PHIPA, the Personal Health Information Protection Act, 2004, is Ontario's provincial health privacy law. It applies directly to Ontario dental clinics: dentists are classified as "health information custodians" and carry full legal responsibility for how their clinic collects, uses, stores, and discloses patient health information. This guide covers what that means in practice, what patients can demand, and what the penalties look like after Ontario's 2024 enforcement changes.

Who PHIPA Covers: Custodians and Agents

Under PHIPA, an Ontario dentist is a health information custodian (HIC). The Royal College of Dental Surgeons of Ontario (RCDSO) states this plainly: "As custodians of personal health information, dentists are held to a very strict standard of confidentiality. Ontario's Personal Health Information Protection Act, 2004 ('PHIPA'), governs the collection, use and disclosure of personal health information by dentists and other health information custodians practising within Ontario."

Your dental staff (hygienists, assistants, and administrative coordinators) are classified as your agents rather than HICs in their own right. That distinction matters: the legal obligations sit with you as the custodian, not with each individual employee. You are responsible for ensuring that every agent handles patient information consistently with PHIPA, which means written confidentiality agreements and documented privacy training.

Every HIC must also designate a contact person responsible for ensuring compliance. Solo practitioners are both the HIC and the contact person by default. Group practices typically designate a senior staff member or the practice owner, though the legal responsibility remains with the dentist as custodian.

PHIPA applies only within Ontario. For a comparison of provincial and federal privacy obligations, see our guide to PIPEDA compliance for dental practices, which explains how the two regimes interact.

What Counts as Personal Health Information

Personal health information (PHI) under PHIPA covers any information about an individual that relates to their physical or mental health, their health care history, or the provision of health care to them. In a dental context that includes:

  • Clinical records: charting, treatment notes, radiographs, photos
  • Medical and medication history provided by the patient
  • Appointment history and referral letters
  • Billing and insurance records linked to health care services
  • Any identifier that, in combination with other information, could reveal health status

Contact information (name, phone number, email address) becomes PHI when it appears in a clinical record. A patient's name alone on a general mailing list is not PHI; that same name on a recall reminder referencing their last dental visit is. This distinction affects how you handle appointment reminders and patient communication.

For guidance on the consent rules that govern automated appointment reminders, see our article on CASL compliance for dental SMS reminders. CASL and PHIPA operate independently; you need to satisfy both.

PHIPA allows consent to be either express or implied. For most treatment purposes, consent is implied through the concept of the "circle of care": when a patient presents for dental treatment, they implicitly consent to the collection, use, and disclosure of their PHI among the health professionals directly involved in providing that care.

Express consent is required outside the circle of care. Common situations that require explicit patient consent in a dental practice include:

  • Sharing records with a patient's employer or insurance company for non-treatment purposes
  • Using clinical photographs in marketing or educational materials
  • Disclosing PHI to a family member who is not directly involved in the patient's care
  • Sending PHI to a specialist clinic or referral partner outside the immediate treatment context

PHIPA's minimum necessary principle applies in all cases: collect, use, and disclose only the PHI that is reasonably necessary for the purpose identified. Blanket access to complete patient records is rarely justified when a narrower disclosure would serve the same purpose.

Patients may also withdraw consent at any time. A patient who withdraws consent for automated appointment reminders should be flagged in your practice management system immediately, and any scheduled messages should be cancelled before they send.

Security Safeguards Required by PHIPA

PHIPA section 12(1) requires HICs to implement security safeguards that are "reasonable in the circumstances." The Information and Privacy Commissioner of Ontario (IPC) groups these into three categories:

📋
Administrative
  • Written privacy policy
  • Designated contact person
  • Agent confidentiality agreements
  • Annual privacy training
  • Breach response procedures
🔒
Technical
  • Encrypted data storage
  • Role-based access controls
  • Audit logs on PHI access
  • Secure patient portal or messaging
  • Software update and patch management
🏢
Physical
  • Locked filing cabinets or server rooms
  • Clean desk policy at reception
  • Screen positioning to prevent sightlines
  • Visitor access controls
  • Secure disposal of paper records

Importantly, your obligations extend to any third-party vendors who handle PHI on your behalf. The IPC has confirmed that custodians remain responsible for safeguarding PHI "even when using third-party providers." Written data processing agreements with any vendor who accesses patient data are not optional.

Your agents must sign confidentiality agreements before accessing any PHI. Privacy training at the start of employment and at least annually thereafter is the IPC's documented expectation. These records should be retained to demonstrate compliance if the IPC ever investigates your practice.

Patient Rights You Must Honour

PHIPA gives patients a defined set of rights over their own PHI. Your clinic has legally binding obligations when a patient exercises any of these rights.

Patient Rights Under PHIPA
Access to records
Respond within 30 calendar days (extensible to 60 days with notice and reason)
Request correction
Respond within 30 to 60 days; no obligation to correct professional opinions
Statement of disagreement
Patient may attach a statement to their record if you decline to correct it
Withdraw consent
At any time; withdrawal is prospective only, not retroactive
Complaint to the IPC
Patients may file a complaint with the Information and Privacy Commissioner of Ontario
Breach notification
Must be notified 'at first reasonable opportunity' when their PHI is improperly disclosed

The 30-day access deadline is measured in calendar days from the date of receipt of the written request. If you cannot comply within 30 days, you must notify the patient in writing of the extension (up to 60 days total) and the reasons. Failing to respond within the required timeframe is itself a PHIPA violation, regardless of whether the underlying records are properly maintained.

Privacy Breach Response: The Four-Step Protocol

The IPC's breach response protocol for health custodians outlines four steps. Ontario dental clinics should document each step in writing whenever a suspected or confirmed breach occurs.

01
Contain
Stop the breach from continuing. Restrict access, retrieve disclosed records where possible.
02
Notify Patients
Inform affected patients at the first reasonable opportunity. Include their right to complain to the IPC.
03
Investigate
Determine scope, root cause, and which records were affected. Document findings.
04
Remediate
Implement safeguards to prevent recurrence. Update policies, training, and systems.

Notification to affected patients is mandatory and must include a statement that they may file a complaint with the IPC. There is no fixed number of days in PHIPA for patient notification; the statute requires "first reasonable opportunity," which regulators and courts interpret as acting as quickly as your investigation allows.

In certain circumstances, you must also notify the IPC directly. These include incidents involving intentional insider access (staff snooping on records without clinical purpose), stolen PHI, subsequent unauthorised use or disclosure, and situations constituting a pattern of incidents. Maintaining an incident log is advisable even for near-misses, as it demonstrates that your clinic takes privacy seriously if the IPC ever investigates.

Effective patient communication is the first line of breach prevention. Practices with structured systems for tracking patient contact preferences and consent status reduce the risk of accidental disclosure significantly. For practical strategies, our article on reducing dental no-shows discusses how organised patient communication workflows support better operational control.

Penalties for PHIPA Violations

Ontario significantly strengthened PHIPA's enforcement regime. Administrative monetary penalties (AMPs) came into force on 1 January 2024, giving the IPC the power to impose financial penalties without initiating a criminal prosecution. The first AMP under these provisions was issued in 2025.

$50,000
Max AMP (individual)
Administrative penalty
$500,000
Max AMP (organization)
Administrative penalty
$200,000
Max criminal (individual)
PHIPA s.72 offence
$1,000,000
Max criminal (corp.)
PHIPA s.72 offence

The IPC's AMP framework sets individual penalties at up to $50,000 and organisation penalties at up to $500,000. These apply alongside, not instead of, the longer-standing criminal offence provisions. Under PHIPA section 72 (as doubled by 2020 amendments), individuals convicted of a criminal PHIPA offence face fines of up to $200,000 and/or one year of imprisonment; corporations face fines of up to $1,000,000.

The distinction between an AMP and a criminal referral matters practically. The IPC may impose an AMP after an investigation without involving the police or the courts. Criminal charges under section 72 require a prosecution, but carry the additional consequence of a criminal record for the individual involved.

Beyond financial penalties, a PHIPA violation finding can trigger RCDSO professional conduct proceedings, which may affect a dentist's ability to practise. Documenting your compliance efforts is therefore important not only to avoid penalties but to demonstrate good faith if an incident occurs.

PHIPA and PIPEDA: Which Applies to Your Clinic?

Federal law (PIPEDA) and provincial law (PHIPA) appear to overlap for Ontario dental clinics, but the relationship is straightforward in practice. PHIPA has been granted "substantially similar" status under PIPEDA, meaning Ontario dental clinics conducting health care activities within Ontario are subject to PHIPA, not PIPEDA, for those activities. The IPC Ontario, not the federal Office of the Privacy Commissioner, governs their health information handling.

PIPEDA still applies in two circumstances relevant to dental clinics:

  • Inter-provincial activities: Disclosing PHI to a provider or insurer located outside Ontario triggers PIPEDA obligations alongside PHIPA.
  • Commercial activities: Processing patient contact information for marketing purposes (such as email campaigns not related to clinical care) falls under PIPEDA even within Ontario.

For most Ontario dental clinics, PHIPA is the operative statute for day-to-day operations. Our broader guide to PIPEDA compliance for dental practices covers the federal framework and where the two regimes overlap for clinics with patients or partners in multiple provinces.

A Practical PHIPA Compliance Checklist for Dental Clinics

The following steps represent the minimum baseline for a compliant Ontario dental practice. Clinics should review this list at least annually and whenever staff, systems, or procedures change.

1
Designate a contact person responsible for PHIPA compliance
2
Obtain signed confidentiality agreements from all agents before PHI access
3
Deliver documented privacy training at onboarding and at least annually
4
Maintain a written privacy policy aligned with PHIPA requirements
5
Implement technical safeguards: encrypted storage, access controls, audit logs
6
Sign data processing agreements with any third-party vendor handling PHI
7
Establish a written breach response procedure (contain, notify, investigate, remediate)
8
Document access requests and your responses, including the dates
9
Review and update your patient consent forms and recall communication practices annually
10
Log all near-miss incidents as well as confirmed breaches

Practices that automate patient recall and appointment reminders should pay particular attention to how contact information is used and stored. The systems you use for recall management affect your PHIPA obligations directly. For an overview of what to look for in recall software from a compliance perspective, see our guide to the best dental recall software for Canadian clinics.

Frequently Asked Questions

Does PHIPA apply to dental clinics in Ontario?

Yes. Ontario dentists are classified as health information custodians under PHIPA, which means the full obligations of the Act apply to how they collect, use, store, and disclose patient health information. All dental staff who handle PHI on behalf of the dentist are considered agents and are subject to the policies and safeguards the dentist is required to implement.

What is a health information custodian under PHIPA?

A health information custodian is a person or organisation that has custody or control of personal health information and falls within a listed category under PHIPA. Ontario dentists are expressly included. HICs are directly responsible for PHIPA compliance; their staff (agents) share that responsibility only to the extent that the HIC defines and enforces appropriate policies.

How long does a dental clinic have to respond to a patient records request?

Thirty calendar days from the date you receive a written access request. You may extend this to a maximum of 60 days, but you must notify the patient in writing within the initial 30-day period that an extension is needed and state the reason. Failing to respond within the required timeframe is itself a PHIPA violation.

What are the penalties for PHIPA violations?

Since 1 January 2024, the IPC may impose administrative monetary penalties of up to $50,000 against individuals and up to $500,000 against organisations. PHIPA section 72 also provides for criminal offences: individuals face fines of up to $200,000 and/or one year of imprisonment; corporations face fines of up to $1,000,000. The first AMP under the new framework was issued in 2025.

Does PHIPA or PIPEDA apply to Ontario dentists?

PHIPA applies to most Ontario dental clinic activities. PHIPA has been granted "substantially similar" status under PIPEDA, exempting Ontario dental clinics from PIPEDA for their health care activities within Ontario. The federal Office of the Privacy Commissioner defers to the IPC Ontario for these matters. PIPEDA continues to apply to inter-provincial disclosures and commercial marketing activities.

What counts as a privacy breach under PHIPA?

A privacy breach under PHIPA is any unauthorised collection, use, or disclosure of personal health information. Examples in dental practice include: a staff member accessing records for a patient they are not treating, sending records to the wrong recipient, losing an unencrypted device containing patient data, or disclosing PHI to a third party without valid consent. A suspected breach must trigger your written breach response procedure even if you cannot initially confirm whether actual harm occurred.

Built for PHIPA-Compliant Canadian Clinics

DentRecall is an AI-powered dental recall and patient engagement platform built specifically for Canadian clinics. It automates SMS and email reminders and recall management from $99/month (billed annually), with online booking available on the Complete plan. See how DentRecall works →