What Is PHIPA? Ontario’s Health Privacy Law and Secure Email
PHIPA is Ontario's sector-specific health privacy law, and it sets the rules for how personal health information is collected, used, and disclosed in the province's health sector. It applies to health information custodians and to people or organisations that receive that information from them, so a clinic's email, charting, and vendor workflows all matter.
If you manage a clinic, you've probably had the same moment many office leads have. A front-desk coordinator is about to email a referral or lab result and pauses, because the patient's information is already sitting in the inbox. At that point, the question is not whether privacy matters, it's which rules apply and what you need to do next.
What Is PHIPA and Why It Exists
A small clinic owner in Ontario usually meets PHIPA through a routine task, not a policy memo. Someone wants to send a lab requisition, a specialist note, or a follow-up message, and the team needs a clear answer before hitting send. That's where PHIPA, the Personal Health Information Protection Act, 2004, comes in, because it gives Ontario's health sector a dedicated set of privacy rules for personal health information.
PHIPA received royal assent on May 20, 2004 and came into force on November 1, 2004. The Information and Privacy Commissioner of Ontario describes five stated purposes for the Act, to set rules for collection, use, and disclosure of personal health information, to give individuals access rights, to give correction rights, to provide independent complaint review, and to provide effective remedies for breaches. Those purposes explain why PHIPA is more than a policy checklist, it's the operating rulebook for how Ontario health organisations handle identifiable patient data. The IPC's PHIPA FAQ

What PHIPA covers in plain language
PHIPA is not a general privacy law. It is a sector-specific regime that focuses on health information, which is why it matters so much inside clinics, hospitals, labs, and related services. The law governs how personal health information moves through day-to-day work, including who can collect it, when they can use it, and when they can share it.
Practical rule: if the information identifies a patient and relates to care, PHIPA is usually part of the conversation.
That matters because health data doesn't stay in filing cabinets anymore. It lives in inboxes, EHRs, cloud systems, and shared work queues, which means the privacy question often shows up in ordinary admin work rather than in a formal compliance review. If you're trying to understand the broader Canadian privacy picture, we've also covered the main federal and provincial rules in our guide to Canadian data privacy laws.
Why the law still matters in daily operations
In 2026, PHIPA is still relevant because most clinics run on digital workflows. A message with a referral attachment can be forwarded, archived, searched, or synced across devices, so the privacy risk is tied to how the tool is used, not just to the content itself.
That's why managers need to think beyond paper charting. Email handling, device access, and record storage all affect whether a clinic is following the law. If the team treats PHIPA as a one-time training topic, they usually miss the practical issues that happen in the inbox, in shared mailboxes, and in third-party systems.
Who Must Comply With PHIPA
PHIPA reaches the people and organisations that hold or process patient information, not every business that happens to touch health data. The key term is health information custodian, which covers the people and organisations that have custody or control of personal health information. In practice, that includes physicians, hospitals, laboratories, pharmacies, long-term care homes, and community health centres.

Custodians and the people who work for them
A custodian can act through staff and service providers. That means your reception team, billing staff, nurses, and office manager are all part of the compliance picture when they handle patient information. It also means a vendor can be pulled into PHIPA obligations when it receives personal health information from a custodian and processes it on the custodian's behalf.
That is where clinics often get confused. A transcription service that turns dictation into chart notes, a managed IT provider with system access, or a cloud backup service that stores records can all sit inside the PHIPA workflow. The law doesn't care whether the task feels “technical” or “administrative”, it cares whether identifiable health information is being handled for a custodian.
If a supplier can read, store, forward, or restore patient data for your clinic, you need to treat that relationship as part of your privacy program.
Who falls outside PHIPA and why that matters
PHIPA does not automatically cover every organisation that handles health-related information. Some situations fall outside the Ontario health-sector framework and are handled under other laws, including PIPEDA where applicable. That distinction matters because a vendor can advertise privacy controls without being ready for the specific obligations a clinic faces under PHIPA.
For example, a commercial software product may be strong on general security but still need a PHIPA-aware contract, access model, and data-handling process before a clinic uses it. The question is not just whether the tool is secure, it's whether the organisation using it has legal control over how patient information moves through that tool. For a wider commercial-privacy refresher, see our PIPEDA compliance guide.
The operational takeaway for clinic managers
If your clinic sends patient information to outside providers, you need to know who is acting as a custodian, who is acting as an agent, and who is a separate business. That distinction drives your contracts, your access controls, and your incident response steps. It also tells you who has to answer when a message goes to the wrong inbox.
PHIPA vs PIPEDA and What Each Law Covers
People search for PHIPA vs PIPEDA because the line between them can feel blurry from the outside. The simplest way to think about it is this. PHIPA is the Ontario health-sector rule set, while PIPEDA is the federal commercial privacy law that can cover organisations outside PHIPA's sector-specific reach. Within Ontario health care, PHIPA is usually the law that drives the day-to-day handling of personal health information.
| Criterion | PHIPA | PIPEDA |
|---|---|---|
| Scope | Ontario's health sector | General commercial activities |
| Main focus | Personal health information | Personal information in commercial contexts |
| Who it covers | Health information custodians and those receiving their information | Private-sector organisations where the law applies |
| Consent and use | Built around health-sector rules for collection, use, disclosure, access, and correction | Built around commercial privacy obligations |
| Oversight | Information and Privacy Commissioner of Ontario | Federal privacy framework and regulator |
Why the distinction matters for email providers
A hosted email provider can say it supports privacy, but that alone doesn't make it PHIPA-ready for a clinic. A provider may be good for ordinary business email and still need extra terms, controls, and operational alignment before it can safely support patient communications. That's because PHIPA looks at how health information is handled in context, not just whether a vendor says it protects data.
The key issue is the workflow. If a clinic uses a provider to send referral letters, receive patient replies, or archive messages with diagnoses and identifiers, the provider becomes part of the compliance chain. A general privacy promise is helpful, but it doesn't replace the clinic's duty to make sure the whole process fits PHIPA.
When both laws can matter
In some situations, more than one privacy framework can touch the same organisation. A clinic may sit inside PHIPA for patient records, while a separate business function follows a different privacy law for employee or commercial information. That's normal, and it's why teams need to map information by use case instead of assuming one policy covers everything.
The Ontario rule generally controls the health-information side when PHIPA applies. That's the practical answer most clinic managers need, because it stops a vendor from being treated as “compliant enough” just because it handles other kinds of private data well. If you want a broader federal comparison, the federal side is covered in our earlier PIPEDA guide, which helps explain where commercial obligations start and stop.
PHIPA Rules for Email and Electronic Health Records
PHIPA shows up most clearly when a clinic sends or stores information electronically. A referral in Gmail, a lab result in a shared mailbox, or a chart summary in an EHR all raise the same basic question, who can see the information, and under what authority? The answer depends on consent, purpose, access controls, and the way the record is stored after it's sent.

Consent and disclosure in day-to-day workflows
PHIPA is built around controlled collection, use, and disclosure. In a clinic setting, that means staff should only send patient information for a valid care purpose, and they should be sure the recipient is the right one. If a patient has agreed to email communication, that helps, but it doesn't remove the need to send information carefully and only to the intended person.
A common confusion is the difference between implied and express consent. In plain terms, implied consent can fit ordinary care workflows when the information is used for treatment purposes and the patient would reasonably expect that use. Express consent is more explicit, and it becomes more important when the communication moves beyond normal care handling or into broader disclosure. The safe approach is to treat each message as part of a specific care workflow, not as a casual administrative email.
Retention, accuracy, and records that live beyond the inbox
A deleted message is not the same thing as a non-existent record. If a message contained PHI, it may still exist in backups, archives, sent folders, forwarding rules, or EHR logs. That's why clinics need retention and disposal practices that match the sensitivity of the data, not just mailbox habits.
Ontario's interoperability regulation, O. Reg. 329/04, makes the technical side clearer. It can define requirements for content, message format, data migration or mapping, terminology or code sets, and privacy or security controls for digital health assets used by custodians. That tells us PHIPA compliance isn't only about policy language, it also reaches how systems exchange and structure data.
What secure exchange looks like in real clinic work
A receptionist sends a referral to a specialist. A nurse forwards a patient update to the physician. A billing coordinator stores a message that includes identifiers and appointment details. Each of those workflows needs the right access, the right recipient, and the right handling after delivery.
Operational rule: if the message contains patient identifiers, treat the email system like part of the medical record process, not like casual office messaging.
That is why encryption alone is not enough. It helps, but it doesn't solve recipient errors, over-broad access, or bad retention practices. PHIPA asks for a broader control set, and that's where clinic operations and IT need to work together.
Secure Email Requirements for Ontario Clinics
A reasonable safeguards approach under PHIPA starts with a simple idea, patient information should only move through systems that your clinic can control. That means looking at transmission, access, logging, vendor terms, and staff habits together, not as separate projects. If one piece is weak, the rest of the stack has to carry too much risk.

Five operational pillars that matter
Encrypted transmission is the first line of defence. If your clinic sends PHI by email, you want encryption in transit so messages are protected while they move between systems. That matters most when staff work from multiple locations or use mobile devices between appointments.
Access controls matter just as much. A shared inbox with weak passwords or broad delegation can expose messages to people who don't need them. That creates a practical problem, not just a technical one, because it becomes harder to prove who saw what after an incident.
Audit logging gives you a record of activity. When a privacy issue surfaces, logs can show when a message was opened, forwarded, or accessed, which helps your team investigate instead of guessing. The true value is accountability, not the feature itself.
Vendor and agent agreements close a gap that many clinics overlook. If an outside provider can process patient emails, your clinic needs terms that reflect PHIPA responsibilities, because privacy obligations do not disappear when the data sits on someone else's system.
Staff training keeps the policy from gathering dust. A receptionist who knows how to verify a recipient, spot an incorrect attachment, or pause before sending a patient message is doing real compliance work.
Email choices shape compliance decisions
Clinic email is also an infrastructure decision. Gmail's daily sending limits can become a workflow constraint for very busy clinics, and all-in-one suites such as Proton can add operational complexity when a team mainly needs straightforward clinic email. Those limits and trade-offs matter because compliance is easier when the tool matches the actual job.
For clinics comparing hosted email options, data residency and contract terms should be on the shortlist. We've covered the hosting side in more detail in our data residency guide for secure hosted email. If you're evaluating providers, ask a simple question, can this vendor support the way our clinic sends, stores, and reviews patient email?
Why this matters to managers, not just IT
A clinic manager does not need to become an encryption engineer. You do need to know whether staff can send messages securely, whether outside vendors can see patient content, and whether your team can prove who accessed records after a complaint. Those are operational questions, and PHIPA turns them into compliance questions fast.
Enforcement, Penalties, and Practical Next Steps
PHIPA has real enforcement power, which is why Ontario treats it as more than a policy statement. Under PHIPA, individuals can face fines of up to $200,000 and imprisonment for up to 1 year, while corporations can face penalties of up to $1 million for violations. The Information and Privacy Commissioner of Ontario is the oversight body responsible for compliance and enforcement. See the IPC's guidance on PHIPA compliance for details. Those numbers are a reminder that a broken email workflow can become a legal issue, not just an IT ticket.
The practical next steps are straightforward. Map where patient information lives across email, EHRs, shared drives, and third-party tools. Review vendor agreements, document a breach response plan, and check whether staff know how to spot a bad recipient before a message leaves the clinic. Then shortlist providers that can support secure email under a PHIPA-aware operating model.
If you're a clinic or health-adjacent team evaluating email providers, look for one that can support PHIPA-compliant workflows, offers Canadian data residency, and provides clear audit trails for patient communications. Typewire is a Vancouver-based email provider that hosts data in Canada and controls its own infrastructure rather than renting capacity from large third-party clouds. That's one foundational piece, but you'll also want to confirm the provider offers the access controls, logging, and vendor agreements that PHIPA requires. The right choice depends on your workflow, but the provider you choose should fit the way your team handles sensitive messages.
What Is PHIPA? Ontario’s Health Privacy Law and Secure Email
Posted: 2026-08-05
What Is PHIPA? Ontario’s Health Privacy Law and Secure Email
Posted: 2026-08-05
Email Sender Authentication: Boost Deliverability
Posted: 2026-08-01
Secure Email Server Login: 2026 Best Practices
Posted: 2026-07-28
Can You Trace an Email? How Email Tracing Works
Posted: 2026-07-24
Canadian Data Sovereignty: Your 2026 Business Guide
Posted: 2026-07-21
What Is Vishing? Voice-Phishing Scams Explained
Posted: 2026-07-17
What Is a Phishing Link? How to Check a Link Before You Click
Posted: 2026-07-14
What Is Quishing: Protecting Against QR Code Scams in 2026
Posted: 2026-07-10