Canada
PHIPA Explained: Ontario's Health Privacy Law, Your Rights, and the Penalties

Ontario's Personal Health Information Protection Act, 2004 (PHIPA) governs how health information custodians such as doctors, hospitals, pharmacies, and laboratories collect, use, and disclose personal health information, and it gives every patient a 30-day right to access and correct their own records.
Information last verified on 2026-08-15. This article has not yet been reviewed by a licensed lawyer.
What PHIPA Is
The Personal Health Information Protection Act, 2004 (PHIPA), Statutes of Ontario 2004, chapter 3, Schedule A, is Ontario's dedicated health-sector privacy statute. It came into force in November 2004 and sets the rules for how personal health information can be collected, used, and disclosed by the organizations and individuals who provide health care in the province.
PHIPA is narrower and more specific than Canada's general private-sector privacy law, PIPEDA. Where PIPEDA applies to commercial activity generally, PHIPA applies to a defined category of health information custodians handling a defined category of personal health information, regardless of whether that custodian is a commercial business. A public hospital or a long-term care home is not typically engaged in commercial activity in PIPEDA's sense, which is part of why Ontario built a separate statute for the health sector. See our companion guide to PIPEDA explained for the general federal framework this page does not repeat.
Who PHIPA Covers: Custodians, Agents, and Personal Health Information
Health information custodians
Section 3 of PHIPA lists who counts as a health information custodian, often shortened to HIC. The list includes:
- Health care practitioners and group practices of health care practitioners
- Home and community care service providers
- Operators of hospitals, private hospitals, psychiatric facilities, long-term care homes, retirement homes, pharmacies, laboratories and specimen collection centres, ambulance services, and community or mental health centres whose primary purpose is providing health care
- Evaluators under the Health Care Consent Act and assessors under the Substitute Decisions Act
- A medical officer of health of a board of health
- The Minister of Health, and any other person or class prescribed by regulation
Traditional Indigenous healers, traditional Indigenous midwives, and faith or prayer healers are explicitly excluded from being a custodian under section 3(4). A person who works for a custodian, such as a receptionist or a records clerk, is generally an agent of the custodian rather than a custodian in their own right.
Personal health information
Section 4 defines personal health information broadly. It covers identifying information about an individual that relates to their physical or mental health, including family health history, relates to providing them health care, relates to payment or eligibility for health coverage, involves body-part or bodily-substance donation, is the individual's health number, or identifies their substitute decision-maker. If a record mixes personal health information with other identifying information, section 4(3) treats the whole record as personal health information.
Consent: Express, Implied, and the Circle of Care
PHIPA requires consent for most collection, use, and disclosure of personal health information, and section 18 sets the ground rules: consent must come from the individual, be knowledgeable, relate to the specific information, and not be obtained through deception or coercion. Consent can be express or implied, except that disclosure to someone who is not a health information custodian, or disclosure between custodians for a purpose other than providing health care, must be express.

Section 20(2) is the provision behind what practitioners commonly call the circle of care. It lets a custodian in specific categories, health care practitioners, home and community care providers, and the facilities listed above, assume implied consent to collect, use, or disclose personal health information they received from the individual, their substitute decision-maker, or another custodian, for the purpose of providing or assisting in providing health care, unless the custodian is aware the individual has expressly withheld or withdrawn consent. The Information and Privacy Commissioner of Ontario's own guidance is direct on the terminology: circle of care is not a defined term in PHIPA. It is sector shorthand for this section 20(2) mechanism, and it comes with real limits. It does not extend to information received from an employer, an insurer, or an educational institution, and it never authorizes disclosure to someone who is not a custodian.
The lockbox a patient can ask for works the same way, as informal shorthand rather than statutory language. The IPC's own fact sheet on the subject states directly that lock-box is not a defined term in PHIPA either. It rests on two statutory hooks: the unless-aware-of-an-express-withdrawal clause in section 20(2) itself, and separate express-instruction provisions in sections 37, 38, and 50 that let a patient block specific uses or disclosures the Act would otherwise permit for health care purposes, whether that is a single diagnosis, an entire record, or disclosure to a named provider. A lockbox does not override a custodian's ability to disclose without consent where there is a significant risk of serious bodily harm.
Your Right to Access Your Records
Section 52 gives every individual a right of access to their own personal health information in a custodian's custody or control, subject to a defined list of exceptions such as legal privilege, an ongoing legal proceeding, or a genuine risk of serious harm from disclosure. A request must be made in writing under section 53, and the custodian has to help reformulate a request that is not specific enough to act on.
From there, section 54 sets the clock. The custodian must respond, by granting access, confirming no record exists, or refusing with reasons, within 30 days of receiving the request. One extension of up to 30 more days is available, but only where the volume of information or the need for outside consultation makes the original deadline genuinely impractical, and the custodian must give written notice of the extension and its reason. If the custodian simply does not respond within the deadline, that silence counts as a deemed refusal. On any refusal, the individual can complain to the Information and Privacy Commissioner, and the burden of proving the refusal was justified sits with the custodian, not the patient.
Custodians may charge a fee, but only after providing a fee estimate, and the fee cannot exceed a prescribed amount, or the amount of reasonable cost recovery if nothing is prescribed. This is the page's key nuance: no regulation has ever actually prescribed that amount. The commonly quoted figure, a $30 flat fee covering the first 20 pages plus $0.25 for each additional page, traces back to a fee schedule the Ontario government proposed in a draft regulation in 2006 and then never adopted. IPC adjudicators picked it up anyway, starting with Order HO-009 in 2010, as their working benchmark for what reasonable cost recovery means, and they were still applying that same unenacted framework as recently as a July 2024 decision, which states plainly, "there is no regulation that prescribes fees for access." Treat the $30 figure as consistent adjudicative practice, not as a codified fee schedule, and be aware a custodian can be ordered to charge less if it skipped required steps like providing an estimate.
Correcting Your Record
Section 55 gives an individual who has been granted access the right to ask, in writing, for a correction if they believe the record is inaccurate or incomplete for the purposes the custodian uses it. The same 30-day clock and single 30-day extension apply, and a non-response is again a deemed refusal.
If the individual demonstrates the record is inaccurate or incomplete and provides what is needed to fix it, the custodian has a duty to correct it under section 55(8). There are two exceptions: a custodian that did not create the record and lacks the knowledge or authority to correct it, and a professional opinion or observation the custodian made in good faith, which cannot be forced to change even on request. A correction never simply erases the original entry. The custodian strikes out or labels the incorrect information while preserving what was originally recorded, and notifies the individual and, on request, anyone who previously received the incorrect version.
Where a correction is refused, PHIPA gives the individual a statement-of-disagreement right instead. They can prepare a statement explaining the dispute, require the custodian to attach it to the record, require it be disclosed alongside the information going forward, and ask that prior recipients be notified. It is the Act's functional substitute for a forced correction when the custodian will not budge, most commonly over a disputed clinical opinion.
Complaining to the IPC
Anyone with reasonable grounds to believe a custodian has contravened or is about to contravene PHIPA can complain to the Information and Privacy Commissioner under section 56, not only the individual whose information is involved. The general limitation period is one year from when the matter came, or reasonably should have come, to the complainant's attention, though the Commissioner can allow more time if it causes no prejudice. Complaints specifically about an access or correction refusal have a shorter, six-month limitation period.
The Commissioner can attempt settlement or mediation first, and if that fails or is not used, decides whether to open a formal review. Reviews come with real investigative powers, including warrantless inspection of custodian premises under conditions, document-production demands, and summons power compelling testimony. A completed review can lead to an order requiring specific action, and orders under most of the Commissioner's order powers can be appealed to the Divisional Court on a question of law within 30 days.
Breach Notification Duties
PHIPA's breach duties run on two separate tracks. Under section 12, a custodian must notify the affected individual at the first reasonable opportunity after any theft, loss, or unauthorized use or disclosure of their personal health information. The Act sets no minimum-harm threshold for this notice. It applies regardless of how serious the incident was.

Notice to the Commissioner is narrower. Ontario Regulation 329/04 sets out seven prescribed circumstances that trigger a mandatory report to the IPC, including reasonable grounds to believe information was stolen, reasonable grounds to believe it will be further misused, the incident being part of a pattern of similar incidents, and the custodian's own determination that the incident is significant after weighing the sensitivity of the information, the volume involved, and how many people were affected.
Separately from any individual incident, every custodian must file an annual report to the Commissioner, on or before March 1 each year, stating the total number of times in the prior calendar year that personal health information in its custody was stolen, lost, or used or disclosed without authority. This numbers-only annual roll-up is required whether or not any single incident during the year met the seven-circumstance threshold for individual reporting.
Penalties: Two Separate Tracks
PHIPA enforces compliance through two distinct mechanisms that are easy to conflate.
The older track is a criminal-style offence under section 72, covering acts such as wilful unauthorized collection, use, or disclosure of personal health information, and wilfully obstructing the Commissioner. A March 2020 amendment quadrupled these fines, not merely doubled them as is sometimes reported: from $50,000 to $200,000 for a natural person and from $250,000 to $1,000,000 for an organization, with up to a year of imprisonment also possible for an individual. Prosecution under this track requires the Attorney General's consent before it can even begin, a real practical brake on how often it is used.
The newer track is a civil administrative monetary penalty, added by a 2023 regulation, Ontario Regulation 343/23, amending the general PHIPA regulation. The Commissioner can order an administrative penalty of up to $50,000 for an individual or $500,000 for an organization, without needing a criminal conviction, and can increase that cap by the amount of any economic benefit the contravener gained. In deciding the amount, the Commissioner weighs factors including how far the conduct deviated from the Act, whether the person could have prevented it, the extent of the harm, and whether the person self-reported. Because this penalty is meant to encourage compliance rather than punish a crime, it is a faster and more commonly usable tool than the offence-fine track above it.
The Employer Misconception
A frequent misunderstanding is that PHIPA governs an employer's file on its own staff, including sick notes and other health-related documentation kept for HR purposes. It generally does not. Section 4(4) excludes identifying information that relates primarily to a custodian's own employees or agents and is maintained primarily for a purpose other than providing them health care. An ordinary personnel file, an attendance record, or a doctor's note kept purely to support a leave request sits outside PHIPA's definition of personal health information for exactly that reason.
That data does not go unregulated. It generally falls under PIPEDA, for a federally regulated employer, or the applicable provincial employment-standards and privacy framework instead, though no single regulator statement makes this point in one place; it follows from reading PHIPA's own scope provision alongside those other frameworks. The exception is an employer that separately operates something like a workplace health clinic staffed by a health care practitioner. In that narrow capacity, the employer could itself become a health information custodian for the clinic's own records. For general workplace medical-note practices, see our guide to sick leave and medical notes in Canada.
PHIPA vs PIPEDA: Where the Boundary Sits
PHIPA and PIPEDA operate side by side rather than one replacing the other. The practical dividing line is whether the organization holding the information is a health information custodian under PHIPA's section 3 list. If it is, and the information is personal health information under section 4, PHIPA governs, regardless of whether the custodian is a commercial or a public entity. If the organization is not a custodian, a life or health insurer or a consumer wellness app, for instance, but is otherwise handling personal information in the course of commercial activity, PIPEDA, or a province's substantially similar law, applies instead.

PHIPA also differs from PIPEDA in ways that matter to a patient directly. PIPEDA has no fee provision at all, so federal access requests are free, while PHIPA allows a cost-recovery fee under the framework described above. PHIPA's correction rights include the formal statement-of-disagreement mechanism described above, which PIPEDA does not have in the same form. For the general federal framework, express and implied consent outside the health sector, and how PIPEDA's own enforcement and substantially-similar provincial carve-outs work, see our full guide to PIPEDA explained.
Related Resources
For the province-by-province picture of how to actually request your medical records, including the outlier structures in British Columbia and Quebec, see accessing medical records across Canada. For federal privacy law generally, see PIPEDA explained and the Privacy Act in Canada. For Alberta and British Columbia's general private-sector privacy statutes, see Alberta and BC's PIPA laws, and for Quebec's private-sector regime, see Quebec's Law 25 explained.
Disclaimer
This article is informational only and is not legal advice. It reflects PHIPA's text as captured in a January 2024 archival snapshot of the Act, cross-checked against regulation and IPC-decision sources current through April 2025 and July 2024 respectively. Readers with a live dispute should confirm current wording directly with the Information and Privacy Commissioner of Ontario or a licensed lawyer. Two items in this article are adjudicative practice rather than codified law and should be treated accordingly: the $30-plus-$0.25-per-page fee framework, which traces to a 2006 proposed regulation that was never adopted, and the circle-of-care and lockbox terminology, which is IPC and sector shorthand rather than language PHIPA itself defines. Health-records disputes warrant contacting Ontario's Information and Privacy Commissioner or a lawyer directly.
Frequently Asked Questions
What does PHIPA stand for?
PHIPA stands for the Personal Health Information Protection Act, 2004, Ontario's dedicated statute governing how health information custodians collect, use, and disclose personal health information.
Who has to follow PHIPA?
Only organizations and individuals who qualify as health information custodians under section 3, such as doctors, hospitals, long-term care homes, pharmacies, laboratories, and ambulance services. A business that simply collects some health-related data without being a custodian is generally governed by PIPEDA instead, not PHIPA.
What is the circle of care under PHIPA?
Circle of care is not a term PHIPA itself uses. It is the Information and Privacy Commissioner's own shorthand for the implied-consent mechanism in section 20(2), which lets certain custodians assume a patient's consent to share information for the purpose of providing health care, unless the patient has expressly said otherwise.
What is a PHIPA lockbox?
A lockbox is the informal name for a patient's right, under sections 20(2), 37, 38, and 50, to instruct a custodian to withhold specific information from being shared for health care purposes, even where implied consent would otherwise allow it. Like circle of care, lockbox is not a defined term in the Act itself.
How long does a custodian have to respond to a records request?
30 days from receiving a written request, with one possible extension of up to 30 more days for a documented reason. If the custodian does not respond in time, that silence is treated as a refusal, and the custodian bears the burden of showing any refusal was justified.
How much can a custodian charge for a copy of my records?
PHIPA allows a cost-recovery fee after providing an estimate, but no regulation has ever set the amount. IPC decisions have consistently treated a $30 flat fee covering the first 20 pages, plus $0.25 per additional page, as reasonable cost recovery since 2010, most recently confirmed in a 2024 decision, but this is adjudicative practice rather than a codified fee schedule.
What are the penalties for violating PHIPA?
Two separate tracks. An offence conviction under section 72 can bring a fine up to $200,000 for an individual or $1,000,000 for an organization, quadrupled by a 2020 amendment, though prosecution needs the Attorney General's consent. A separate administrative monetary penalty, added by a 2023 regulation, caps at $50,000 for an individual or $500,000 for an organization and does not require a conviction.
Does PHIPA apply to my employer's file on me?
Generally no. Section 4(4) excludes identifying information kept primarily about a custodian's own employees for a purpose other than providing them health care, so an ordinary personnel file or an HR-held doctor's note typically falls outside PHIPA and is governed by PIPEDA or provincial employment law instead.
How is PHIPA different from PIPEDA?
PHIPA is a health-sector-specific law that applies to defined custodians and personal health information regardless of whether the custodian is a commercial entity. PIPEDA is a general private-sector law that applies based on commercial activity. The two operate alongside each other rather than one replacing the other.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Personal Health Information Protection Act, 2004, SO 2004, c.3, Sched. A (archived full text, capture 2024-01-12)(web.archive.org).gov
- IPC of Ontario - Circle of Care: Sharing Personal Health Information for Health-Care Purposes(ipc.on.ca).gov
- IPC of Ontario - Lock-box Fact Sheet (Fact Sheet #8)(ipc.on.ca).gov
- IPC Order HO-009 (2010) - origin of the fee-estimate framework(decisions.ipc.on.ca).gov
- PHIPA Decision 257 (IPC, 2024-07-15) - fee framework confirmed still current(decisions.ipc.on.ca).gov
- Ontario Regulation 329/04, General (live consolidated text) - administrative penalties and breach notification(ontario.ca).gov