Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
AI vendors are walking into Ontario clinics with demo decks every week. The pitches sound clean: Heidi drafts your notes, Tali closes your charts, DAX integrates with Epic.
None of those decks lead with where the data lives, what the College expects in an audit, or how a PHIPA breach notification reads when the AI medical scribe’s logs sit in a US-east-1 bucket. This post does.
Key Takeaways
- Three regulators bind every Ontario clinic AI deployment in 2026: the CPSO AI advice (August 2025), the IPC’s 2026 AI scribe guidance, and PHIPA s. 12 notification duties.
- The OntarioMD and WIHV evaluation put over 150 Ontario primary-care providers on an AI scribe for three months. The lab result was a 69.5 percent cut in documentation time; the real-practice result was three hours a week.
- Ontario now has a qualified vendor list. Supply Ontario’s Vendor of Record arrangement Tender-20123 pre-qualified 30 AI scribe products against privacy, security and clinical criteria.
- PHIPA sets no 60-day breach clock. Notice to the patient and to the IPC is due at the first reasonable opportunity, with a separate statistical report each March 1.
- A US-hosted scribe triggers Quebec Law 25 assessment plus CLOUD Act exposure and PIPEDA cross-border consent obligations at once.
- The 6-step rollout separates clinics that pass an IPC review from clinics that explain themselves to one.
The 2026 regulator stack: CPSO, IPC Ontario, and PHIPA section 12
The Personal Health Information Protection Act, 2004 (PHIPA) sets the notification duty and dictates which incidents reach the IPC. AI incidents, from a prompt leak to an unsanctioned tenant, run on the same statutory clock. The breach SOP section below operationalizes it.
Above that sits a third layer most clinics miss. The IPC and the Ontario Human Rights Commission published joint Principles for the responsible use of artificial intelligence on January 21, 2026, covering privacy and human-rights expectations across every Ontario sector, health included.
What is an AI scribe under PHIPA, and when does a clinic become the accountable custodian?
According to the Information and Privacy Commissioner of Ontario (2026), an AI scribe is a transcription tool that produces summaries of care visits for entry into an electronic medical record. The Commissioner draws a hard line around it: entering personal health information into an AI scribe the custodian has not authorized is itself a privacy breach.
The custodian question settles before the software question. Under PHIPA a physician in independent practice is a health information custodian, and the clinic corporation usually is not.
That matters because accountability does not transfer to the vendor. A scribe is either an agent under s. 17 or a supplier of electronic services under s. 10(4). Neither route moves the duty off the custodian.
Why Canadian data residency is now table-stakes
The fastest way to fail a 2026 cyber-insurance renewal is deploying an AI scribe whose index lives in a US AWS region. Three legal frameworks bite at once.
The US CLOUD Act lets US law enforcement compel disclosure from a US-headquartered cloud provider wherever the data sits. Quebec’s Law 25 demands an impact assessment for cross-border transfers and gives patients a right to refuse automated processing. PIPEDA calls for comparable protection, and the Office of the Privacy Commissioner of Canada treats cross-border PHI flows as high-risk.
According to Microsoft Learn’s Microsoft 365 data residency documentation, Canada is a Local Region Geography. Microsoft 365 Copilot and Copilot Chat are among the services that provision to a tenant’s default geography. A tenant created with Canada as its default geography is the low-risk starting point for administrative drafting.
Ambient AI scribes are a different question, and the answer is now checkable. Read the clause naming the hosting region and refuse if the answer is not Canada. Across our 41 Canadian SMB client fleets we measured how often that clause was actually produced on request: rarely on the first ask, usually by the second.
Our engineers found the same failure pattern each time. The sales deck says Canadian, and the signed agreement says the vendor may process in any region it operates. The agreement wins. Our contract reviews are CISSP-led at a Microsoft Solutions Partner.
PHIPA vs HIPAA: what does a HIPAA business associate agreement not cover in Ontario?
According to the Ontario Medical Association (AI Scribe Guidance Tips), PHIPA applies to the physician directly. Most physicians are custodians of health information under that law. The OMA tells physicians to have the vendor attest to PHIPA compliance in the contract terms. It also offers to review any AI contract sent to its legal affairs team.
HIPAA is United States federal law. It has no application to an Ontario clinic and no bearing on what the IPC will ask for. A business associate agreement is a US artifact answering a US statute.
The practical test is short. If the only privacy document a vendor offers is a HIPAA BAA, that vendor has not yet done Canadian work.
| Question an Ontario clinic must answer | Covered by a HIPAA BAA? | Canadian instrument that governs it |
|---|---|---|
| Restrictions on a supplier’s use of PHI. | No. | O. Reg. 329/04 s. 6(1) under PHIPA s. 10(4). |
| Responsibility for an agent’s handling of PHI. | No. | PHIPA s. 17(1) and s. 17(3)(b). |
| Notice to the patient after a breach. | No. | PHIPA s. 12(2)(a), at the first reasonable opportunity. |
| Notice to the regulator after a breach. | No. | PHIPA s. 12(3) and O. Reg. 329/04 s. 6.3. |
| Annual breach statistics filing. | No. | O. Reg. 329/04 s. 6.4, due March 1 each year. |
| Cross-border transfer of patient data. | No. | PIPEDA comparable-protection, plus Quebec Law 25 where applicable. |
AI scribes in primary care: what OntarioMD actually said
Read those two numbers together and the gap is the story. A 69.5 percent cut in the lab is not three hours a week in a real practice, and the difference is where clinic owners get their expectations wrong.
The national picture confirms it. Canada Health Infoway’s AI Scribe Program launched in June 2025 and now enrols more than 12,000 primary care clinicians. Its evaluation reports an average of one hour or more saved per week during work hours.
Nearly 70 percent reported reduced administrative burden and more than 90 percent agreed the scribe added value. The satisfaction numbers run well ahead of the clock numbers.
The clinical reality is messier still. Any gain assumes the scribe sits inside the consent workflow, physicians review every note before signing, and the EMR integration holds. Clinics in Ontario that skipped any of those controls hit lower numbers.
FC internal benchmark from Q1 2026: across three Ontario clinic deployments we measured documentation-time reduction at 58 percent in week one, 64 percent at week eight, and 71 percent by month four.
Clinics that compressed the order of operations hit 30 to 40 percent in the same window. Order of operations, and not vendor selection, was the dominant variable in our sample.
Ontario AI Scribe Program: what criteria did Supply Ontario use to qualify 30 vendors?
According to Supply Ontario (Tender-20123, 2025), the province established a Vendor of Record arrangement for AI scribe solutions. It runs from April 27, 2025 to April 27, 2028, and it was built with the Ministry of Health, Ontario Health and OntarioMD. Thirty vendors were pre-qualified through a competitive request for bids.
This changed the buying job. The starting point is now a published Ontario list of 30 products that already cleared provincial privacy, security and clinical criteria.
Four privacy and legal requirements from that evaluation are worth quoting to any vendor, on or off the list:
- Residency. All personal health information must be stored and processed in Canada, unless the buyer and user are notified and the alternative location meets equal or higher security standards.
- No training on patient data. Vendors cannot use patient information, even de-identified, to train or improve their models.
- Secure deletion. Visit summaries and related personal information should be destroyed once the clinician has reviewed the note and uploaded it to the EMR.
- Independent assessment. Vendors must run threat risk assessments and privacy impact assessments using qualified independent professionals, and hold SOC 2 Type II, ISO 27001 or HITRUST r2.
Adoption runs through the OntarioMD Practice Hub for primary care clinics and Ontario Health Teams. That is where a clinic starts the procurement, not at a vendor website.
Which AI scribe vendors are on the Ontario Vendor of Record list?
According to Supply Ontario (Tender-20123, 2025), thirty suppliers were pre-qualified for AI scribe solutions under an arrangement running to April 27, 2028. The list is public and names the product alongside the corporate entity. It is the fastest way for a clinic owner to separate a real Ontario option from a demo deck.
The qualified suppliers, as published by Supply Ontario:
- Able Industrial Trades (Aliant Technologies).
- ADGTech (ADGScribe).
- Alifor.
- AlphaGlobal IT.
- Aya Health Technologies (Autochart.ai).
- Canadian Shield Health Care Services.
- Data Centre Intelligence.
- Deljoo (DelVoice).
- DLS Technology.
- DocSplain AI.
- Empathia AI.
- EMERGE Healthcare (AI EMERGE Scribe).
- Heidi Health Corporation.
- iQonsulting.
- MarkiTech (CliniScripts).
- MD Voice AI.
- MEDFAR Clinical Solutions (CareWay).
- Mikata Health (Mika AI Scribe).
- Mutuo Health Solutions (AutoScribe).
- Newbuy.
- Pippen AI.
- QuickChart.
- Rosc AI.
- Scribeberry.
- SinaAI.
- Siy.Ai Systems.
- Solventum Canada (Fluency Align).
- Tali AI.
- Vero Scribe.
- Zokforce.
Two names Ontario clinic owners ask about most are absent. Nabla and Microsoft Dragon Copilot are not on this list, which does not make either unusable. It means no provincial body has checked them on your behalf.
The PHIPA AI Decision Matrix
Each column is a question the IPC or the CPSO will ask in an Ontario audit. A vendor that cannot answer any one of the 6 in writing is not deployable. An IPC-grade privacy impact assessment is required before deploying any of them.
| Product | Ontario VOR Tender-20123 | Residency you can hold them to | PHIPA s. 10(4) and s. 17 obligations | OHIP billing exposure |
|---|---|---|---|---|
| Heidi Health Corporation | Listed. | VOR Canadian storage rule applies. Name the region. | Both, by section number. A HIPAA BAA alone fails. | Low. No billing-code automation. |
| Tali AI | Listed. | VOR Canadian storage rule applies. Name the region. | Both, by section number. A HIPAA BAA alone fails. | Medium. SOAP notes reach billing. |
| Mutuo Health Solutions (AutoScribe) | Listed. | VOR Canadian storage rule applies. Name the region. | Both, by section number. A HIPAA BAA alone fails. | Low. Transcription only. |
| Solventum Canada (Fluency Align) | Listed. | VOR Canadian storage rule applies. Name the region. | Both, by section number. A HIPAA BAA alone fails. | Medium. Enterprise EMR billing flow. |
| Nabla Copilot | Not on the Ontario list. | No provincial backstop. You negotiate residency yourself. | You draft them. Nothing pre-checked. | Low to medium by integration. |
| Microsoft Dragon Copilot (Nuance DAX) | Not on the Ontario list. | No provincial backstop. Check tenant geography and the CLOUD Act position. | You draft them onto the Microsoft agreement. | Medium. Enterprise EMR billing flow. |
| Consumer ChatGPT, Gemini or Claude.ai | Not on the Ontario list. | None available on consumer terms. | Not offered on consumer terms. | Critical. Any paste is reportable. |
The matrix is a starting point. Vendor postures shift quarterly, the Vendor of Record list is refreshed, and the deployable set depends on what each vendor will sign. Rebuild it against your own contract reads before every renewal.
Note what the matrix deliberately does not carry: vendor-quoted retention defaults and vendor-quoted hosting regions. Across our Ontario engagements those 2 claims change between the demo and the signature more often than any other, so we grade the clause and not the brochure.
How much does an AI scribe cost an Ontario clinic in 2026?
According to Canada Health Infoway (2026), its national AI Scribe Program provided fully funded one-year licences for pre-qualified tools to eligible primary care clinicians, and now enrols more than 12,000 of them. A clinic that qualifies can pilot at no licence cost, which changes the business case before any vendor negotiation begins.
Outside a funded program, budget 100 to 200 CAD per physician per month for scribe licensing. Add 30 CAD per administrative user per month for Microsoft 365 Copilot.
Deployment services run 15,000 to 30,000 CAD depending on safeguard posture and EMR complexity. The privacy impact assessment, the consent rollout and the network work all sit inside that number, and in our Ontario engagements the network work is the part clinics underestimate.
Physician accountability under CPSO: what “informed by AI” means in audit
The College states the position plainly: although there is currently no specific law or policy addressing AI, the core expectations of physicians remain unchanged. The physician keeps every pre-existing duty. What AI changes is the documentation expectation.
An audit-ready chart names the AI tool used, identifies what the tool informed, and records the physician’s review. A consistent template line works: “Encounter transcribed by Tali AI; physician reviewed and approved before sign-off.” The audit hinges on consistency, not elegance.
The College has been clear that “informed by AI” without supervision fails: a physician who approves an AI-generated note unread is exposed to professional discipline as well as civil liability and PHIPA breach reporting. In our practice, that review discipline is the first thing an IPC file review asks about.
Anonymized client data from FC’s 2026 healthcare engagements backs the practical version of that standard. Across the three-clinic Q1 2026 cohort we measured a median of 1.4 transcription corrections caught per chart in month one, dropping to 0.6 by month three.
The corrections do not stop. They shrink. A clinic that budgets for zero corrections by month 3 has budgeted wrong, and our engineers found that the residual rate holds steady rather than trending to zero.
Every correction was logged through the EMR approval audit trail at each Ontario clinic. That discipline (review, correct, approve) is what makes “informed by AI” hold up.
Our reviews are CISSP-led at a Microsoft Solutions Partner. Book an AI Readiness Call to get your documentation template written.
The 60-day breach SOP every clinic needs before deploying AI
Where this usually goes next
If the work you want to hand to AI is a repeatable process rather than a writing task, automation is usually the cheaper answer. Individual flows start from $500, and a scoped discovery engagement is $750.
How we scope and build automation
Book a 20-minute call
Senior engineer, not sales. If there is nothing worth doing we will tell you.
According to PHIPA s. 12(2)(a) and s. 12(3) (2004), a custodian must notify the affected individual “at the first reasonable opportunity” after personal health information is stolen, lost, or used or disclosed without authority. Notice to the Commissioner follows the same standard under O. Reg. 329/04 s. 6.3(3).
So why does Fusion Computing publish a 60-day SOP? Because a clinic needs a bounded internal window to work inside, and 60 days is the outer edge we hold engagements to for closing out the full package. It is an operating standard, not a legal ceiling.
A working SOP names who logs the breach, who calls the IPC, who notifies the patient, and who reconstructs the AI prompt history. Our internal sequence is 72 hours for triage, one week for the interim report, and 30 days for the remediation summary.
The seven circumstances that force a call to the Commissioner are listed in O. Reg. 329/04 s. 6.3(1). They include theft, an unauthorized use or disclosure by someone who knew better, a pattern of similar incidents, and any loss the custodian judges significant after weighing sensitivity, volume and the number of patients involved.
Three artifacts must exist before the first AI tool goes live. A written breach SOP naming the clinical-director-level owner. A tabletop test inside the first quarter. A vendor escalation contact in every agreement with a 24-hour response commitment.
Meeting the first-reasonable-opportunity standard is a configuration problem before it is a paperwork problem. Our Purview eDiscovery and legal hold walkthrough for Ontario clinics covers the Purview case template that scopes an incident in hours instead of weeks.
Patient consent: implied, express, and when CPSO requires disclosure
According to the Ontario Medical Association (AI Scribe Guidance Tips), a physician should obtain express consent the first time an AI scribe is used. Patients must be able to opt out of AI and recording without any effect on the care they receive. Notice of recording and retention belongs in clinic signage and in the privacy notice.
That is a stronger position than PHIPA’s baseline. PHIPA permits implied consent inside the circle of care for routine clinical use, and the CPSO requires patient consent before conversations are recorded.
For tools routing patient data outside Ontario, the OMA adds a further step: the fact of that transfer belongs in your publicly available privacy policy. OntarioMD publishes a patient consent toolkit a clinic can adopt rather than draft.
Quebec’s Law 25 forces the issue with express, informed, granular consent for automated processing. Multi-province groups are well served adopting the Law 25 standard network-wide: it satisfies PHIPA and British Columbia’s PIPA at once.
British Columbia runs the same logic. Its College publishes Ethical Principles for Artificial Intelligence in Medicine, effective April 11, 2024 and last revised April 1, 2026. It requires licensees to be transparent about how far they rely on AI. It also bars transferring patient data out of the care environment without consent.
Under the 2025 CPSO advice, the College expects disclosure when AI surfaces a differential the physician would not otherwise have considered, drafts a referral letter the patient signs, or shapes the medication decision. Routine transcription the physician reviews and signs does not trigger explicit clinical disclosure, though the consent-for-use posture still applies.
“The PHIPA-compliant rollout Fusion ran for our four-physician family practice put consent, residency, and the breach SOP in writing before the scribe ever recorded a patient. Our IPC posture is stronger now than it was before we deployed AI, not weaker. That is the bar a clinic owner should hold any vendor to.”
Vendor selection: 15 questions to ask any AI scribe vendor
Every question below maps to a written answer the IPC or the College can later ask to see. The screen condenses the PHIPA s. 10(4) and s. 17 review, the Supply Ontario privacy criteria, and the Law 25 and PIPEDA cross-border tests into one demo-meeting checklist for Ontario clinic owners.
- Are you on the Supply Ontario Vendor of Record list under Tender-20123? If not, why not?
- Where does the data physically reside? Name the cloud region in the agreement.
- Will you carry the PHIPA s. 10(4) and O. Reg. 329/04 s. 6(1) obligations by section number?
- Are you an agent of the custodian under PHIPA s. 17, or a supplier of electronic services?
- Do you use patient data, de-identified or otherwise, to train or improve any model?
- Will you commit in writing that recordings and transcripts are destroyed inside 30 days?
- What is your incident-response commitment on a suspected breach, in hours?
- How do you handle US law-enforcement disclosure requests under the CLOUD Act?
- Will you furnish a privacy impact assessment and threat risk assessment we can hand to the IPC?
- Which security certification do you hold: SOC 2 Type II, ISO 27001 or HITRUST r2?
- What is your physician sign-off workflow inside the EMR integration?
- How do you handle a request to delete a specific patient’s data?
- What is your disclosed error rate for medical-term transcription?
- Do you warn the clinician when part of a conversation was not fully processed?
- Who signs the agreement on your side, and how quickly?
A vendor that hesitates on question 1, 3, 5 or 6 is out. One that answers all 15 in writing inside a week is doing the work to be deployable. Fusion Computing runs this screen, CISSP-led, in every clinic readiness review.
The Ontario Medical Association will also review any AI contract sent to its legal affairs team and flag issues for the physician. Of our clients who used that route, none regretted the extra week.
Does every AI tool need its own privacy impact assessment?
According to the Information and Privacy Commissioner of Ontario (2026), a custodian should assess the vendor and the AI system before deployment and keep monitoring it afterwards. That framing runs per system rather than per clinic. A second tool means a second assessment, not an amendment to the first.
The practical shortcut is a template. Build the assessment once against PHIPA s. 10(4), the residency question and the retention question, then re-run it for each tool.
Re-run it again when a vendor materially changes the product. Across our Ontario engagements the trigger that catches clinics out is a vendor adding a new model or a new sub-processor mid-term.
The 6-step rollout: policy, DPIA, pilot, consent, audit, renew
The discipline below is the exact sequence Fusion Computing runs for healthcare engagements in 2026. No step is optional or parallelized; compressing the sequence is the most common reason a clinic ends up in front of the IPC instead of a vendor.
- Policy. Publish the AI acceptable use policy and name a clinical-director-level AI steward.
- DPIA. Complete a privacy impact assessment covering PHI flows, residency, retention, cross-border posture.
- Pilot. Deploy to two physicians for four weeks; track time saved plus accuracy incidents and patient feedback before expanding.
- Consent. Ship the consent script and lobby notice; confirm the EMR carries the AI-flag into the audit log.
- Audit. Run the first quarterly audit: PHIPA compliance, label hygiene, CPSO documentation, the breach SOP tabletop.
- Renew. Renegotiate the DPA at 12 months, and re-run the DPIA if the product materially changes.
What should an Ontario clinic deploy first, Copilot or an AI scribe?
According to Microsoft Learn (2026), Microsoft 365 Copilot and Copilot Chat provision to a tenant default geography, so a tenant created with Canada as its default keeps that processing in Canada. That makes Copilot the lower-risk first move for administrative drafting inside an Ontario clinic.
Copilot first and scribe second is the order we run. Administrative drafting carries no consult-room recording, no patient consent script and no ambient capture of a clinical encounter.
The scribe is a separate procurement with its own consent, residency and retention obligations. A clinic that has already governed Copilot has built most of the muscle the scribe deployment needs.
Do and don’t: four sanctioned moves, four deployment killers
Do these four things:
- Deploy Microsoft 365 Copilot in a Canadian-geography tenant for administrative drafting first: the lowest-risk starting point.
- Sign a PHIPA-aligned DPA with any scribe vendor before a pilot, not after.
- Run the privacy impact assessment as a working document, not a one-time artifact.
- Bake AI-use review into the supervision cycles the clinic already runs.
Do not do these four things:
- Do not paste PHI into consumer ChatGPT, Gemini or Claude.ai. That is a notifiable breach the moment it happens.
- Do not skip the privacy impact assessment because the vendor demo went well.
- Do not deploy a US-hosted scribe without a cross-border PIA and Law 25-grade consent.
- Do not let the AI tool sign the note. The physician signs. Every time.
What happens at IPC audit, and how OHIP billing exposure compounds risk
According to the Information and Privacy Commissioner of Ontario (April 27, 2026), an unapproved AI scribe auto-joined a hospital clinical-rounds meeting. In reported breach HR24-00691 it transcribed the personal health information of seven patients. The account belonged to a physician who left in June 2023, whose personal calendar still carried the recurring invite.
Read that case closely. Nobody pasted patient data into a chatbot. A departed clinician installed a consumer transcription tool on a personal device in September 2024, and it walked into a meeting on its own.
The Commissioner’s takeaway is blunt. Entering personal health information into an AI scribe the custodian has not authorized is a privacy breach, and it may trigger both patient notification and a report to the IPC.
An IPC audit on a clinic AI deployment opens with a document request. The AI policy, the privacy impact assessment, the vendor agreement, 90 days of audit logs, the breach SOP, the consent posture. Clinics that produce the binder inside 5 business days move through quickly.
OHIP billing exposure adds a second axis. When an AI tool produces or suggests a billing code, the College and the Ministry of Health both pay attention. An incorrect code is a billing dispute; a pattern of AI-attributable incorrect codes without physician review is a compliance event.
In Ontario, the simplest control is a hard rule that the physician opens the code field manually rather than accepting an AI default, and that the binder proves it.
HOW THIS GUIDANCE WAS ASSEMBLED.
This article rests on three first-party inputs. Anonymized client data from FC’s 2025 and 2026 Ontario clinic engagements. An FC internal benchmark from Q1 2026 on scribe deployment across three clinics. First-person field observation from Mike Pearlstein’s practice since 2012.
Every external claim was checked against the primary document in August 2026, including the statute and regulation text on Ontario e-Laws. Where a source did not support the claim we previously published, the claim was rewritten or removed rather than repointed.
Further reading and primary sources
- CPSO, Advice to the Profession: Using Artificial Intelligence in Clinical Practice. Last updated August 2025.
- IPC Ontario, AI Scribes: Key Considerations for the Health Sector. January 28, 2026, plus its checklist.
- IPC Ontario, Artificial intelligence gone wrong (case of note HR24-00691). April 27, 2026.
- IPC Ontario and OHRC, Principles for the responsible use of artificial intelligence. January 21, 2026.
- Supply Ontario, Tender-20123 Artificial Intelligent Solutions, AI Scribe. The Vendor of Record list and its criteria.
- OntarioMD Practice Hub, Ontario AI Scribe Program. Where the procurement starts.
- Ontario Medical Association, AI Scribe Guidance Tips. Retention ceiling and consent guidance.
- OntarioMD, WIHV and eHealth Centre of Excellence, Clinical Evaluation of AI and Automation Technology (2024). The 69.5 percent and three-hour figures.
- Canada Health Infoway, AI Scribe Program. The national evaluation, 12,000 clinicians.
- Personal Health Information Protection Act, 2004 and O. Reg. 329/04. Act ss. 10(4), 12, 17; regulation ss. 6, 6.3, 6.4.
- CPSBC, Ethical Principles for Artificial Intelligence in Medicine. Revised April 1, 2026.
Frequently Asked Questions
Is Microsoft 365 Copilot PHIPA-compliant out of the box?
No. A default tenant is not enough. Canadian tenant geography, sensitivity labels in Microsoft Purview, DLP rules, Entra ID conditional access and a documented privacy impact assessment all come first, in writing.
What does AI adoption typically cost for a 10-physician Canadian clinic?
Budget 100 to 200 CAD per physician per month for AI scribe licensing. Add 30 CAD per administrative user per month for Microsoft 365 Copilot. Deployment services run 15,000 to 30,000 CAD depending on safeguard posture and EMR complexity.
Can a clinic use ChatGPT or Gemini on patient data in an emergency?
No. Consumer AI tools sit outside any PHIPA-compatible agreement, and pasting patient data into them is a reportable breach in Ontario. Microsoft 365 Copilot in a Canada-geography tenant is the deployable alternative.
What is the relationship between the CPSO Advice and the IPC guidance?
The CPSO Advice governs the physician: accuracy, accountability, privacy, bias, transparency. The IPC’s 2026 AI scribe guidance governs the data layer: vendor assessment, contractual safeguards, monitoring, accountability. A clinic that satisfies 1 of the 2 is exposed under both.
Does PHIPA give an Ontario clinic 60 days to report a breach?
No. PHIPA contains no 60-day breach deadline. Section 12(2)(a) requires notice to the individual at the first reasonable opportunity, and O. Reg. 329/04 s. 6.3(3) applies that same standard to the Commissioner. The only fixed date is the March 1 statistical report under s. 6.4.
Does HIPAA apply to a Canadian clinic?
No. HIPAA is US federal law with no force in Canada. An Ontario clinic answers to PHIPA and, for cross-border flows, PIPEDA. A vendor offering only a HIPAA business associate agreement has answered 0 of the 6 questions that matter here. Ask for the PHIPA s. 10(4) and O. Reg. 329/04 s. 6(1) obligations in writing.
Is Heidi PHIPA compliant?
No AI scribe is compliant on its own; the custodian is. Heidi Health Corporation is 1 of the 30 products pre-qualified on Supply Ontario’s Tender-20123, which required PHIPA, PIPEDA and FIPPA compliance plus Canadian storage. That clears the product. The clinic still owes the assessment, the consent script and the breach plan.
What is the Ontario AI Scribe Program vendor list?
It is Supply Ontario’s Vendor of Record arrangement Tender-20123, effective April 27, 2025 through April 27, 2028, built with the Ministry of Health, Ontario Health and OntarioMD. It pre-qualified 30 AI scribe products across clinical, privacy and security criteria. Clinics start through the OntarioMD Practice Hub.
Does the CPSO require patient consent before an AI scribe records?
Yes. The CPSO tells physicians to inform patients how AI will be used and to obtain consent before recording conversations. The Ontario Medical Association goes further, recommending express consent on first use with a genuine opt-out that does not affect care.
How long can an AI scribe keep the recording and transcript?
The OMA sets the clearest Ontario benchmark: no longer than the minimum needed to deliver the service, and in no case beyond 30 days. Supply Ontario goes further for listed products, expecting the visit summary destroyed once the clinician uploads the note.
Who is liable if an AI scribe writes an inaccurate note?
The physician. The CPSO holds physicians ultimately accountable for their use of AI tools and expects all AI-generated content reviewed for accuracy. PHIPA s. 17(3)(b) keeps the custodian responsible for what an agent handles. Across our three-clinic Q1 2026 cohort we measured 1.4 corrections caught per chart in month one.
Can an unapproved AI note-taker cause a reportable breach on its own?
Yes, and it has. In IPC reported breach HR24-00691 a consumer transcription tool auto-joined a hospital clinical-rounds meeting through a departed physician’s personal calendar and captured data on 7 patients. The controls the IPC asked for: an offboarding calendar audit, a meeting lobby, a participant-list check, AI-specific training.
Final thoughts
The clinics that win with AI in 2026 move in the right order. Policy before pilot. Privacy impact assessment before deployment. Consent before recording. Audit before expansion.
Ontario has done more of the work for you than most clinic owners realize. There is a qualified vendor list, a published checklist, a consent toolkit and a decided enforcement case.
Fusion Computing has run PHIPA-grade AI readiness reviews for Ontario clinics since 2012, CISSP-led, at a Microsoft Solutions Partner. Book an AI Readiness Call and we will map your clinic against all four.
AI sits on top of the same custodial controls as everything else in the clinic. For the underlying stack, see managed IT services for healthcare providers.

