📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Privacy

Ontario PHIPA

The Personal Health Information Protection Act, 2004 · Ontario health information custodians

PHIPA governs how personal health information is collected, used, disclosed, and protected in Ontario. Since 1 January 2024 the Information and Privacy Commissioner can levy administrative penalties up to $500,000 without going through a court, and the breaches that have drawn them so far were not hackers. They were staff looking at records they had no business in.

Map to PHIPASee the obligations

What PHIPA requires

The obligations sit in five places, and they apply to every health information custodian and to the agents and electronic service providers acting for them.

ObligationWhat it means
Lawful handlingCollect, use, and disclose personal health information only with knowledgeable consent or a statutory authority.
SafeguardsTake reasonable steps under section 12(1) to protect the information against theft, loss, and unauthorized use or disclosure.
Access and correctionGive each individual access to their own record and a route to have it corrected.
Breach notificationNotify the affected individual of any theft, loss, or unauthorized use or disclosure, and notify the Commissioner at the first reasonable opportunity where one of seven prescribed circumstances applies.
Annual statisticsFile breach statistics with the Commissioner on or before 1 March each year, covering the previous calendar year.

Two penalty regimes, routinely confused

PHIPA carries two separate enforcement routes, and it helps to keep them apart.

  • Administrative monetary penalties. In force since 1 January 2024, imposed by the Information and Privacy Commissioner without a prosecution, up to $50,000 for an individual and $500,000 for an organization.
  • Prosecuted offences. Up to $200,000 for an individual and $1,000,000 for an organization, plus up to a year in prison.

The practical lesson is in who has been penalized. Both administrative penalties imposed so far were for snooping by an authorized user, which is why audit-log review, not perimeter security, is the control that decides most PHIPA outcomes.

How Lavawall® helps you evidence PHIPA

Lavawall maps your posture to PHIPA from the same shared control library it uses for every framework, and collects timestamped evidence continuously rather than the week before a review.

  • Watch the audit log, the control that matters here. Surface access and monitoring signals across Microsoft 365, Google Workspace, and your endpoints, so authorized-user snooping shows up as a pattern rather than a surprise in a complaint.
  • Prove the safeguards. Evidence the section 12(1) protections, access controls, and configuration against the PHIPA mapping.
  • Be ready for the breach clock. Keep the record you need to notify the individual and the Commissioner at the first reasonable opportunity, and to file the annual statistics.

Related

Primary source: the Personal Health Information Protection Act, 2004, and the Information and Privacy Commissioner of Ontario. Last verified August 28, 2026.

Frequently asked questions

Who does PHIPA apply to?

Every health information custodian in Ontario: hospitals, physicians, clinics, pharmacies, laboratories, long-term care homes, ambulance services, and the boards and agencies that run them, along with their agents and the electronic service providers they use. If you hold or handle Ontario personal health information, PHIPA reaches you.

What are the penalties under PHIPA?

Two separate regimes. Administrative monetary penalties, in force since 1 January 2024, are imposed by the Information and Privacy Commissioner without a prosecution, up to $50,000 for an individual and $500,000 for an organization. Prosecuted offences run up to $200,000 for an individual and $1,000,000 for an organization, plus up to a year in prison.

What breaches must be reported, and when?

A custodian must notify the affected individual of any theft, loss, or unauthorized use or disclosure of their personal health information, and must notify the Information and Privacy Commissioner at the first reasonable opportunity when one of seven prescribed circumstances applies. Custodians also file breach statistics with the Commissioner by 1 March each year for the previous calendar year.

What is the single most important PHIPA control?

Audit log review. Both administrative penalties the Commissioner has imposed to date were for snooping by an authorized user, not an outside attacker. That means the control that matters most is watching what your own authorized users do inside the record, which is a monitoring and review problem more than a perimeter one.

Does Lavawall make us PHIPA compliant?

Lavawall maps your posture to PHIPA, collects timestamped evidence continuously, and surfaces the access and audit-log signals the Act cares about, so a custodian can see and prove its position. Compliance is the custodian's, held with the Information and Privacy Commissioner of Ontario; Lavawall gets you there and keeps you audit-ready.

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →