Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · PHIPA
Reference · LeakTrace Intelligence Team

PHIPA.

Personal Health Information Protection Act, 2004 (Ontario)
At a glance
Jurisdiction
Ontario
Breach reporting deadline
At the first reasonable opportunity
Applies to
Healthcare
Authoritative source
https://www.ontario.ca/laws/statute/04p03
Last updated
August 5, 2026
## What it is PHIPA is Ontario's sector-specific privacy statute governing personal health information (PHI). Enforced by the Information and Privacy Commissioner of Ontario (IPC), it operates as substantially-similar legislation to PIPEDA for the Ontario health sector — PIPEDA does not apply to PHI handled by Ontario health information custodians (HICs). ## Who it applies to Health information custodians as defined in section 3 — a broad category including: - Health care practitioners (physicians, dentists, nurses, pharmacists, psychologists, and other regulated health professionals) - Hospitals, long-term care homes, community care access centres - Independent health facilities, laboratories, specimen collection centres - Ambulance services - Ministry of Health and Long-Term Care in specified capacities - Local health integration networks Agents of custodians (employees, contractors, service providers) are bound by the same duties on the custodian's behalf. ## Key data protection requirements Custodians must obtain express or implied consent depending on circumstance, limit collection/use/disclosure to what is reasonably necessary, provide individuals with access to their PHI, and implement safeguards appropriate to sensitivity. The circle-of-care doctrine allows PHI sharing among practitioners providing care to the same individual without explicit consent for each transfer. ## Breach reporting Since October 1, 2017, PHIPA has required custodians to: - **Notify affected individuals** at the first reasonable opportunity of any theft, loss, or unauthorized use/disclosure of PHI - **Notify the IPC** in prescribed circumstances (Ontario Regulation 224/17): where the incident was theft/deliberate act by an agent, involved further unauthorized use after initial breach, is part of a pattern of breaches, or the custodian would be required to notify the College or regulator - **Report annually to the IPC** the total number of privacy breaches — regardless of whether they met the individual-notification threshold ## Penalties Provincial offence prosecutions can result in fines up to CAD $200,000 for individuals and CAD $1,000,000 for corporations under section 72. Wilful contravention, use of PHI for personal gain, or obstruction of the Commissioner is treated as an offence. The IPC also has order-making powers to require compliance, cease certain practices, and require security improvements. ## How LeakTrace aligns LeakTrace runs continuous monitoring on healthcare-sector exposures — credential leaks affecting practitioner accounts, misconfigured PHI-adjacent infrastructure, dark-web listings of Ontario health data. Breach evidence is prepared for IPC submission with chain-of-custody documentation and includes the annual breach statistics format IPC now requires from HICs.
Key provisions
Section 12 — Duty to protect
HICs must take reasonable steps to safeguard PHI against theft, loss, unauthorized use, and unauthorized disclosure.
Section 17 — Circle of care
Assumed implied consent for PHI sharing among practitioners providing direct care to the same individual.
Section 12(2) — Individual notification
Notify affected individuals at the first reasonable opportunity following any theft, loss, or unauthorized use/disclosure.
Ontario Regulation 224/17 — IPC notification triggers
IPC must be notified where the incident involved a deliberate act by an agent, further unauthorized use, was part of a pattern, or triggered college/regulator reporting.
Section 72 — Offences
Fines up to CAD $200,000 (individual) or CAD $1,000,000 (corporation) for offences including obstruction of the Commissioner.
Recent amendments & guidance
2017-10-01
Mandatory individual notification and expanded IPC notification triggers (Ontario Regulation 224/17) came into force.
2020-03-25
Bill 188 (Economic and Fiscal Update Act, 2020) — expanded IPC powers including administrative monetary penalties (AMP) framework. [VERIFY AMP proclamation status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs