🏥 PHIPA Compliance

PHIPA protects patient data in Ontario.Is your health practice compliant?

Ontario's Personal Health Information Protection Act (PHIPA) sets strict rules for how health information custodians collect, use, and protect patient data. A breach can result in fines up to $1,000,000 and mandatory patient notification.

Check your PHIPA compliance free →

PHIPA applies to your practice

Dental clinics
Medical practices
Physiotherapy clinics
Chiropractic offices
Optometry practices
Pharmacies
Mental health practices
Naturopathic clinics
Midwifery practices
Massage therapy clinics
Occupational therapy
Speech language pathology

If your practice collects, uses, or discloses personal health information about Ontario patients — PHIPA applies to you.

Key PHIPA requirements for health practices

Limit collection to what is necessary

Collect only the personal health information reasonably necessary for the purpose of providing care.

Obtain consent before disclosure

Patient consent is required before sharing personal health information with third parties not directly involved in care.

Written agent agreements

Any agent handling personal health information on your behalf — IT providers, billing companies, cloud services — must have a written PHIPA agreement.

Safeguards appropriate to sensitivity

Health information is among the most sensitive personal data. Security measures must match the sensitivity — strong passwords alone are not sufficient.

Breach notification to patients

If personal health information is stolen, lost, or accessed without authority, you must notify the affected patients and the Information and Privacy Commissioner.

Retention and disposal policies

Personal health information must be retained for at least 10 years after last use and disposed of securely when no longer needed.

PHIPA questions answered

Does PHIPA apply to my dental clinic or medical practice?
+
What is personal health information under PHIPA?
+
What are the penalties for PHIPA non-compliance?
+
Do I need written agreements with my IT providers?
+
How does Guardlyne help healthcare practices with PHIPA?
+
Check your PHIPA compliance free →