Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
PHIPA sets no 60-day breach clock. The phrase “60 days” appears exactly once in the Act, at s.74(3), fixing a comment period before the Minister makes a regulation. The 60 days every Ontario clinic has heard about is the HIPAA rule, imported by analogy until it looked domestic.
What PHIPA requires is s.12(2)(a): notify the affected individual “at the first reasonable opportunity”. Subsection 12(3) adds notice to the Information and Privacy Commissioner of Ontario in circumstances prescribed by O. Reg. 329/04 s.6.3. Neither names a day count.
The 60-day window here is our own operating standard. Fusion Computing runs it because a clinic that has not closed the patient letters, the IPC file, the College question and the evidence package inside two months is usually about to discover it cannot.
Key Takeaways
- PHIPA s.12(2)(a) tells you to notify the patient “at the first reasonable opportunity”, and s.12(2)(b) makes the letter itself say the patient may complain to the Commissioner.
- The 7 IPC-reporting triggers sit in O. Reg. 329/04 s.6.3(1), added by O. Reg. 224/17 s.1. Section 6.3(3) applies the same standard.
- The only hard day count is 30 days: the PHIPA s.17.1(2) letter to a College when an employed practitioner is terminated, suspended, disciplined, or resigns over records conduct.
- The annual statistical report is due on or before March 1 under O. Reg. 329/04 s.6.4(1), covering every theft, loss, and unauthorized use or disclosure.
- Ontario custodians self-reported 709 health privacy breaches to the IPC in 2024, up from 590 in 2023. Snooping led at 248 files.
What is a notifiable PHIPA breach: what section 12 requires, explained
Subsection 12(1) is the safeguard duty: reasonable steps against theft or loss, against unauthorized use or disclosure, and against unauthorized copying or disposal. The IPC reads safeguard posture and notification conduct as one file.
Subsection 12(3) turns on when the prescribed requirements are met. Those are the seven circumstances at O. Reg. 329/04 s.6.3(1), inserted by O. Reg. 224/17 s.1 with effect from October 1, 2017.
- Use or disclosure without authority by someone who knew or ought to have known.
- Records the custodian has reasonable grounds to believe were stolen.
- Further use or disclosure after an initial loss or unauthorized event.
- An incident forming part of a pattern of similar losses or unauthorized uses.
- A case where the custodian must give a College notice under PHIPA s.17.1.
- A case where that College notice would be required if the agent were a member.
- Any loss the custodian judges significant on sensitivity, volume, individuals affected, or how many custodians and agents were involved.
Item 7 is the catch-all, and it is why a single-record incident still reaches the Commissioner. A mental-health note, an HIV result or an addiction-treatment file clears the sensitivity limb alone.
Unsure whether your incident crosses s.6.3(1)? Mike Pearlstein, CISSP, runs a CISSP-led incident-response readiness review before the clock starts on a real one.
When the 60-day clock actually starts
Discovery is the trigger. Day 0 is when the clinic knew or ought to have known that records were stolen, lost, or used or disclosed without authority. A weekend and a vendor ticket queue sit inside the window.
Three dates anchor the SOP. Day 0 is discovery and containment. Day 1 is the insurer call, the vendor call and the forensic call. Day 60 is the outer boundary for patient notice, IPC notice, the College question and the evidence package.
The Commissioner has criticised custodians who took months to reach affected patients, because late notice defeats the duty. In our practice most clinic incidents close well inside 60 days once the runbook exists.
The four stakeholders you must notify
Four directions open at once. Each carries its own statutory anchor, its own timing standard and its own evidence trail. Skip one and the Commissioner reads the gap as a gap in the s.12(1) safeguard duty.
| Stakeholder. | Statutory anchor. | Timing standard. | Trigger. |
|---|---|---|---|
| Affected patient. | PHIPA s.12(2)(a) and (b). | First reasonable opportunity. | Any theft, loss, or unauthorized use or disclosure of records. |
| Information and Privacy Commissioner of Ontario. | PHIPA s.12(3) with O. Reg. 329/04 s.6.3. | First reasonable opportunity, plus the annual report by March 1. | One of the seven prescribed circumstances. |
| The practitioner’s College, including the CPSO. | PHIPA s.17.1(2), with CPSO reporting policy on top. | Written notice within 30 days of the event. | Employed member terminated, suspended, disciplined, or resigning over records conduct. |
| Opposing parties in active litigation. | Ontario Rules of Civil Procedure, preservation and discovery. | Per the discovery plan and any preservation order. | Breach touches a filed or contemplated claim. |
The College row is the one clinic owners miss. It turns on what you do about the staff member afterwards, and the 30 days run from that employment event, not from discovery. The CPSO reporting policy sits on top.
The 15-minute incident triage
- Confirm discovery. Date and time, plus who reported it and the facts as stated, in one dated note. The Commissioner will ask when you knew and what you knew.
- Assess scope. Records involved, patients affected and sensitivity. Then the suspected cause, and whether the information is still exposed.
- Preserve. Freeze the logs, the screenshots, the mail and the record audit trails. Isolate a suspect device from the network rather than wiping it.
- Call the contact person. PHIPA s.15(2) requires a custodian that is not a natural person to designate one, and s.15(3) makes that person your file owner and the Commissioner’s point of contact.
Confirmation precedes preservation because the dated note starts the clock you are measured against. Preservation precedes the call because a snooping incident can self-erase while the phone rings. Quarterly drillers finish in under 10 minutes.
Documentation requirements: what the IPC will ask for
The Ontario submission asks for 9 things: discovery date, nature and scope, cause where known, patients affected, sensitivity, containment, notification, prevention, and any third party. A clinic that ran the triage already holds 8 of them.
Speed of assembly is itself evidence. A clinic answering inside 48 hours with a complete package is read differently from one answering in two weeks.
PHIPA, cyber-insurance, and the CMPA-equivalent claims layer
Late notice is the layer that kills coverage outright. Well before an incident, the contact person should hold the policy number and the carrier breach hotline in the same Ontario clinic folder as the 30-day deadline and the IPC contact details.
CMPA files are opened by the affected physician directly, so a clinic owner cannot open one on a member’s behalf. Pull the vendor contract on Day 1 too, because most Ontario record agreements set a vendor-to-custodian window that runs without a reminder.
Of our clients that missed a layer, it was almost always the insurer. Owners notify the Commissioner and the patients, settle into the response, then call the broker on Day 50 to learn the policy required notice by Day 30. One late notice cost about CA$24,000 in defence costs.
Audit your notification gaps with Mike Pearlstein, CISSP →
Common breach categories Ontario clinics face: the 4-don’t list
- Don’t misdirect faxes. Misdirected or lost information opened 209 files in 2024. Move referrals to a verified electronic channel where the receiving practice supports one, and log a confirmation step for the faxes that remain.
- Don’t let staff snoop. Snooping led at 248 files and is the category most likely to engage both s.6.3(1) item 1 and the 30-day College notice under s.17.1(2). Audit-log review plus a written termination policy is the fix.
- Don’t leave a laptop unencrypted. A stolen unencrypted device is near-automatic IPC territory. Whole-disk encryption and device management cost nothing extra in a Microsoft 365 Business Premium tenant.
- Don’t skip MFA on the record system. PHIPA never says “multi-factor”, so nobody can cite you a section. It is still the highest-yield control we deploy, and the one most often missing when a clinic arrives.
The 60-day timeline (Day 0 to Day 60)
| Day. | Milestone. | Owner. | Evidence captured. |
|---|---|---|---|
| Day 0. | Discovery, triage, containment. Contact person opens the file. | Contact person and owner. | Discovery note. Containment screenshots. Access logs frozen. |
| Day 1. | Scope assessment. Notify insurer and record vendor. Engage counsel and forensics. | Contact person, counsel, provider. | Scope memo. Claim number. Vendor case number. |
| Day 3. | Forensic snapshot done. Affected list final. Section 6.3(1) assessment recorded. | Provider and contact person. | Forensic report. Affected roster. Trigger memo. |
| Day 7. | Patient letters drafted with the Part VI complaint sentence. IPC submission drafted. College duty decided. | Contact person and counsel. | Letter template. Draft submission. College decision memo. |
| Day 14. | Patient notices sent. IPC notice filed where triggered. Media lines queued. | Contact person and owner. | Sent-letter log. IPC acknowledgement. Talking points. |
| Day 30. | Remediation complete. Audit-log review embedded. Any s.17.1(2) College notice sent. | Contact person and provider. | Remediation plan. Updated runbook. College letter. |
| Day 60. | Closure memo. Ledger entry for the March 1 statistical report. Debrief. | Contact person, owner, counsel. | Closure memo. Ledger entry. Debrief notes. |
The closure memo is what you hand a successor contact person or new counsel, and what the Commissioner reads if a second incident lands. It also feeds the March 1 filing, so 3 incidents on this template file in half an hour.
“When the IPC investigator called, we sent the closure memo by email inside 90 minutes. She had three follow-up questions on a 30-minute call the next day, and the file closed two weeks later. She told me the average for a clinic our size is a six-month back-and-forth.”
Clinic administrator, 5-physician family practice, Mississauga. Anonymized, PHIPA breach Q4 2025.
Field note from Mike
A 5-physician family practice in Mississauga lost an unencrypted laptop on a Friday evening in Q4 2025. It held cached records for roughly 280 patients, 12 of them mental-health files. The owner phoned at 7:14 p.m.
We ran the triage that night and were done by 7:48 p.m. The s.12(3) notice went in on the Tuesday and the letters went out that week. The file closed on Day 47. The clinic had never tabletopped the scenario, so we put it on the annual schedule.
Field note from Mike
The costliest habit we see in Ontario clinics is waiting for certainty. A Hamilton walk-in group held patient letters for three weeks while its vendor finished a scope report, on the theory that a precise number beat an early one.
PHIPA does not ask for precision at first contact. It asks for notice at the first reasonable opportunity, and a follow-up carrying the final count reads better than one late letter.
What changes if the breach intersects litigation or a CPSO complaint
The second is a live College complaint against the physician whose conduct caused the incident. A clinic owner who is also that physician should get independent counsel first, and should sequence the College and IPC submissions with that lawyer.
Cross-border adds a third layer. A United States hosted record add-on or scribe pulls the incident into CLOUD Act exposure and switches on the federal regime.
Map every regulator that touches your clinic stack →
Where this SOP connects to the rest of the clinic security guide
The Ontario ransomware version is our ransomware playbook for FHO clinics. The billing-data version is the OHIP billing data-security checklist. The AI governance version is our IPC AI-healthcare checklist walkthrough, alongside CPSO expectations for AI disclosure to patients. The stack behind it sits at our cybersecurity services overview.
The parent document for this cluster is the PHIPA-compliant AI playbook for Ontario clinics, and the practice-wide view is on our healthcare IT page.
Frequently asked questions
Does PHIPA actually impose a 60-day deadline?
No. “60 days” appears once in PHIPA, at s.74(3), governing a ministerial comment period. Patient notice is due at the first reasonable opportunity under s.12(2)(a). The 60-day window is the Fusion Computing operating standard used in this SOP, and runbook-equipped clinics close their files in about 19 business days.
Which prescribed circumstances trigger IPC notification under PHIPA?
Seven, at O. Reg. 329/04 s.6.3(1): unauthorized use or disclosure by someone who knew better, theft, further use after a loss, a pattern of similar events, 2 College-notice situations under s.17.1, and any loss the custodian judges significant.
When must a clinic file its annual statistical report with the IPC?
On or before March 1, under O. Reg. 329/04 s.6.4(1). It counts every theft, loss, unauthorized use, unauthorized disclosure, and unauthorized record-system collection from the prior year, not only incidents that triggered s.12(3) notice.
Does every PHIPA breach require notifying the patient?
Yes. Section 12(2) covers any theft, loss, or unauthorized use or disclosure, with no de-minimis floor. The 1 statutory exception, s.12(4), covers a researcher who received records under s.44(1). O. Reg. 329/04 s.18.9 adds a narrow record-system exemption.
When does a PHIPA breach become a CPSO matter?
PHIPA s.17.1(2) requires written College notice inside 30 days where an employed member is terminated, suspended, disciplined, or resigns over records conduct. CPSO reporting policy engages separately for professional misconduct, incompetence, or incapacity.
How does PIPEDA fit alongside PHIPA when a breach involves data outside Ontario?
PHIPA covers records in an Ontario custodian’s control. PIPEDA covers personal information handled in commercial activity, including clinic data sent to a United States hosted provider. 1 add-on can engage both, and federal reporting turns on real risk of significant harm.
What records do we need to keep about a breach we decided not to report?
Keep a file on every incident, including those below the s.12(3) threshold: discovery date, scope, sensitivity, your analysis of the 7 prescribed circumstances, and containment. Unreported events still feed the March 1 statistical report.
Should a clinic call the police before notifying the IPC?
File the report where a theft or criminal act is involved, then notify in parallel. PHIPA has no law-enforcement deferral, so a police request does not suspend the s.12(2)(a) duty or the s.6.3(3) duty. Record the case number.
What happens if we miss the cyber-insurance notification window?
Most policies treat late notice as a coverage-killer. A clinic that notifies the Commissioner and its patients but misses the carrier window, typically 30 or 60 days, can lose defence and indemnity. Notify on Day 1, not Day 50.
Does a breach by an EMR vendor become the clinic’s notification responsibility?
Yes. The custodian stays accountable for records handled by an agent, and PHIPA s.17(4)(b) requires that agent to notify the custodian at the first reasonable opportunity. Enforce the contractual notice clause too.
Who in the clinic should be designated as the privacy officer?
PHIPA s.15(2) requires a custodian that is not a natural person to designate a contact person, and s.15(3) lists the 5 functions that person performs. In a 4 to 6 physician practice it is usually the administrator.
How often should a clinic tabletop the breach response?
Annually at minimum, quarterly at 3 or more physicians or with a higher-sensitivity caseload. Run a real scenario through the triage, the Day 0 to Day 60 sequence, and the closure memo. Quarterly drillers close 30 to 50 percent faster.
Bottom line
PHIPA names the obligations and leaves the cadence to you, which is why the 60-day myth spread so easily. Decide what Day 0 through Day 60 looks like before an incident. Keep the 30-day College clock and the March 1 filing on one calendar. Then ask Mike Pearlstein, CISSP, to pressure-test the runbook while nothing is on fire.

