PHIPA compliance for Ontario
health information custodians
PHIPA governs how Ontario health information custodians collect, use, and disclose personal health information. Valdra assesses your obligations, documents your safeguards, and keeps you IPC audit-ready — and goes further, covering 8 provincial health privacy acts so multi-province providers assess once.
Based on your answers, you may need a Privacy Impact Assessment under Law 25 §12.
AI guidance at every step.
As you answer each question, our Claude-powered AI explains the relevant statutory requirement in plain English, flags your risk level, and suggests remediation steps — so your team learns while they comply.
Request a demoFrom gap to resolved, automatically.
Every identified gap automatically creates a prioritized task with suggested remediation, assigned to the right team member. Track closure rates and demonstrate continuous improvement to your regulator.
Request a demoAdditional features
Request a demoFull PHIPA Coverage
Assesses your obligations as a health information custodian under Ontario's Personal Health Information Protection Act — consent, circle of care, the lockbox, and limiting use to what care requires.
8 Provincial Health Acts
Goes beyond PHIPA to cover Alberta's HIA, Nova Scotia's PHIA and other provincial health privacy acts, so multi-province health providers assess once instead of law-by-law.
Breach Protocol & IPC Reporting
Builds your PHIPA breach response — when to notify the affected individual and the Information and Privacy Commissioner of Ontario (IPC) — with ready-to-send letter templates.
Safeguards Documentation
Documents the administrative, technical, and physical safeguards PHIPA requires and generates audit-ready evidence the IPC will expect to see.
Agent & Service Provider Tracking
Tracks agreements with agents and electronic service providers who handle personal health information on your behalf, as PHIPA requires.
Consent & Circle of Care
Maps implied versus express consent and circle-of-care sharing so clinical workflows stay compliant without slowing patient care.
Frequently asked questions
What is PHIPA compliance?
PHIPA — Ontario's Personal Health Information Protection Act — governs how health information custodians collect, use, and disclose personal health information (PHI). Compliance means having lawful consent, the right safeguards, a breach-response process, and documented agreements with anyone who handles PHI on your behalf. Valdra assesses each obligation and generates the evidence the IPC expects.
Who has to comply with PHIPA?
Health information custodians in Ontario — including hospitals, clinics, physicians, dentists, pharmacists, long-term care homes, and many digital health vendors — plus the agents and electronic service providers acting on their behalf. If you collect or handle personal health information in Ontario, PHIPA applies to you.
When do I have to report a PHIPA privacy breach?
PHIPA requires you to notify affected individuals at the first reasonable opportunity when their PHI is lost, stolen, or accessed without authority. You must also notify the Information and Privacy Commissioner of Ontario (IPC) in defined circumstances, and track statistics for annual reporting. Valdra builds the breach record, scores the risk, and generates the IPC report and notification letters.
Does Valdra cover health privacy laws outside Ontario?
Yes. Beyond PHIPA, Valdra covers 8 provincial health privacy acts — including Alberta's HIA and Nova Scotia's PHIA — so health providers operating in more than one province assess once instead of law-by-law.
Do I report a PHIPA breach to the Ontario IPC or the federal Privacy Commissioner?
For a breach of personal health information held by an Ontario health information custodian, the regulator is the Information and Privacy Commissioner of Ontario — not the federal Office of the Privacy Commissioner. PHIPA is the governing statute and the IPC administers it. The federal OPC enters the picture only where PIPEDA independently applies, such as personal information handled in the course of commercial activity that crosses a provincial or national border. Many compliance tools assume a cross-border transfer by default and list the federal OPC on every report, which sends custodians to the wrong regulator. Valdra lists the IPC alone for an Ontario-only breach, and adds the federal OPC only when you flag a genuine cross-border or interprovincial transfer.
What is the difference between a health information custodian and an agent under PHIPA?
A health information custodian is the organization or practitioner that holds personal health information in connection with their duties — a hospital, clinic, physician, pharmacy or long-term care home. An agent is a person or organization authorized by the custodian to handle that information on the custodian's behalf, such as staff, a billing service, or an IT provider. The distinction matters because accountability does not transfer: the custodian remains responsible for what its agents do with personal health information, and PHIPA also places specific obligations on electronic service providers who supply the systems that store or transmit it. Valdra tracks which parties are custodians, which are agents, and which are electronic service providers, and records the agreements PHIPA expects for each.
Our lines of business are separate legal entities in different provinces. How should we structure that?
Each legal entity should be assessed as its own custodian under the health privacy law of its own province, because obligations, breach thresholds and the responsible regulator all follow the entity and the province rather than the corporate group. Assessing the group as a single organization is a common mistake: it blends provincial obligations together and produces breach reports naming regulators that have no jurisdiction over the entity involved. In Valdra each entity gets its own workspace with its own province, incidents, deadlines and reporting, and you move between them in one click.
Learn more about Valdra
Get compliant and build trust
Join hundreds of Canadian organizations using Valdra to automate their privacy obligations — no consultants required.
🍁 Canadian data residency · PIPEDA compliant · SOC 2 in progress