Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Canada

PHIPA compliant EMR: What your Ontario practice has to prove

Avatar photo Maja Popovska
Last Updated: August 31, 2026
Reviewed by: Avatar photo Lucy Galloway
Key takeaways

Key takeaways

PHIPA does not certify software, so no EMR is PHIPA compliant on its own.

The custodian line splits every duty between your practice as health information custodian and your EMR provider as its agent.

PHIPA offences carry fines up to CAD $1,000,000 for an organization, and administrative penalties now reach CAD $500,000.

Ontario’s first administrative penalties landed in August 2025, and the shared system’s own search records were the evidence.

Ask a vendor for the written agreement, the risk assessment results and the hosting location before you sign.

A PHIPA compliant EMR is an arrangement, not a certified product. Ontario’s Personal Health Information Protection Act, 2004 (PHIPA) places its duties on your practice and on your software provider. PHIPA places none on the software itself.

This guide calls that split the custodian line. The custodian line sets out which duty belongs to you as a health information custodian and which belongs to your EMR provider. Each duty also comes with the document that proves it.

In practices we onboard, the question usually arrives as “is this EMR PHIPA approved?”. That question has no answer, because no PHIPA certification exists for anyone to hold. What does exist is a short list of documents you can ask for and read.

Below you get the four statutory roles and the duty-by-duty split. You also get the current CAD penalty ceilings with their dates, and the record set an Ontario nurse injector’s EMR has to hold.

Found our content helpful?

What makes an EMR PHIPA compliant?

No EMR is PHIPA compliant on its own, because PHIPA assigns its duties to your practice and to your EMR provider. Your practice holds them as the health information custodian. Your provider holds a narrower set as the custodian’s agent or service provider.

EMR is the abbreviation for electronic medical record, the system that holds your patients’ charts. PHIPA governs the information inside it rather than the software around it.

Personal health information (PHI) is identifying information about an individual’s physical or mental health, the health care they received, or their health number. Their substitute decision-maker counts too. A patient’s credit card number is personal information, not PHI, and a different set of rules covers it.

A health information custodian is the person or organization with custody or control of that PHI. In a private practice, the custodian is usually the practice itself or the physician who owns it. An agent is anyone the custodian authorizes to act for it in respect of PHI, for the custodian’s purposes and not their own.

The definition of agent is wide. Your receptionist is an agent, and so, in most arrangements, is the company hosting your charts. The Information and Privacy Commissioner of Ontario (IPC) enforces PHIPA against custodians, and increasingly against their agents too.

So read the rest of this EMR guide as a set of questions to ask, not as a shortlist of approved products. The next section sets out the custodian line duty by duty.

The custodian line: What PHIPA asks of you and what it asks of your EMR provider

PHIPA and its general regulation between them create four roles that matter when you buy software. Which role your provider occupies decides what you can demand of it.

  • Health information custodian. Your practice. Every duty in the Act starts here, and none of them transfers to a vendor.
  • Agent. Anyone authorized to act for the custodian in respect of PHI. Most hosted EMR providers sit here, alongside your own staff.
  • Electronic service provider. A person supplying services that let a custodian handle PHI electronically, and who is not an agent. Section 6(1) of O. Reg. 329/04 gives this role three duties.
  • Health information network provider (HINP). Under O. Reg. 329/04, s. 6(2), a person whose services exist primarily to let two or more custodians disclose PHI to one another electronically.

The HINP role carries the heaviest duties, set out in seven paragraphs of s. 6(3). A HINP must notify every affected custodian at the first reasonable opportunity of unauthorized access.

A HINP must also hand over the written results of a privacy impact assessment and a threat, vulnerability and risk assessment. And it must sign a written agreement describing its services and its safeguards.

There is a practical payoff for the practice. Section 6(4) says that where the provider complies with s. 6(1) and s. 6(3), your practice is not treated as disclosing PHI to the provider. Handing charts to a compliant provider stops being a disclosure that needs consent.

Section 10(4) of the Act is the hook that makes the regulation bite. Anyone supplying goods or services that enable a custodian to handle PHI electronically must comply with the prescribed requirements. Section 6 of the regulation holds those requirements.

OntarioMD certification is not a PHIPA certification

OntarioMD certification tests an EMR offering against Ontario’s mandatory EMR specifications and against the vendor’s own EMR Vendor Certification Agreement. Certification is what allows an offering to connect to provincial services such as OLIS, HRM and the Digital Health Drug Repository.

The current Ontario primary care release, PCON-2024-02, does include a Privacy and Security specification and an EMR Hosting specification. Both specifications are useful assurances about the product. Neither one is a finding about your practice.

Two consequences follow. A certified EMR still leaves every custodian duty with you. The program is also scoped to care domains like primary care. An aesthetic or wellness practice usually has no certified option to shop for at all.

The duty split, and the document that proves each side

DutyYour practice, as health information custodianYour EMR provider, as agent / electronic service provider / HINPThe document that proves it
Written agreementHave one signed before any PHI goes inMust enter one describing the services and the safeguards (reg. s. 6(3)7)The signed agreement and its security schedule
Privacy impact assessmentAssess your own workflow, especially new tools and new integrationsAs HINP, must assess privacy effects and hand over the written results (reg. s. 6(3)5 ii)The written assessment results
Threat, vulnerability and risk assessmentCover your own devices, network and premisesAs HINP, must assess threats to security and integrity, in writing (reg. s. 6(3)5 i)The dated written results
Notification of unauthorized accessNotify the affected patient at the first reasonable opportunity (s. 12(2))Notify every affected custodian at the first reasonable opportunity (reg. s. 6(3)1)The notification clause, with a stated time
Audit logging and log retentionAudit and monitor who opened which record, and how oftenKeep and make available a record of every access and transfer (reg. s. 6(3)4)An export naming users, records, dates and times
Access control and user provisioningSet roles, review them, and remove a leaver the same dayBuild the permission model, and bind its own staff (reg. s. 6(1)3)Your role matrix, plus the leaver checklist
EncryptionRequire it, then check that it is onState the algorithms at rest and the TLS version in transitThe vendor’s written security statement
Retention and secure disposalSet the period, and dispose securely (s. 13(1))Delete on instruction, and confirm the deletionYour retention schedule and a deletion confirmation
Breach reporting to the IPCReport when a trigger applies, and file annually by March 1 (reg. ss. 6.3, 6.4)Give you the facts you need in time to reportThe incident record and the filed annual report
Staff privacy trainingTrain every agent, and take reasonable steps so none misuses PHI (s. 17(3))Train its own staff and any subprocessorDated training records and signed confidentiality agreements

Read down the fourth column and the pattern is clear. Every duty on the custodian line resolves into a document. So compliance tools for practices get judged on what they can produce, not on what they claim.

The diagram below plots the same duties by side, using only the rows in the table above.

Two-column diagram of the custodian line: the practice as health information custodian sets roles, trains agents, sets retention, notifies patients and reports to the IPC by March 1; the EMR provider uses PHI only as needed, never discloses it, binds staff and subprocessors, notifies custodians of unauthorized access and publishes its safeguards; four duties cross the line in writing, namely the written agreement, the privacy impact assessment, the threat vulnerability and risk assessment, and an exportable access log
Four duties sit on the line itself, and each one only counts if it exists in writing. Duties drawn from PHIPA ss. 10 to 17 and O. Reg. 329/04, s. 6.

The whole section lands on one sentence. “PHIPA compliant EMR” describes an arrangement, not a badge on a product.

PHIPA, PIPEDA and HIPAA: Which privacy law applies to your practice

If you provide health care in Ontario, PHIPA governs your patient records. PIPEDA covers personal information handled in commercial activity, and HIPAA is US law that does not reach an Ontario practice.

The reason the two Canadian statutes do not collide is a federal order. On December 14, 2005, the Governor in Council declared PHIPA substantially similar to Part 1 of PIPEDA.

The instrument is the Health Information Custodians in the Province of Ontario Exemption Order. That order exempted Ontario custodians and their agents from PIPEDA for PHI handled within the province.

PIPEDA still reaches an Ontario practice in three places. It applies to PHI you send across a provincial or national border. It applies to commercial activity unrelated to care, such as retail product sales or a loyalty scheme. And it applies to federally regulated organizations you may deal with.

Searches like “CRM HIPAA compliant” and “HIPAA-compliant EMR” send Ontario buyers to US vendor pages every week. A vendor’s HIPAA claim describes a different statute, a different regulator and a different breach clock. The claim tells your practice nothing about its own duties under PHIPA.

Our own guide to HIPAA compliance software is written for US practices, and the contrast is useful. HIPAA runs on a required risk analysis and a business associate agreement. PHIPA runs on reasonableness, a written service agreement, and the IPC’s willingness to read your logs.

StatuteWho it bindsWhat informationRegulatorMaximum penalty (CAD)
PHIPAOntario health information custodians and their agentsPersonal health informationInformation and Privacy Commissioner of Ontario$1,000,000 fine for an organization, or a $500,000 administrative penalty
PIPEDAOrganizations handling personal information in commercial activity across CanadaPersonal information, outside the Ontario custodian exemptionOffice of the Privacy Commissioner of Canada$100,000 per offence on indictment, $10,000 on summary conviction
HIPAAUS covered entities and their business associatesProtected health informationUS Department of Health and Human Services, Office for Civil RightsDoes not apply to an Ontario practice

Two Ontario statutes sit alongside PHIPA for some organizations. Public hospitals fall under FIPPA, and municipal boards of health under MFIPPA, for their records that are not PHI. A private practice normally has neither to worry about.

The 4 categories of PHIPA duties your EMR has to support

PHIPA’s duties on custodians and their agents fall into four categories, and your EMR has to carry its share of each one. The 4 categories of PHIPA duties below follow the Act’s own structure. The Act runs to nine parts, and the parts that touch software are practices to protect PHI, consent, and access and correction.

  1. Collection, use and disclosure of PHI. Your EMR has to record the consent it relied on, honour a patient’s instruction to lock part of the record, and log any override.
  2. Security of PHI. Section 12(1) asks for steps that are reasonable in the circumstances, across administrative, technological and physical safeguards.
  3. Transparency of information practices. Section 10(1) requires you to have information practices that comply with the Act, and to describe them publicly.
  4. Responding to access and correction requests. Your EMR has to produce a patient’s whole record, in a readable form, inside a statutory clock.

Consent sits inside the first category and causes most of the confusion. A custodian may rely on implied consent to share PHI with another custodian for the purpose of providing health care. Sharing outside that circle of care generally needs express consent.

PHIPA also lets a patient give a consent directive, widely called a lock-box, restricting what may be shared. An override is permitted in narrow circumstances, and the override is exactly the event your EMR should record. A lock-box the software cannot enforce is a policy, not a safeguard.

The statutory definition of “use” is worth reading closely. PHIPA defines use as viewing, handling or otherwise dealing with PHI, and it excludes disclosing that information. Opening a chart is a use, which is why every chart opened belongs in the log.

The fourth category comes with two hard numbers. Section 54(2) gives you 30 days to respond to an access request, and s. 54(3) allows one extension of up to 30 more days in defined circumstances. Section 55 covers correction requests.

Age matters too. Where a child is under 16, a parent may generally give or withhold consent, with exceptions for treatment and counselling decisions the child made alone. From age 16, the patient may authorize someone else in writing to act for them. Retention sits nearby, and our guide to medical record retention covers the periods your college sets.

What PHIPA requires from your EMR charting and audit log

PHIPA requires your EMR to record who accessed which patient record, when, and what they did, and to keep that log available for the IPC. EMR charting generates most of that log volume, because every note opened is a use of PHI.

One provision spells the log out field by field, and it is not yet in force. Bill 188 added s. 10.1 to PHIPA, an electronic audit log section. Section 10.1 sits on the statute books awaiting proclamation.

Section 10.1(4) names the fields the log would have to carry for every record viewed, handled or modified.

  • The type of information that was viewed, handled, modified or otherwise dealt with
  • The date and time it happened
  • The identity of every person who dealt with the information
  • The identity of the individual the information relates to

Section 10.1(2) would also require the custodian to give the Commissioner a copy of the log on request. Treat that list as the specification to buy against now. Until proclamation, the duty still arrives through s. 12(1) and through reg. s. 6(3)4, which requires your provider to keep an access and transfer record and make it available.

The safeguards your EMR has to carry

  • Role-based access control. Permissions by job, not by seniority, and least privilege as the default.
  • User provisioning and de-provisioning. A named owner for adding accounts, and a same-day rule for removing them.
  • Encryption. At rest on the server and in transit over the network, with the vendor stating both.
  • Backups. Tested restores, a stated retention period, and encryption on the backup copies too.
  • Device controls. Mobile device management, remote wipe, screen locks, and a written rule for personal devices.

Two habits break all of this faster than any technical weakness. Shared login credentials make the log useless, because an entry names an account rather than a person. Unmanaged personal devices put charts on a phone your practice cannot wipe.

Ontario’s first administrative penalty case turned on log quality. The searches were reconstructed from the shared system’s own records, which is covered in full further down. Our guide to EHR security goes deeper on the controls themselves.

Pabau user detail screen showing the Permissions tab, with expandable sections for Features, Patient information and Read/Write permissions for a single staff member
Staff permissions in Pabau, our practice management software, set what each person can see, edit and export. Least privilege becomes a setting rather than a policy nobody checks.

EMR and EHR in Ontario: Why the difference changes your PHIPA duties

The EMR and EHR distinction decides which set of rules applies to a given click. Your EMR is your practice’s own record system, in your custody and control. Ontario’s provincial EHR is a separate shared asset, and Part V.1 of PHIPA governs it.

Part V.1 came into force on October 1, 2020. It defines the electronic health record as the systems developed and maintained by the prescribed organization. O. Reg. 329/04 prescribes the Agency for that role, which is Ontario Health, continued under the Connecting Care Act, 2019.

Ontario Health is the sole prescribed organization, and the IPC does not simply take its word for its controls. Under s. 55.12(1), the Commissioner reviews the prescribed organization’s practices and procedures every three years and may renew the approval.

What changes for your practice is the label on the same action. Section 55.1(2) says that viewing another custodian’s PHI in the provincial EHR for the first time is a collection. Every later view of it is a use. You only disclose when another custodian collects what you contributed.

That relabelling matters because your consent obligations follow the label. Consent directives at the provincial level run under s. 55.6, and overrides under s. 55.7. Part V.2 adds digital health identifier activities, which is the layer ONE ID sits on.

Types of EMR Ontario practices use, and what each means for compliance

Ontario has no single system, and no ranked answer is honest here. The types of EMR below differ less in features than in who holds the keys. Ask the same nine questions of every EMR application you shortlist, whatever type it belongs to.

  • OntarioMD-certified EMRs. Mostly primary care. Certification covers hosting and a privacy and security specification, and it is what permits connection to OLIS and HRM. Every custodian duty still sits with you.
  • Cloud-hosted practice management systems. Common in aesthetics, wellness and allied health, where no certification program applies. The hosting region is the vendor’s choice, so get it in writing along with the subprocessor list.
  • On-premise systems. You hold the server and the keys, so patching, backups and physical security are yours. Your IT environment becomes part of the compliance question, separately from the software.
  • Specialty systems. Dermatology, physical therapy and injectables tools, often paired with a separate booking or photo product. Each extra product is another written agreement you owe yourself.

One distinction saves a lot of argument. An EMR license tells you what you may use and for how long. The license says nothing about where your data lives, who at the vendor can read it, or what you get back when you leave.

EMR/EHR integration with Ontario’s provincial systems

EMR/EHR integration in Ontario means a small number of named connections, each with its own PHIPA consequence. Four come up most often.

  • OLIS. The Ontario Laboratories Information System, which delivers lab results into the EMR.
  • HRM. Health Report Manager, which delivers hospital and specialist reports into the EMR.
  • ConnectingOntario ClinicalViewer. A web portal giving a province-wide view of dispensed medications, lab results, hospital visits, home and community care, mental health information and diagnostic imaging.
  • ONE ID. eHealth Ontario’s digital identity and authentication service, which is how a clinician proves who they are before any of the above opens.

OLIS and HRM come with a gate. Connecting to them requires an OntarioMD-certified EMR offering holding an active certificate, so the choice of product decides whether the connection is available at all.

Each connection also changes what your log has to show. A report arriving from HRM is a collection, and the ClinicalViewer records a lookup against the clinician who made it rather than against your practice.

Integration is also where a provider’s role can shift. The moment a service exists primarily to let two or more custodians disclose PHI to one another, reg. s. 6(2) catches it as a HINP, and the seven duties in s. 6(3) attach. Ask any integration partner which side of that line it thinks it is on.

Virtual care, video and messaging: Keeping add-on tools inside PHIPA

Every tool that touches patient information sits inside your PHIPA duties, so a video platform needs the same written agreement as your EMR. A free tool, or a widely used one, is no exception.

Searches like “Zoom PHIPA compliance” and “Doxy me PHIPA compliant” get typed constantly, and the honest answer is the same for both. No product is compliant by itself. Some are configurable into a compliant arrangement, and some are not, and the agreement is what tells you which.

So run the tool through five checks rather than looking for a verdict.

  1. Will the vendor sign an agreement naming the services and the administrative, technical and physical safeguards?
  2. Where does the session land, and where does any recording land?
  3. Is that recording a record of PHI in your custody, and who is expected to delete it?
  4. What encrypts the session in transit, and which vendor staff can reach the content?
  5. What happens to the data when the subscription ends?

The answers also tell you the vendor’s role. A video tool serving only your practice is usually an electronic service provider under reg. s. 6(1), owing those three duties. A tool built so your practice and a hospital can exchange PHI can be a HINP instead.

One warning is worth adding about recordings. A consultation recording that nobody has assigned to a retention schedule is the record most likely to outlive its purpose. Secure disposal under s. 13(1) still applies to it.

Nurse injectors and medical directives: What your EMR has to record

An Ontario nurse injector works under a medical directive, and the EMR has to hold the directive, the authorizing prescriber and the product’s batch number. Injecting botulinum toxin or a dermal filler is a controlled act, so an RN or RPN needs an order to perform it.

That order arrives one of two ways. A patient-specific order authorizes one named patient. A written medical directive authorizes a procedure for a class of patients who meet stated conditions. Either mechanism has to satisfy two sets of standards. Those come from the College of Nurses of Ontario (CNO) and the College of Physicians and Surgeons of Ontario (CPSO).

PHIPA does not write that record set for you. Your college standards and your own liability do. What PHIPA adds is that the whole set is PHI, so it inherits every duty in the table above.

The record set the EMR has to hold

  • The authorizing prescriber’s name and registration number
  • The directive, its version number and its effective dates
  • Which authorizing mechanism applied to this appointment, recorded per appointment
  • The injector’s documented training and competence for this procedure
  • The product, the dose, and the batch or lot number administered
  • The consent form, signed and dated before the treatment
  • Before-and-after photographs on the same patient timeline
  • Who administered the treatment, and who else was on site

The third item is the one practices skip, and it is the one under active change. CNO has consulted on new guidance for non-surgical cosmetic procedures, and one direction under discussion would narrow when a directive can be used at all.

Under that version, a physician or nurse practitioner would authorize each treatment rather than a class of them. Public consultation closed in 2026 and the guidance was not settled when this was written, so treat the direction of travel as the planning assumption.

The practical response costs nothing. Record the authorizing mechanism against each appointment instead of once against the directive. A record built that way survives either rule without a migration.

Size does not change the duty, but it changes what counts as reasonable. A solo injector and a six-site group owe identical duties under PHIPA. The IPC’s own safeguarding guidance says organization size is a factor, and that custodians must scale security to their circumstances.

How to verify a PHIPA compliant EMR before you sign

Ask the vendor for the written agreement, the privacy impact assessment, the hosting location and the breach-notification commitment, then read them before you sign. Each question below has a document that answers it, and a bad answer that should slow you down.

  1. Will you sign an agreement naming the services and the safeguards? Get the agreement and its security schedule. A link to a public security page is not an agreement.
  2. In this arrangement, are you our agent, an electronic service provider or a HINP? Get the clause that says which. “We’re PHIPA compliant” answers nothing.
  3. What did your privacy impact assessment find? Get the written results. A confirmation that one exists is not the finding.
  4. What did your threat, vulnerability and risk assessment find, and when? Get the dated written results. A penetration test summary is a different document.
  5. Where is the data hosted, and does it stay in Canada? Get a statement naming the infrastructure provider and the region. “In the cloud” is not a location.
  6. Which subprocessors touch the data, and are they bound to the same terms? Get the list. No list usually means nobody has counted.
  7. How fast will you tell us about unauthorized access, and in what form? Get a stated time in the agreement. “As soon as possible” is not a commitment.
  8. Can we export the access log ourselves, and how long do you keep it? Get a sample export and the log retention period. Raising a support ticket is not self-service.
  9. What is the retention, secure disposal and export process on exit? Get the schedule and the export format. A folder of PDFs is not a portable record.

Name a privacy contact person on your side too, and get the vendor’s equivalent named in the agreement. An incident at 6pm on a Friday is not the moment to work out who to email.

If you run a solo practice, four of the nine carry most of the weight. Questions 1, 5, 7 and 8 cover the agreement, the hosting location, the notification clock and the exportable log.

Table of nine vendor questions and the document that answers each: the signed agreement and security schedule, the clause naming the provider's role, written privacy impact assessment results, dated threat vulnerability and risk assessment results, a hosting statement naming provider and region, the subprocessor list, a notification service level with a stated time, a sample access log export with its retention period, and the retention, disposal and export process on exit. Questions 1, 5, 7 and 8 are marked insist for a solo practice
The four rows marked “insist” are the ones a solo practice should not sign without. Questions built from the duties in O. Reg. 329/04, s. 6.

PHIPA penalties and breach reporting: What happens when the EMR is the weak point

A PHIPA breach means notifying the affected patient and, in prescribed circumstances, the IPC, and it can carry an administrative penalty up to CAD $500,000. The reporting duty arrives before any penalty question does.

Section 12(2) requires you to notify the affected individual at the first reasonable opportunity, and to tell them they may complain to the Commissioner. Section 12(3) adds the report to the IPC, and O. Reg. 329/04, s. 6.3(1) lists the seven circumstances that trigger it.

Three of those triggers catch EMR incidents most often. A use or disclosure by someone who knew they were not authorized. A loss that is part of a pattern. And any loss you judge significant, weighing sensitivity, volume and the number of patients involved.

There is also an annual filing that catches practices out. Under reg. s. 6.4, every custodian must give the Commissioner a report on or before March 1 each year. The report counts the previous year’s thefts, losses, unauthorized uses and unauthorized disclosures. A fifth category covers PHI collected without authority through the provincial electronic health record. A year with none still needs a filing of zero.

RouteWho it applies toMaximum (CAD)In force since
PHIPA s. 72(2) offenceA natural person$200,000, and up to one year’s imprisonmentMarch 25, 2020, doubled from $100,000
PHIPA s. 72(2) offenceA person other than a natural person$1,000,000March 25, 2020, doubled from $500,000
Administrative monetary penaltyA natural person$50,000January 1, 2024
Administrative monetary penaltyA person other than a natural person, including a professional corporation$500,000January 1, 2024

The doubling in 2020 came from Bill 188, the Economic and Fiscal Update Act, 2020. The administrative penalty regime arrived through an amendment to O. Reg. 329/04, and s. 35 of that regulation sets both ceilings.

Two details in s. 35 matter more than the headline figures. The Commissioner may add to a penalty an amount equal to the economic benefit the person gained. And s. 61.1(3) of the Act gives a two-year limitation from when the contravention came to the Commissioner’s knowledge.

PHIPA Decision 298, and why the log was the case

PHIPA Decision 298, dated August 27, 2025, was the first time the IPC imposed administrative penalties. A physician with privileges at three Windsor-area hospitals used their shared electronic health record to find newborn males.

He ran person searches by sex and date of birth rather than opening charts. The hospitals’ shared services organization reconstructed 146 such searches, through which he could view the PHI of potentially 831 patients.

Between April 20 and May 7, 2024, he used that information to contact 91 individuals by phone or text. The offer was circumcision services at his own pediatric practice, at $350 per procedure.

The Commissioner imposed CAD $5,000 on the physician and CAD $7,500 on the practice. The practice was its own health information custodian, and the physician was acting as its agent. It had imposed no conditions or restrictions on him at the time.

The lesson sits in how he was caught. Nobody spotted this in a chart, because he never opened one. The count of 146 searches, the 831 patients and the window of dates all came out of the system’s own access records.

The practice’s own remediation makes the point again. Before the breach it had no privacy program at all, so neither control existed to be switched on. It then limited EMR access by role and began six-monthly audits of who logged into which chart. Those audits started in September 2024, months after the April and May searches.

So treat the access log as evidence rather than a compliance checkbox. Somebody may read it back to you, which makes log quality the feature to buy on.

One point keeps the risk in proportion. The IPC’s published guidance says administrative penalties are not its default response, and are aimed at more severe contraventions rather than one-off mistakes.

How Pabau supports a PHIPA-ready record in an Ontario practice

In most Ontario practices we meet, the record set from the injector section is spread across four places. The directive sits in a binder, the photos on a phone, the batch numbers in a notebook, and the consent forms in a filing cabinet. No single log covers any of it.

Practice management software like Pabau puts the appointment, the consent form, the treatment note, the before-and-after photographs and the stock record on one patient timeline. Pabau’s staff permissions control who can view, edit or export each part of the client record, down to individual fields.

Every action lands in Pabau’s audit trail, so an access question has an answer you can print instead of reconstruct. Photos carry automatic date and time stamps, and pre- and aftercare messages stay in the record as evidence they were sent.

On the vendor side of the custodian line, Pabau publishes what it will put in writing. A Data Processing Agreement is available. Encryption uses AES-256 at rest and TLS 1.2 or higher in transit, with DigitalOcean as the infrastructure provider. Backups run daily and are kept for six months. Independent penetration testing runs at least annually.

Pabau is not a PHIPA certified EMR, and no vendor is, because no such certification exists. So run the nine questions above at us exactly as you would at anyone else, starting with the written agreement and the hosting location.

Keep every access and consent on one record

Pabau puts the consent form, the treatment note, the batch number and the photos on one patient timeline. Staff permissions and an audit trail sit behind them. Pabau gives an Ontario practice one place to answer an access question.

Pabau clinic management dashboard

Conclusion

Stop shopping for a compliance badge, because Ontario does not issue one. Judge a vendor on the custodian line instead. That means the agreement the vendor will sign and the assessments it will hand over. It also means the hosting location it will name, and the log it will let you export.

Two things change when you buy that way. Your due diligence becomes a file you can show the IPC, and your access log becomes readable evidence rather than a feature nobody has opened.

The trade-off worth remembering is that none of it transfers. A vendor can carry its share of the duties and prove that share in writing. The custodian duty stays with your practice permanently. Book a demo to see how Pabau keeps consent, charting and the access log on one Ontario patient record.

Continue your research

Continue your research

Worried what your access log would show today? Medical chart audit sets out how to review your own charts before a regulator does.

Need to know how long records have to stay? How long to keep medical records covers retention periods and the secure disposal step at the end of them.

Something already gone wrong? What to do if you violate HIPAA walks a breach response sequence that maps closely onto PHIPA’s notification steps.

Writing the public statement of your information practices? Notice of privacy practices template gives you a structure to adapt for your own practice.

Still moving off paper charts? Running a paperless practice covers the safeguards that change when the filing cabinet disappears.

Frequently asked questions

What does PHIPA stand for?

PHIPA stands for the Personal Health Information Protection Act, 2004. The statute governs how Ontario health information custodians collect, use and disclose personal health information, and the IPC enforces it.

What’s the difference between PHIPA and HIPAA?

PHIPA binds Ontario custodians and is enforced by the Information and Privacy Commissioner of Ontario. HIPAA is a US statute enforced by the Office for Civil Rights. A vendor’s HIPAA-compliant claim describes American obligations, so it names duties an Ontario practice does not have.

What EMR does Ontario use?

There is no single provincial system. Primary care largely runs OntarioMD-certified products that connect to OLIS and HRM, while aesthetic, wellness and allied health practices mostly use cloud practice management systems. The types of EMR matter more than the brand name.

What is the best EMR system in Canada?

No single product wins, because the deciding factors sit in the arrangement around it. Judge a system on the agreement the vendor will sign and the hosting location it will name. Then check the access log you can export, and the retention terms on exit.

What is the definition of use in PHIPA?

PHIPA defines use as viewing, handling or otherwise dealing with personal health information, and it expressly excludes disclosing that information to someone else. Opening a patient chart is therefore a use, which is why it belongs in your audit log.

Found our content helpful?
×