Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Building and managing secure IT for Canadian businesses since 2012 across Toronto, Hamilton, and Metro Vancouver.
The Information and Privacy Commissioner of Ontario published AI Scribes: Key Considerations for the Health Sector on January 28, 2026, with a companion checklist. It reads short and lands hard. Custodians are told to assess the vendor and the system, and to write explicit contractual safeguards. They must also monitor the system over time and stand up a governance framework before a scribe touches a patient encounter.
Hospitals have privacy teams that turn that into a project plan. A four-doctor Family Health Organization does not.
This walk-through applies the checklist line by line to a composite four-physician clinic in Etobicoke. Read it if you are the lead physician, the practice manager, or the named privacy contact, and you are the one who has to produce the artifacts.
Key takeaways
- The IPC guidance is interpretive, not statutory. It reads PHIPA, and PHIPA binds every Ontario custodian (IPC Ontario, 2026).
- A four-doctor clinic needs a 10-to-15 page Privacy Impact Assessment before the scribe is switched on. It is filed at the clinic, not submitted to the Commissioner.
- Three of the four Ontario clinics Fusion Computing reviewed in Q1 2026 had no written vendor attestation letter on file, and in every case the vendor had one available on request.
- PHIPA has no section 12.3 and no audit-log section in force. Section 10.1, the electronic audit-log duty, is enacted but awaits proclamation. The live hooks are sections 10, 12, 13 and 17.
- The CPSO disclosure duty runs in parallel. Patient consent to AI use is separate from consent to the encounter.
What is the IPC AI scribes checklist, explained
According to the Information and Privacy Commissioner of Ontario (2026), four things are in scope. Assessing vendors and AI systems, setting clear contractual safeguards, monitoring systems over time, and building a governance framework. A separate checklist companion turns it into questions a custodian answers.
The Commissioner’s position is that PHIPA already governs AI in clinics. The guidance amends nothing. It explains how existing duties apply to systems that process personal health information.
So the Ontario compliance gap is not missing rules. It is the absence of the 6 written clinic artifacts showing those rules were operationalized. A clinic that cannot produce them has a problem before the Commissioner reads a single page.
Which PHIPA sections does each checklist domain require?
According to the Personal Health Information Protection Act, 2004 (2026 consolidation), four sections carry the weight for a clinic AI deployment. Section 10 governs information practices and electronic service providers. Section 12 is the reasonable-steps safeguards duty. Section 13 governs secure retention, transfer and disposal. Section 17 makes the custodian responsible for its agents.
[REGULATOR QUOTE].
Remain responsible for any personal health information that is collected, used, disclosed, retained or disposed of by the custodian’s agents, regardless of whether or not the collection, use, disclosure, retention or disposal was carried out in accordance with subsection (2).
Personal Health Information Protection Act, 2004, section 17(3)(b), read from the Ontario e-Laws consolidation.
Two corrections are worth making before you write anything down, because both circulate widely in Ontario clinic templates. There is no section 12.3 of PHIPA. And the electronic audit-log duty is section 10.1, which is enacted but not yet proclaimed. So an audit-log requirement in 2026 comes from the vendor contract and from professional record-keeping rules, not from a live statutory section.
| Domain | PHIPA anchor | Artifact | Common pitfall. |
|---|---|---|---|
| Lawful authority | s.29, s.37 | Written purpose statement, named privacy contact | Nobody owns AI compliance. |
| Privacy Impact Assessment | s.12 | 10-to-15 page assessment | Go-live decided on a sales call. |
| Vendor contract | s.10, s.17 | Agreement naming the vendor an agent or service provider | Click-through terms, no agent designation. |
| Patient disclosure | s.18, CPSO advice | Consent script, signage, per-visit chart note | Physician improvises, some patients never told. |
| Audit logging | Contract, s.10.1 pending | Contractual retention, custodian access, annual review | Short vendor default, logs gone before review. |
| Safeguards | s.12, s.13 | Administrative, technical and physical controls | Technical only, no training log. |
The flagship piece on PHIPA-compliant AI deployment for Canadian clinics covers the wider policy architecture. This walk-through is what the privacy contact uses on Monday morning.
A four-doctor clinic walk-through, domain by domain
According to the College of Physicians and Surgeons of Ontario (2026), physicians stay accountable for their use of AI tools. They must review AI-generated content for accuracy, tell patients how AI will be used, and obtain consent before an encounter is recorded. Those duties sit on top of the custodian’s PHIPA duties.
Our worked example is a composite: four physicians, one nurse practitioner, two registered nurses, two medical office assistants, an outsourced IT provider, a panel of 6,400, and a Canadian-hosted EMR. The practice manager is the named privacy contact. The lead physician wants an AI scribe live by the end of the quarter.
- Lawful authority. A one-paragraph purpose statement naming the tool, the use case, and the PHIPA section relied on for providing health care, signed and dated by the privacy contact.
- Privacy Impact Assessment. Ten to fifteen pages covering vendor, data flow from microphone to EMR, residency confirmed in writing, contract clauses, consent script, and the log-review plan.
- Vendor contract. Not the click-through terms. The clinic asks for the vendor’s data-processing agreement, checks it against the section 17 agent designation, and red-lines what conflicts.
- Patient disclosure. A six-sentence script the physician reads when the scribe is on, waiting-room signage, and the patient’s decision recorded per visit. If the patient declines, the scribe stays off.
- Audit logging. A contractual retention period with custodian access on request, spot-checked quarterly and reviewed in full once a year.
- Safeguards. Annual training with signed acknowledgements, MFA on every clinic account, encryption in transit and at rest, managed physician laptops, locked workstations.
The assessment never goes to the Commissioner for a routine deployment. It is filed at the clinic and produced within a reasonable time if asked. The disclosure script is harmonized with our CPSO AI disclosure guide so the physician duty and the custodian duty are met with one artifact.
The PIA template: eight sections and what goes in each
According to the IPC privacy impact assessment guidelines (2026), the assessment records data flows, risks and mitigations. Most small-clinic assessments fail at the same three points: vague data flow, no written residency confirmation, and no audit-log specifics.
- Custodian and contact. Legal name, address, lead physician, named privacy contact, date.
- Purpose. One paragraph naming the tool, the use case, and the PHIPA section relied on.
- Data flow. One page from microphone to EMR, each arrow labelled with data type and destination region.
- Vendor profile. Jurisdiction of incorporation, hosting region, named sub-processors, certifications held.
- Contract analysis. Agent designation, no training on personal health information, log retention, breach-notification window, return-or-destroy on termination.
- Consent and disclosure. The script itself, plus the signage and chart-documentation protocol.
- Safeguards. Administrative, technical and physical controls actually in force, not planned.
- Residual risk. What the clinic accepts, and the privacy contact’s sign-off.
In our experience a four-doctor clinic completes that in two afternoons. Ask us for the Fusion Computing PIA template and we will walk your first one through →
Vendor due diligence: how do you compare AI scribe vendors?
According to Microsoft (2026), Canada is a Local Region Geography and a tenant’s data-residency commitment follows the default geography set at tenant creation. Vendors built on Microsoft Azure inherit Canadian regions only if the vendor elected them. Vendors on other clouds have their own Canadian regions, and the clinic confirms which one in writing.
The intake runs before the contract is signed, sits in the assessment appendix, and gets refreshed annually. These are the 12 questions Fusion Computing asks, in the order that surfaces problems fastest.
- Where does the data live? Region, sub-region, and the legal entity owning the infrastructure.
- Does the vendor accept agent status? Written confirmation of the PHIPA section 17 designation.
- Will personal health information ever leave Canada? Inference, fallback regions, training, support and sub-processors are five separate questions.
- Is data used to train models? The default answer must be no for anything identifiable.
- What is the breach-notification window? PHIPA fixes no day count and requires notice at the first reasonable opportunity. Fusion Computing holds itself to a 60-day outside limit; 30 days is better.
- What is the audit-log retention? Match it to the clinical record it describes, which for Ontario physicians is at least 10 years.
- Who at the vendor can reach the data? A role-based access list by named function.
- Which certifications are held? SOC 2 Type 2, ISO 27001 and ISO 27018 are the ones worth asking for.
- What is the termination protocol? Return or destroy inside a defined window, with written attestation.
- Which sub-processors are used? Named, with the same obligations flowed down.
- What happens on a foreign legal demand? A commitment to notify the custodian and challenge where lawful.
- What does a Canadian-residency tier cost? Several vendors quote a United States region by default and price Canadian residency as a separate tier.
Vendor-published defaults change quarterly, so treat any retention or residency figure in a comparison table, including ours, as something to confirm in the contract rather than accept. Our AI scribe comparison for Ontario family doctors turns this intake into a scorecard.
How long must audit logs be kept, and who runs the annual audit?
According to the College of Physicians and Surgeons of Ontario (2026), records are kept at least 10 years from the last entry. For a patient who was a minor, that runs until 10 years after they turn 18. Match the scribe’s log retention to the record it documents.
PHIPA section 13 requires secure retention, transfer and disposal, which is a different duty from keeping an access log. Since section 10.1 is not proclaimed, the log obligation you can actually enforce in 2026 lives in the vendor contract. That is why the retention line belongs in the contract analysis section of the assessment.
- Refresh the assessment. Update the vendor list, data flow, residency line, retention line and consent script. Signed by the privacy contact.
- Get the vendor attestation letter. Written confirmation of Canadian residency, agent designation, log retention and breach window.
- Pull and review the logs. Export 12 months, spot-check 10 visits at random, confirm every access has a matching encounter.
- Sample the consent records. Twenty charts. Confirm the script was offered and the decision recorded.
- Run the staff training. Annual refresher for all personnel, new hires inside 30 days of start, sign-off filed.
- Write the one-page audit report. Date, contact, findings, remediation, next review date. Filed and producible on request.
[FIELD NOTE]
Across the four Ontario FHO clinics Fusion Computing supported through readiness audits in Q1 2026, the same gap appeared in three: no written vendor attestation letter on file. The vendors had the letter ready in every case. The clinic had simply never asked.
The deeper pattern is that small clinics treat a scribe rollout as a software purchase. It is a new collection, use and disclosure of personal health information, and PHIPA treats each of those as a custodial decision.
Mike Pearlstein, CISSP, Fusion Computing.
Whether the clinic can produce 12 months of logs on demand also depends on its tenant licence tier. Our Purview eDiscovery and legal hold walkthrough shows which tier keeps audit records for a full year. We will check your tenant tier against the retention you contracted for →
Which four moves matter most, and which four to avoid?
According to the Office of the Privacy Commissioner of Canada (2026), health information is among the most sensitive data an organization holds. Documented assessment before deployment is what regulators look for when a matter opens. One written under inquiry never reads as well.
- Do name a privacy contact and give that person authority to halt a deployment. Do not let the IT vendor make compliance calls without their sign-off.
- Do run the 12-question intake before signing. Do not accept click-through SaaS terms as the contract.
- Do document residency, retention and agent designation in writing. Do not rely on a sales representative’s verbal assurance that data stays in Canada.
- Do run the annual audit and write the report. Do not assume the assessment written at deployment is still accurate 12 months later.
Across our 40 Canadian client environments in regulated sectors, the same pattern repeats. The Fusion Computing benchmark from Q1 2026 holds here. Three of four Ontario clinics that ran the checklist line by line closed every artifact gap inside one afternoon plus one vendor email. The fourth needed an amendment because no Canadian-residency tier existed at signing.
For the adjacent federal picture, our PIPEDA compliance guide for Canadian small business sets the baseline that interacts with PHIPA across jurisdictions, and our cybersecurity services deploy the technical safeguards section 12 expects.
Bottom line
Six domains, 6 artifacts, 1 privacy contact who owns the file. An Ontario four-doctor clinic produces the assessment, the vendor letter, the consent script, the log review and the audit report in two focused afternoons, then an hour a quarter. The clinics that get blindsided are not the ones with bad technology. They are the ones with no documentation.
CISSP-led reviews. Fusion Computing has run PHIPA readiness audits for Ontario FHO clinics since 2018.
Frequently asked questions
Is the IPC AI scribes guidance mandatory law for Ontario clinics?
It carries interpretive weight without being statutory. It interprets PHIPA, which binds every Ontario health information custodian. The guidance is what the Commissioner will measure a clinic against during a breach investigation or a privacy complaint, so in practice it operates as the floor.
Does a four-doctor clinic actually need a Privacy Impact Assessment?
Yes. An AI scribe is a new collection, use and disclosure of personal health information all at once. The assessment does not have to be long. Ten to fifteen pages naming the vendor, the data flow, the residency, the contract clauses, the log retention and the consent script is what the Commissioner expects to see if asked.
What lawful authority does a clinic rely on when a scribe processes encounters?
The clinic is the custodian and the vendor is an agent or electronic service provider acting on its behalf under PHIPA section 17. Authority flows from the clinic’s collection and use of personal health information to provide health care. The vendor cannot use the data for its own purposes without consent, and the contract must say so.
Does PHIPA require the vendor to store data in Canada?
The Act does not say so in those words. PHIPA treats disclosure outside Ontario under section 50, and where the vendor is an agent the analysis runs through section 17 instead. The Commissioner expects a custodian to weigh jurisdictional risk, including foreign lawful-access regimes, and to record that reasoning in the assessment. Canadian residency confirmed in the contract is the 2026 practice standard.
Does PHIPA mandate multi-factor authentication for AI tools?
No. Neither PHIPA nor Ontario Regulation 329/04 uses the words multi-factor or two-factor anywhere. The duty is section 12(1) reasonable steps. A 2026 clinic running an AI scribe without MFA on the accounts that reach it will have difficulty arguing its steps were reasonable.
What does CPSO require physicians to disclose about AI scribes?
The College places the disclosure duty on the physician. Patients are told an AI tool is in use, what it does, that they may decline, and that the physician remains accountable for the record. A clinic-level script plus waiting-room signage is the standard implementation.
What must be in the vendor agreement?
It names the vendor as the custodian’s agent or electronic service provider and restricts use to purposes the custodian directs. It sets a breach-notification window and requires safeguards equivalent to PHIPA. It requires return or destruction on termination, and prohibits training on personal health information without explicit consent. Generic terms of service do not meet that bar.
How often should the clinic audit the scribe?
Annually at minimum, with a quarterly spot-check of access logs and any incidents. The annual pass covers residency confirmation, the vendor attestation, log retention, assessments for any new use case, staff training completion, and consent complaints. It produces 1 written page the Ontario Commissioner can be shown on request.
What audit-log retention should a clinic contract for?
Match it to the record the log describes. Ontario physicians keep records at least 10 years from the last entry, so a 90-day vendor default leaves the log gone long before any review. Note that PHIPA section 10.1, the electronic audit-log duty, is enacted but awaits proclamation, so the enforceable obligation today is contractual.
Who at the clinic owns AI compliance?
PHIPA requires the custodian to designate a contact person responsible for facilitating compliance. In a four-doctor practice that is usually the lead physician or the practice manager. The checklist treats the named contact as accountable for every domain, and a clinic without one fails at the first row.
What happens if a patient refuses the AI scribe?
The refusal is honoured and recorded. The scribe stays off for that visit and the decision is documented in the chart. Both the College and the Commissioner treat consent to AI use as separate from consent to the clinical encounter, so leaving the scribe running after a refusal breaches both.
Does the Commissioner want the assessment submitted?
Not for a routine deployment. It is filed at the clinic and produced within a reasonable time on request. Submission becomes relevant in narrow situations such as a significant new collection at scale or where the Commissioner has opened a file. Most four-doctor clinics will never submit one.
Further reading and primary sources
- Personal Health Information Protection Act, 2004. Sections 10, 12, 13 and 17 are the live hooks for a clinic AI deployment.
- Ontario Regulation 329/04. Section 6.3 carries the seven Commissioner-notification triggers.
- CMPA advice publications. Advisories on technology and clinical record-keeping.
[ORIGINAL DATA] HOW THIS GUIDANCE WAS ASSEMBLED.
This article draws on Fusion Computing anonymized client data from four Ontario FHO readiness audits in Q1 2026, plus an FC internal benchmark covering AI scribe assessment and vendor attestation across our clinic clients. Statutory text was read from the Ontario e-Laws consolidation of PHIPA rather than from secondary guidance, and layered over it is first-person field observation from CEO Mike Pearlstein, CISSP.

