PHIPA custodians and safeguards
Sources reviewed: August 29, 2026
Health information custodians are accountable for lawful information practices, appropriately authorized agents, reasonable safeguards, statutory accuracy obligations, and required responses to privacy breaches.
Key information
Accountable information practices
A custodian must maintain information practices that comply with PHIPA and its regulations and make accountability visible to individuals.
Adopt compliant practices governing the collection, use, disclosure, retention, transfer, and disposal of personal health information.
Designate a contact person as PHIPA requires and make a written public statement available that describes the custodian’s information practices, contact information, access and correction process, and complaint routes.
Collect, use, or disclose personal health information only with valid consent under PHIPA or when PHIPA permits or requires the activity.
Inform agents of their duties, authorize only necessary handling, and remain accountable for information the agents use on the custodian’s behalf.
Purpose, necessity, and accuracy
PHIPA limits when personal health information may be collected, used, or disclosed and how much information may be involved.
Do not collect, use, or disclose personal health information when other information would serve the purpose, unless the law requires the personal health information.
Do not collect, use, or disclose more personal health information than is reasonably necessary for the purpose, unless the law requires it.
Before using personal health information, take reasonable steps to ensure it is as accurate, complete, and up to date as necessary. Before disclosing it, take those steps or clearly set out any limitations on its accuracy, completeness, or currency.
Ensure each collection, use, or disclosure is necessary for a lawful purpose covered by valid consent or is permitted or required by PHIPA.
Reasonable safeguards and secure records
Safeguards must be reasonable in the circumstances and protect personal health information throughout its lifecycle.
Use reasonable administrative, technical, and physical safeguards against theft, loss, unauthorized use or disclosure, and unauthorized copying, modification, or disposal.
Retain, transfer, and dispose of records securely and in accordance with applicable legal and professional requirements.
Ensure employees, staff, and other agents understand their PHIPA duties and the custodian’s information practices.
Use role-appropriate agreements and controls for third-party services, including any requirements prescribed for persons supplying services that enable custodians to handle personal health information electronically or for health information network providers.
Privacy breach response
PHIPA assigns specific duties when personal health information is stolen or lost, or used or disclosed without authority.
Act promptly to contain the incident, investigate what occurred, mitigate harm, and prevent recurrence as part of an accountable response.
Subject to the Act’s exceptions and additional requirements, notify the affected individual at the first reasonable opportunity of theft, loss, or unauthorized use or disclosure. The notice must state that the individual may complain to the IPC.
When personal health information is used or disclosed without consent in a manner not described in the custodian’s public statement, the custodian must generally inform the individual at the first reasonable opportunity and make a note in, or link it to, the record unless the individual has no right of access to it.
Report prescribed categories of privacy breaches to the IPC and make any other notification required by the Act or regulation.
How implementation varies by organization
PHIPA establishes the legal requirements, while each custodian must follow compliant information practices and make its required written public statement available.
Different custodians may use different privacy contacts, identity-verification steps, request forms, secure delivery methods, and lawful fee schedules.
A public-sector organization may act as a health information custodian for some records and hold other records under a different Ontario access and privacy statute.
An organization’s notice explains its local process; it does not replace the current PHIPA statute, regulation, or IPC oversight.
Authoritative sources
These summaries are based only on current Ontario legislation and official guidance from Ontario’s health privacy regulator. Check the linked sources for amendments, exceptions, forms, and current procedural instructions.