Business
Business Security · Overview Shadow · Mailbox Forensics Executive Protection
Individual
Personal Protection · Overview Personal Credential Scan
Programs
Family Offices Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
Home · Frameworks · PHIPA
Reference · LeakTrace Intelligence Team

PHIPA.

Personal Health Information Protection Act, 2004 (Ontario)
At a glance
Jurisdiction
Ontario
Breach reporting deadline
At the first reasonable opportunity
Applies to
Healthcare
Authoritative source
https://www.ontario.ca/laws/statute/04p03
Last updated
August 5, 2026
## What it is PHIPA is Ontario's sector-specific privacy statute governing personal health information (PHI). Enforced by the Information and Privacy Commissioner of Ontario (IPC), it operates as substantially-similar legislation to PIPEDA for the Ontario health sector — PIPEDA does not apply to PHI handled by Ontario health information custodians (HICs). ## Who it applies to Health information custodians as defined in section 3 — a broad category including: - Health care practitioners (physicians, dentists, nurses, pharmacists, psychologists, and other regulated health professionals) - Hospitals, long-term care homes, community care access centres - Independent health facilities, laboratories, specimen collection centres - Ambulance services - Ministry of Health and Long-Term Care in specified capacities - Local health integration networks Agents of custodians (employees, contractors, service providers) are bound by the same duties on the custodian's behalf. ## Key data protection requirements Custodians must obtain express or implied consent depending on circumstance, limit collection/use/disclosure to what is reasonably necessary, provide individuals with access to their PHI, and implement safeguards appropriate to sensitivity. The circle-of-care doctrine allows PHI sharing among practitioners providing care to the same individual without explicit consent for each transfer. ## Breach reporting Since October 1, 2017, PHIPA has required custodians to: - **Notify affected individuals** at the first reasonable opportunity of any theft, loss, or unauthorized use/disclosure of PHI - **Notify the IPC** in prescribed circumstances (Ontario Regulation 224/17): where the incident was theft/deliberate act by an agent, involved further unauthorized use after initial breach, is part of a pattern of breaches, or the custodian would be required to notify the College or regulator - **Report annually to the IPC** the total number of privacy breaches — regardless of whether they met the individual-notification threshold ## Penalties Provincial offence prosecutions can result in fines up to CAD $200,000 for individuals and CAD $1,000,000 for corporations under section 72. Wilful contravention, use of PHI for personal gain, or obstruction of the Commissioner is treated as an offence. The IPC also has order-making powers to require compliance, cease certain practices, and require security improvements. ## How LeakTrace aligns LeakTrace runs continuous monitoring on healthcare-sector exposures — credential leaks affecting practitioner accounts, misconfigured PHI-adjacent infrastructure, dark-web listings of Ontario health data. Breach evidence is prepared for IPC submission with chain-of-custody documentation and includes the annual breach statistics format IPC now requires from HICs.
Key provisions
Section 12 — Duty to protect
HICs must take reasonable steps to safeguard PHI against theft, loss, unauthorized use, and unauthorized disclosure.
Section 17 — Circle of care
Assumed implied consent for PHI sharing among practitioners providing direct care to the same individual.
Section 12(2) — Individual notification
Notify affected individuals at the first reasonable opportunity following any theft, loss, or unauthorized use/disclosure.
Ontario Regulation 224/17 — IPC notification triggers
IPC must be notified where the incident involved a deliberate act by an agent, further unauthorized use, was part of a pattern, or triggered college/regulator reporting.
Section 72 — Offences
Fines up to CAD $200,000 (individual) or CAD $1,000,000 (corporation) for offences including obstruction of the Commissioner.
Recent amendments & guidance
2017-10-01
Mandatory individual notification and expanded IPC notification triggers (Ontario Regulation 224/17) came into force.
2020-03-25
Bill 188 (Economic and Fiscal Update Act, 2020) — expanded IPC powers including administrative monetary penalties (AMP) framework. [VERIFY AMP proclamation status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs