A named incident commander and a call tree that doesn't depend on the compromised email system to reach people.
- Cyber insurance with healthcare-specific coverage, reviewed against your actual environment — many policies exclude claims where basic controls (MFA, patching cadence) weren't in place, which is worth confirming before you need it, not after.
Breach Notification: The IPC, Alberta OIPC, and Your Patients
Ontario. Under PHIPA s.12(2), you must notify affected individuals "at the first reasonable opportunity" for essentially any breach. Separately, under O. Reg. 329/04 (s.6.3), you must notify the IPC for seven defined categories: (1) unauthorized use/disclosure by someone who knew or should have known it was unauthorized — this covers snooping; (2) theft of PHI, including ransomware; (3) further unauthorized use/disclosure following an initial breach; (4) a pattern of similar breaches; (5) a college-notification trigger involving a regulated professional; (6) an equivalent disciplinary trigger for a non-college-member agent; (7) a breach that is "significant" given sensitivity, volume, number of affected individuals, or number of custodians involved. HICs also file an annual statistical report to the IPC by March 1 covering all breaches from the prior year, reportable or not.
Alberta. Under HIA s.60.1(2), notification to the OIPC Alberta is mandatory whenever the custodian determines there is a "risk of harm" — a broader, lower-bar trigger than Ontario's category list, closer to "when in doubt, report." Under s.60.1(3), you must also notify the Minister of Health and the affected individuals — the Minister-notification requirement is distinctive to Alberta among the provinces compared here. Notification must happen "as soon as practicable."
Penalties. Under PHIPA s.72, wilful offences carry fines of up to CAD 200,000 and/or up to one year's imprisonment for an individual, and up to CAD 1,000,000 for an organization — these figures were doubled from the original CAD 100,000 / 500,000 caps under later amendments. Separately, since January 1, 2024, the IPC has authority to issue Administrative Monetary Penalties (AMPs) directly, without prosecution, of up to CAD 50,000 for individuals and CAD 500,000 for organizations. In Alberta, legal commentary on HIA amendments has reported a penalty range running from roughly CAD 2,000 up to CAD 500,000 depending on the contravention; confirm the current figure against the statute or with counsel before citing it in a client-facing document, as we were not able to independently verify the exact current band against primary legislative text.
Retention and Disposal
PHIPA does not set one blanket retention period for all PHI — retention is generally driven by professional college requirements, the Limitations Act, and your own policy. For Ontario physicians, the College of Physicians and Surgeons of Ontario (CPSO) sets a regulatory minimum of 10 years from the date of the last entry for adult patient records, and 10 years past the age of majority for pediatric records — but recommends retaining records for 15 years from the last entry, citing the discoverability window under s.15(2) of Ontario's Limitations Act, 2002. Build your retention schedule to the 15-year CPSO recommendation, not the 10-year regulatory floor, unless you have a specific reason not to.
Disposal is not "delete the file":
- Use disposal methods appropriate to the medium — cryptographic erasure or physical destruction for drives, cross-cut shredding for paper, with a certificate of destruction from any third-party disposal vendor.
- Log every disposal event: what was destroyed, when, by what method, authorized by whom.
- Include disposal obligations in every vendor and agent agreement — if your EMR vendor holds backups after you terminate, that's still your custodial liability.
Compliance Checklist: Small Clinic vs. Digital Health Platform
These are two different risk profiles requiring different levels of control maturity.
| Control area | Small clinic (1–15 staff, single EMR) | Digital health platform (multi-tenant, API-driven, scaling) |
|---|---|---|
| Access control | Named logins, RBAC by role, quarterly recertification | RBAC + attribute-based access control, automated deprovisioning tied to HR system, SSO with MFA enforced org-wide |
| Audit logging | EMR's built-in log, reviewed monthly, self-access alerts enabled | Centralized log aggregation (SIEM), automated anomaly detection, immutable log storage, real-time alerting |
| Agent agreements | Signed agreements with EMR vendor, MSP, and any locum/contractor | Signed agreements with every sub-processor, data processing addenda per customer contract, vendor risk-tiering |
| Encryption | AES-256 at rest, TLS 1.2+ in transit, full-disk encryption on all devices | Same baseline plus field-level encryption for high-sensitivity fields, dedicated key management service (HSM/KMS) |
| Incident response | Documented plan, tested annually, named incident commander | 24/7 monitoring, formal IR retainer, breach notification automation across multiple provincial regimes |
| Third-party assurance | Request vendor's SOC 2 or equivalent on renewal | Maintain your own SOC 2 Type II / ISO 27001, penetration test at least annually |
| Regulatory footprint | Single-province PHIPA or HIA obligations | Multi-province (and possibly multi-country) obligations mapped per customer jurisdiction |
The Counter-Case: Why Buying More Security Tools Rarely Fixes the Real Risk
Every clinic and platform we've assessed already owns more security tooling than it uses effectively. Endpoint detection, a firewall appliance, sometimes a SIEM nobody tuned after the trial period — and the breach still happens because a terminated employee's login was never deactivated, or because thirty staff have "administrator" access to a system where four actually need it.
Here's the arithmetic. A mid-sized clinic spending CAD 15,000/year on an additional security tool (say, an EDR upgrade or a second firewall layer) gets a marginal reduction in external-attacker risk. The same CAD 15,000 spent on a part-time access governance function — quarterly recertification, deprovisioning automation tied to your HR/payroll system, and audit log review — addresses the failure mode that actually produces most PHIPA-reportable events: authorized users doing unauthorized things, and departed users who still have access. Tools defend the perimeter; governance defends the record.
This isn't an argument against security tools — encryption, endpoint protection, and network segmentation are non-negotiable baseline controls covered earlier in this article. It's an argument against treating tool acquisition as a substitute for the harder, less glamorous work of knowing exactly who has access to what, why, and for how long. The IPC's own breach statistics consistently point to internal, authorized-access breaches (snooping) as a dominant category — not sophisticated external intrusion. A clinic that can answer "who accessed this record and why" in under five minutes has done more for its compliance posture than one that bought a second firewall it can't fully configure.
A practical test: if you can't produce a current list of every person with access to your EMR, cross-referenced against your current staff roster, in under 30 minutes — you have an access governance gap that no additional tool purchase will close.
Anti-Patterns and Common Mistakes
- Treating the EMR vendor's compliance as your compliance. The vendor being PHIPA-aware doesn't discharge your custodial obligations — you're still the HIC.
- Shared logins "for efficiency." This is the single fastest way to make an audit log useless and a snooping investigation unresolvable.
- No agent agreement with the IT contractor who has admin access. If they can see PHI while fixing a printer issue, they're an agent, and you need it in writing.
- Assuming accidental breaches never need reporting. A single misdirected fax usually doesn't; the same mistake happening five times in a quarter is a reportable pattern.
- Treating patient notification and IPC notification as the same trigger. They're not — patient notice is required far more broadly than IPC notice in Ontario.
- No tested backup restore. A backup that has never been restored is a hope, not a control.
- Confusing PHIPA and Alberta HIA requirements when operating in both provinces, and applying Ontario's category-based IPC trigger to an Alberta operation where the "risk of harm" bar is different.
- Buying a tool to solve a governance problem. See the counter-case above.
FAQ
Do I need to report every privacy breach to the IPC in Ontario? No. You must always notify affected patients under PHIPA s.12(2), but IPC notification is only mandatory for the seven categories in O. Reg. 329/04 — including snooping, theft, and "significant" breaches. A single accidental, isolated incident (like a misdirected fax) typically doesn't require IPC notice unless it becomes a pattern.
Is a small clinic actually a health information custodian under PHIPA? Yes. Any physician, dentist, physiotherapist, or clinic that has custody or control of PHI in the course of providing health care is a HIC under PHIPA s.3, regardless of size. There is no small-practice exemption from custodial obligations.
What counts as snooping under PHIPA, and is it really reportable? Snooping is accessing a patient record without a legitimate clinical or administrative reason — checking a neighbour's, celebrity's, or family member's chart out of curiosity. It's reportable to the IPC regardless of motive or whether any harm resulted, per O. Reg. 329/04.
How is Alberta's HIA different from Ontario's PHIPA for breach notification? Alberta uses a broader "risk of harm" trigger (HIA s.60.1(2)) rather than Ontario's seven defined categories, and Alberta additionally requires notifying the Minister of Health, not just the Commissioner and the patient.
How long do I need to keep patient records in Ontario? CPSO sets a regulatory minimum of 10 years from the last entry for adult records (10 years past age of majority for pediatric records), but recommends 15 years due to the discoverability period under the Limitations Act, 2002.
Does encrypting patient data reduce our breach-reporting obligations? In Ontario, yes for the theft category specifically — under O. Reg. 329/04, stolen PHI does not require mandatory IPC notification if it was encrypted or de-identified at the time. Encryption doesn't eliminate your other obligations, but it materially changes this one.
Related Reading
- If your clinic is scaling toward multi-province operations, pair this with our B2B DevSecOps & Security Compliance Roadmap for how to build compliance into your engineering pipeline rather than bolting it on after the fact.
- For clinics and digital health platforms handling broader Canadian privacy obligations beyond PHI, see our Penetration Testing Guide for Canadian SMBs: PIPEDA Compliance for how PIPEDA interacts with sector-specific statutes like PHIPA.
- If you operate across borders and need a comparative view of how another jurisdiction structures data protection obligations, our KVKK Data Protection Compliance Roadmap walks through Turkey's regime as a useful structural comparison.
- For platforms considering cloud infrastructure decisions alongside compliance requirements, our Cloud Migration Playbook for Saudi Enterprises: NCA ECC covers a parallel regulated-cloud migration model worth reviewing for pattern reuse.
Talk to Our Team
D-Elite Solutions' Senior Engineering & Security Team has run PHIPA and HIA readiness assessments and incident response engagements for Canadian healthcare organizations, from single-physician clinics to multi-province digital health platforms. Book a free consultation and walk away with a concrete gap list against PHIPA, HIA, or your applicable provincial statute — mapped to your actual EMR, staffing, and infrastructure, with no obligation to engage further.
Need Technical Architecture & Advisory?
Our senior engineering pod helps enterprises modernize legacy architecture, audit DevSecOps compliance, and scale execution velocity.
