A five-chair dental practice in Oakville does not think of itself as a hospital. It has a receptionist, two hygienists, a practice management system, and a Microsoft 365 tenant for email and scheduling. Under Ontario law, though, that practice is a health information custodian, the same legal category as a hospital or a diagnostic imaging clinic, and it carries most of the same obligations. A lot of small dental and medical offices in the GTA do not realize that until something goes wrong.
Size Does Not Exempt You
The Personal Health Information Protection Act (PHIPA) governs how health information custodians in Ontario collect, use, disclose, and safeguard personal health information. The definition of custodian covers regulated health professionals providing care, which includes dentists, physicians, and the clinics and small practices they run. There is no employee-count threshold that exempts a solo practitioner or a four-person dental office. A single dentist with one associate and a shared front desk carries the same statutory duty to protect patient charts as a large hospital network, just at a scale that matches the practice.
That duty comes with teeth that most owners underestimate. PHIPA requires custodians to take reasonable steps to protect personal health information against theft, loss, and unauthorized use or disclosure, and it requires notifying affected patients when a breach occurs. It also requires an annual report to the Information and Privacy Commissioner of Ontario, due by March 1, summarizing the privacy breaches the practice experienced the previous year. Many small clinics have never filed that report because nobody told them it exists, not because they had nothing to report.
Encryption Alone Counts as a Breach
The part that catches practices off guard is what actually triggers the notification duty. A ransomware attack that encrypts a practice management database, without any confirmed evidence that the attacker copied or viewed a single record, still counts. The Information and Privacy Commissioner of Ontario has been explicit that encrypting personal health information is itself an unauthorized use and loss of that information under PHIPA, which means the clock on notifying patients starts the moment the ransomware note appears on screen, not whenever a forensic investigation eventually confirms what the attacker actually did with the data.
That standard matters because most small practices assume ransomware is primarily an operational headache, a few days of paper charting while a technician rebuilds servers. Under Ontario law it is also, immediately, a privacy event with a legal notification duty attached, regardless of whether the attacker ever opened a single chart.
A Small Clinic Does Not Have to Be the Target
The scale of what this looks like when it goes wrong in the real Ontario health sector is worth sitting with, because the pattern that hits large institutions is the same pattern that reaches small practices through their vendors. In October 2023, a ransomware attack on TransForm Shared Service Organization, the shared IT provider for five southwestern Ontario hospitals, compromised the personal health information of more than 516,000 patients and employees. It cost those organizations upward of $7.5 million, delayed cancer radiation treatments, and left some systems down until February of the following year. The breach did not stop at the hospitals either. Tilbury District Family Health Team, a small community clinic that shared the same IT vendor, was swept into the same disclosure. A dental or medical office that outsources its practice management hosting or IT to a third party inherits that vendor's security posture whether it chose to or not, which is exactly why PHIPA requires custodians to have agreements in place confirming their vendors meet the same safeguard standard the custodian is on the hook for.
Ontario Has Started Actually Fining People
For most of PHIPA's history, the consequence of a bad breach was reputational, a notification letter and an uncomfortable few weeks. That changed in August 2025, when the Information and Privacy Commissioner of Ontario issued the first administrative monetary penalties in the law's history, using enforcement powers that let it fine individuals up to $50,000 and organizations up to $500,000 per contravention. The case involved a physician who misused access to a shared electronic health record system to identify and contact patients for services unrelated to their care, and it was flagged and reported by the hospitals sharing that record system. That case had nothing to do with ransomware, and it is still the clearest signal yet that Ontario's privacy regulator now has, and is willing to use, real financial teeth. A framework that used to run entirely on voluntary compliance and public shaming now has fines attached, and dental and medical practices are squarely inside its scope.
What Actually Closes the Gap
The technical side of PHIPA compliance overlaps heavily with what any professional-services firm handling sensitive data should already be doing, and we covered the general version of this in our look at PIPEDA and SOC 2 for growing firms, the same overlap we described for accounting practices handling client SINs and tax filings. For a practice running Microsoft 365 or Google Workspace, a handful of things do most of the work. Multi-factor authentication needs to sit on every account that touches patient data, with legacy authentication protocols switched off so an attacker cannot route around MFA through an older mail client. Centralized audit logging matters just as much, because a breach investigation always starts with the same question, which accounts touched which records and when, and a practice without logs has no way to answer it. Backup for the practice management system and patient records needs to be encrypted, immutable against ransomware, and tested with an actual restore rather than trusted on a green dashboard, a point we go into in more detail in why backups only count if you test them. And someone needs to have written down, before an incident happens, who calls the IPC, who calls affected patients, and who calls the practice's insurer, so that decision does not get made for the first time under pressure.
None of this requires a dedicated privacy officer working full time or a six-figure security budget. It requires treating patient data with the same seriousness the law already assumes a hospital applies, scaled down to the size of a four-chair office, and documenting it so the annual report to the IPC is a formality instead of a scramble. Practices that get ahead of it, the way our clients in managed security and compliance do, rarely spend a week reconstructing what happened after an incident, because the documentation and the backups were already sitting there waiting for the question. If your practice has never mapped its PHIPA obligations against what your Microsoft 365 or Google Workspace tenant actually enforces, that gap is worth closing before an insurer, a patient complaint, or the IPC finds it first.