If You Run a Health Clinic in Ontario, PHIPA Applies to You

Most small health clinic owners in Ontario don’t think much about privacy legislation. They’re focused on running their practice, seeing patients, and keeping things moving. Compliance feels like something that applies to hospitals and large healthcare organizations – not a physio clinic or an orthotics practice with a handful of staff.

But if your clinic collects patient names, health history, treatment records, or assessment data, Ontario’s Personal Health Information Protection Act applies to you. You’re considered a health information custodian under the Act, whether you knew it or not.

What PHIPA actually expects from your IT

PHIPA doesn’t require anything exotic. It requires reasonable safeguards – which sounds vague until you look at what that actually means in practice.

It means computers should be password-protected and set to lock automatically when not in use. Patient data should be stored on encrypted devices, not on an open laptop at the front desk that anyone can access. Backups should be happening regularly and stored securely. And access to patient information should be limited to the people who actually need it.

Most small clinics aren’t there yet. Not because anyone is being careless – just because nobody ever flagged it as something that needed attention.

The Gmail problem

This one comes up more often than you’d expect. A clinic using a free Gmail account to send appointment reminders or communicate with patients is a PHIPA issue. That patient data is being processed on servers outside Canada, with no data residency guarantees and no proper agreement between the clinic and Google about how that information is handled.

It works. It’s convenient. But it’s not compliant – and most clinic owners have no idea there’s a problem.

Old devices are a risk too

That old laptop sitting in a back room waiting to be donated or thrown out – if it ever had patient data on it, deleting the files isn’t enough. Under PHIPA, personal health information has to be securely destroyed before any device leaves your hands. A factory reset doesn’t cut it either.

This is one of those things that feels minor until a device ends up in the wrong hands and a breach notification has to go out.

What a breach actually triggers

If patient data is compromised – a lost laptop, a hacked email account, a file sent to the wrong person – PHIPA requires mandatory notification. The affected patient has to be informed, and the Ontario Information and Privacy Commissioner has to be notified.

That’s not a theoretical risk. It happens to small practices, and the fix after the fact is always harder and more expensive than getting things set up properly in the first place.

The good news

Most of this is just good IT done right from the start. Proper email setup, encrypted devices, screen locks, access controls, secure disposal of old hardware – none of it is complicated or expensive. The compliance angle just means doing it intentionally rather than hoping for the best.

If you run a health clinic and you’re not sure where your IT stands, it’s worth finding out. Not because someone is going to audit you tomorrow, but because the gap between “it works” and “it’s set up right” is usually not that big to close.


IMM Computer Services helps Ottawa small businesses get their IT set up properly – secure, practical, and built for how your business actually works. Schedule a free consultation to find out where things stand.