Skip to content
Datarex
PHIPA for Community Organizations: What Applies to You
Back to Blog

PHIPA for Community Organizations: What Applies to You

Russ AlexanderAugust 27, 20264 min read

The short answer

PHIPA is Ontario's Personal Health Information Protection Act, 2004. It sets the rules for how personal health information can be collected, used, and shared in the province. Whether it applies to your organization comes down to one question: are you a health information custodian, or do you handle personal health information on behalf of one.

This is plain-language orientation, not legal advice. If you need a definitive answer about your organization's status under PHIPA, get that from counsel. What follows is meant to help you ask the right questions, not to replace a legal opinion.

Who PHIPA applies to

The Information and Privacy Commissioner of Ontario, the regulator that oversees PHIPA, defines a health information custodian as a person or organization that has custody or control of personal health information as a result of their power, duties, or work. The IPC's own guidance points to hospitals, pharmacies, laboratories, and individual health care providers such as physicians in clinical practice as the clearest examples.

Most community organizations are not custodians themselves. Many still fall under PHIPA because they act as an agent: someone authorized by a custodian to handle personal health information on the custodian's behalf, for the custodian's purposes rather than their own. A contracted service provider, a program running alongside a clinic, or an organization that receives client referrals from a health care provider can all end up in this category. The custodian stays responsible for how the information is handled overall, but the agent has real obligations too, and both sides need to be clear on which one they are.

If your organization neither has custody of personal health information nor acts on a custodian's behalf, PHIPA likely doesn't apply directly to your work. Other privacy law may still apply, depending on what data you hold and how you're funded.

What PHIPA expects in practice

For organizations that are custodians or agents, the same few expectations come up again and again.

Know where personal health information lives. Every system, spreadsheet, and shared folder that holds it needs to be on a list somewhere. You can't protect what you haven't located.

Limit who can reach it. Access should match role, not convenience. The fewer people who can open a record, the smaller the exposure if something goes wrong.

Log access. Custodians need to be able to show who looked at a record and when, both to catch problems early and to answer for them after the fact.

Report breaches. PHIPA requires custodians to notify affected individuals if their personal health information is stolen, lost, or used or disclosed without authority, and to notify the IPC in the circumstances set out in the Act and its regulations.

A practical checklist

  • List every system, spreadsheet, and shared drive that holds personal health information, including informal ones.
  • Confirm whether your organization is a custodian, an agent, or neither, and get that confirmed by counsel if it's unclear.
  • Review who has access to health information and whether that access still matches their current role.
  • Confirm you can produce a record of who viewed a specific file, and when, if asked.
  • Write down what happens in the first hour after a suspected breach, including who gets told and in what order.
  • Revisit all of the above at least annually, and whenever a system or a staff role changes.

The takeaway

PHIPA compliance starts with knowing which side of the custodian question you're on, and it holds up better when it's planned for early rather than added on after something goes wrong. Datarex plans for PHIPA from the start of an engagement with organizations in this sector, rather than treating it as a separate step once something else is already built. A Security & Compliance Review covers where sensitive data lives, who can reach it, and what your obligations actually require, with the gaps named and a remediation list in priority order. For more on how Datarex works with organizations in this sector, see Technology for Nonprofits and Social Services.

Schedule a quick call to see if we can help.

Get in Touch