Ransomware Playbook for a 4-Physician FHO Clinic (PHIPA + CPSO Edition, 2026)

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Building and managing secure IT for Canadian businesses since 2012 across Toronto, Hamilton, and Metro Vancouver.

Note: the clinic below is a composite drawn from Fusion Computing engagements with several Ontario family practices. Identifiers have been changed. The timeline and the recovery numbers are real.

The text message landed at 7:04 on a Monday. The office manager of a four-physician Family Health Organization clinic in west-end Toronto had opened up to find three front-desk workstations stuck on a black screen with red lettering.

The EMR was unreachable and the first patient was booked for 8:30. She did not know whether to send everyone home, and she did not know whether she was allowed to. The first ten minutes were not about the ransomware. They were about stopping the next twenty staff actions from making the legal exposure worse than the encryption already had.

I am an MSP, not a lawyer. The patient-notification wording belongs with your privacy counsel. The first sixty minutes, the evidence preservation, the PHIPA math, and the recovery sequence are mine to write.

Key takeaways

  • PHIPA sets no 60-day clock. Section 12(2)(a) requires notice “at the first reasonable opportunity”. The 60-day figure is imported from United States HIPAA rules.
  • The Commissioner trigger is a separate duty. Ontario Regulation 329/04 section 6.3(1) lists seven circumstances. Clinic ransomware normally clears trigger 2, theft, on day one.
  • Isolate, do not power off. Keeping an encrypted device powered preserves memory-resident forensic evidence, per Canadian Centre for Cyber Security guidance.
  • Backup-first recovery inside 72 hours is achievable for a four-physician clinic when immutable offline copies exist. Without them, downtime runs into weeks.
  • The artefact that decides outcome is a written incident response plan tested in the last 12 months, which is evidence of reasonable steps under section 12(1).

Book a Clinic IT Consultation

This piece sits inside the longer PHIPA-compliant AI playbook for Ontario clinics. It assumes you already accept that your EMR, your scribe vendor, and your billing add-ons are in scope the moment an attacker reaches your network.

What a clinic ransomware morning looks like at 7am, explained

According to the Canadian Centre for Cyber Security (2024), ITSAP.00.099 treats ransomware as a service-disruption event, not only a data event. That framing matters in family medicine, where the loss is the afternoon clinic list rather than a database. The Cyber Centre scopes its national ransomware warnings to Canadian critical infrastructure, and health care sits inside that definition.

The owner had been picturing something cinematic. A skull on a monitor, a countdown, a stranger demanding crypto. What a west-end Toronto family practice actually got was duller and more dangerous.

Three workstations sat at a generic Windows ransom page. The EMR server showed a flashing amber light. The fax modem, because family medicine still runs a fax modem, was rebooting in a loop. The dental clinic sharing the floor was untouched because it ran its own network, and that single boundary saved their morning.

The 8:30 was an INR draw, which does not wait the way an annual physical does. The 9:00 was a same-day child with a suspected ear infection. The 9:15 was a biopsy result one physician needed to deliver in person.

Across our 40 Canadian client environments in regulated sectors, the first call almost always wants to be wrong. Owners phone the EMR vendor. TELUS PS Suite, OSCAR Pro, Accuro and Med Access all run software help desks, not cyber incident response teams.

The right first call is your MSP. Failing that, the Cyber Centre operates an incident reporting line and the Canadian Anti-Fraud Centre is second.

If your clinic has no named IT incident contact in writing, fix that this week.

When does the PHIPA breach clock start, and what does section 12 require?

According to the Personal Health Information Protection Act, 2004 (2026 consolidation), section 12(2)(a) requires a custodian to notify the affected individual “at the first reasonable opportunity”. The Act fixes no day count anywhere. Section 12(1) is the reasonable-steps safeguards duty, and section 12(3) is what pushes the file to the Commissioner once the prescribed circumstances are met.

[REGULATOR QUOTE]

Notify the individual at the first reasonable opportunity of the theft or loss or of the unauthorized use or disclosure.

Personal Health Information Protection Act, 2004, section 12(2)(a), read from the Ontario e-Laws consolidation.

The owner asked me at 7:31 whether the clock had started. It had, and not from that conversation. It ran from the moment encryption began on the EMR server, which the logs later placed at 2:47am.

The 60-day figure is not law. It is a HIPAA number that migrated north through vendor marketing and template privacy binders. Fusion Computing runs a 60-day window as its own internal standard, and says so plainly. A clinic that treats it as the statutory deadline has inverted the risk, because PHIPA can require notice far sooner than day 60.

The harder half of section 12(2) is the awareness question. It is the earliest point at which a competent technical observer should have caught the indicator, which for ransomware is usually hours before the lock screen appears, while the attacker moves laterally and disables backups.

  • Patient notice. PHIPA section 12(2)(a), at the first reasonable opportunity, with a statement of the right to complain to the Commissioner.
  • Commissioner notice. PHIPA section 12(3) as prescribed by Ontario Regulation 329/04 section 6.3(1).
  • College notice. PHIPA section 17.1(2), within 30 days, and only where an employed practitioner is terminated, suspended, disciplined or resigns over a privacy event.

The only fixed day count in that chain is the 30 days in section 17.1(2), and it runs from the employment event rather than from the breach. Our PHIPA breach notification SOP for Ontario clinics walks the letter templates and the IPC reporting form field by field.

The first 60 minutes: the containment checklist, and what not to power off

According to the Cyber Centre’s ITSAP.00.099 (2024), isolate the device but leave it powered. That preserves the forensic evidence. Pulling network cables, disabling Wi-Fi and shutting switch ports stops lateral movement while keeping memory artefacts that ransom payloads hold only in RAM.

THE FIRST 60 MINUTES: ARTEFACT FOR THE SUPPLY CLOSET DOOR

  1. Minute 0 to 10. Photograph every ransom screen, including wallet address and ransom amount. A phone camera is fine. Click nothing.
  2. Minute 10 to 20. Pull network cables from affected workstations and the EMR server. Disable Wi-Fi. Power off nothing. Lock the server-rack door.
  3. Minute 20 to 30. Call the named IT incident contact and the insurer breach hotline. The policy number lives on the declarations page, which must exist outside email.
  4. Minute 30 to 45. Identify clinically time-sensitive patients on today’s list from the paper ledger. INR draws, biopsies, prenatal visits, suspected acute conditions.
  5. Minute 45 to 60. Decide whether the clinic opens, runs paper-only, or closes. Give reception a written script saying “a technical disruption affecting our scheduling system”, not “ransomware”.

Source: Fusion Computing field protocol, adapted from CCCS ITSAP.00.099 and IPC Ontario breach guidance.

The do-not-power-off rule is the one clinic owners argue with me about, and the instinct to shut everything down is operationally wrong. Encryption keys held in RAM, malware fragments and the timestamps that establish when a reasonable person should have known all evaporate on a hard power-off. Our engineers found on two Ontario engagements that powering down before isolation cost the clinic its ability to prove no data left the building.

How long do you have? The five notification clocks

According to Ontario Regulation 329/04 (2026 consolidation), section 6.3(1) prescribes seven circumstances that require notice to the Commissioner. Theft is trigger 2. Onward use or disclosure after an initial loss is trigger 3. A significance assessment covering sensitivity, volume and number of individuals is trigger 7. Section 224/17 inserted the whole provision in 2017.

Five clocks run in parallel after an Ontario clinic ransomware event, and only one of them is fixed by statute.

  • Patients. PHIPA section 12(2)(a), first reasonable opportunity. Fusion Computing holds itself to a 60-day operating ceiling as a practice standard, not a legal one.
  • The Commissioner. Ontario Regulation 329/04 section 6.3(1), where any of the seven triggers is met.
  • The College. PHIPA section 17.1(2), within 30 days, on the employment events described in that section.
  • CMPA. Each physician calls personally, because every member holds their own file.
  • Cyber insurer. Typically 24 to 72 hours under Canadian policies, and usually the tightest of the five.

There is a sixth filing most owners have never heard of. Ontario Regulation 329/04 section 6.4(1) requires an annual report to the Commissioner on or before March 1, counting every theft, loss, unauthorized use, unauthorized disclosure, and unauthorized electronic-health-record collection from the previous year. That count covers more than the breaches that triggered a section 12(3) report.

[FIELD NOTE]

Across four Ontario clinic ransomware engagements between 2022 and 2026, three had no cyber-insurance declarations page reachable outside email. In two of those, the owner could not produce the policy number in the first 60 minutes because the mailbox was encrypted.

We now ask every healthcare client to tape a printed declarations page and breach-hotline number inside the supply-closet door. It is the cheapest change we make on these engagements.

Mike Pearlstein, CISSP, lead on Fusion Computing healthcare engagements since 2018.

Letter content has a floor. Canadian privacy counsel use the six elements set out by the Office of the Privacy Commissioner of Canada (2018): circumstances, period, information type, what the clinic did, what the patient can do, and who to contact. We will review your notification stack against all five clocks.

Restore versus ransom: the backup-first recovery protocol

According to Statistics Canada (2024), 16% of Canadian businesses were hit by a cyber incident in 2023. Large businesses fared worst at 30%. Small clinics are not the primary target set, which is why so many still run flat networks and untested backups.

This Ontario clinic had one piece of luck. Six months earlier it had moved to a managed immutable backup platform with daily offline cloud copies, after Fusion Computing pushed for it during a quarterly review. The attacker encrypted the endpoints but could not delete or alter those copies, because immutability locks the API path ransom payloads use to scrub backups first.

Clinic ransomware downtime with and without immutable backups. A four-physician Ontario clinic restored full clinical service in about 76 hours with immutable offline backups. Comparable Ontario clinics without them ran on paper for 11 to 21 days. CLINICAL DOWNTIME, ONTARIO FAMILY PRACTICE. 76 hours, immutable backups in place. 11 to 21 days, no immutable backups. Source: Fusion Computing incident-response cohort, three Ontario clinic recoveries, 2025 to 2026.

We measured the recovery in three overlapping tracks.

  • Track 1, forensic image. Bit-for-bit captures of the EMR server, the three locked workstations and the fax appliance, taken before any restore, with a copy to privacy counsel under privilege.
  • Track 2, clean rebuild. A new EMR host in the clinic’s Azure tenant, the previous Friday’s immutable snapshot restored into it, vendor patches applied, every directory credential rotated.
  • Track 3, vector remediation. The fax appliance retired for a cloud fax service with no public-internet listener, and the flat network segmented into clinical, administrative and guest VLANs.

The clinic ran on paper from 7:30 Monday to noon Thursday, roughly 76 hours. The ransom was 1.8 BTC and the clinic did not pay. All-in cost, including our time, forensics, hardware, counsel and lost clinical revenue, was about CA$187,000, of which the cyber policy covered roughly CA$124,000.

We thought paying the ransom would be the fastest path back to seeing patients on Wednesday. The backup-first protocol felt slower in the moment, but we had every chart back, every prescription queue intact, and a clean letter to the Commissioner inside 48 hours. We never touched the bitcoin wallet.

Clinic owner, four-physician FHO family practice, Greater Toronto Area, anonymized for PHIPA.

What is a clinic incident response plan, and what goes in it?

According to the Ontario Medical Association (2026), member cybersecurity guidance treats written incident procedures and tested backups as baseline practice management, not an IT specialism. The plan is what turns PHIPA section 12(1) reasonable steps into something an owner can hand a regulator.

The clinic here had a one-paragraph plan buried in a privacy binder. It said the clinic would respond appropriately to security incidents in accordance with applicable law, which is a sentence rather than a plan under PHIPA section 12(1). The replacement runs to 4 printed pages and reads as a series of decisions made before they had to be made.

  • Page 1. The first-hour checklist with numbers filled in: MSP after-hours line, insurer breach hotline, Cyber Centre reporting line, privacy counsel mobile, CMPA member services, and the landlord.
  • Page 2. The clock matrix: patients at first reasonable opportunity, Commissioner under Regulation 329/04 section 6.3, College within 30 days where section 17.1 applies, CMPA per physician, insurer 24 to 72 hours.
  • Page 3. The patient phone script and the staff communication template.
  • Page 4. The annual tabletop log: date, scenario, gaps found, fixes assigned.

The highest-impact item is the tabletop itself. A 2-hour drill with the office manager, the physicians and the MSP, run against a written scenario, surfaces most of the plan’s gaps before they cost anything. In our experience it costs less than one billable physician half-day.

For the 8-control hardening layer underneath the plan, covering EMR access control, billing-data segmentation, MFA enforcement and backup verification, read the OHIP billing data security clinic owner checklist.

Which four clinic-owner conversations decide the outcome?

According to the College of Physicians and Surgeons of Ontario (2026), the Medical Records Documentation policy treats record accuracy, completeness and accessibility as a continuing physician duty. A multi-day EMR outage interrupts all three, which is why the College conversation belongs in week one.

Day three is decided less by technical work than by four conversations the owner runs.

  • The partners. Ransom-decision authority. Family Health Organization governance means this cannot be a single-partner call, and delaying it is the largest driver of avoidable letter-scope creep.
  • The office manager. The patient phone script. Short, factual, pointing at the letter that will follow.
  • The insurer breach coach. Scope, agreed before forensic costs accrue.
  • The referring network. The top fifteen specialists, plus lab, imaging and pharmacy, all of whom were receiving faxes that are about to stop.

The script is the thing Ontario clinic owners get wrong most often. Saying nothing and over-explaining are both mistakes. This practice used: “We are experiencing a technical disruption affecting our scheduling system. Your appointment is being rescheduled. If your visit is time-sensitive, tell me and we will arrange same-day care.”

The referring-specialist note was one line, sent Monday afternoon, and it prevented a week of confused calls. The CMPA Electronic records handbook is the companion reading on eRecord obligations and EMR contract terms.

If your clinic has never written a patient-facing incident script, write it before you need it.

Fusion Computing builds the operational half of clinic security for Ontario family practices: incident response, EMR hardening, PHIPA-aligned backup architecture, and the annual drill. For the non-clinical picture, see our PIPEDA compliance guide for Canadian small business.

Bottom line

An Ontario family practice can survive ransomware without paying, without losing charts, and without a regulator action. Five things must exist before the morning it hits.

  • Immutable offline backups verified inside 90 days.
  • A written plan tested inside 12 months.
  • A named after-hours IT contact.
  • A printed insurance declarations page.
  • A settled partnership decision on ransom authority.

Talk to Fusion Computing

FAQ

Does PHIPA set a 60-day breach notification deadline?

No. Section 12(2)(a) requires notice at the first reasonable opportunity, and the Act fixes no day count. The 60-day figure comes from United States HIPAA rules. Fusion Computing runs a 60-day internal ceiling as an operating standard, which is a practice choice rather than a legal one.

When does a clinic have to notify the Information and Privacy Commissioner?

Ontario Regulation 329/04 section 6.3(1) prescribes seven circumstances for the section 12(3) duty. Theft is trigger 2, onward unauthorized use after an initial loss is trigger 3, and a significance assessment weighing sensitivity and volume is trigger 7. Most clinic ransomware clears one on day one.

Should I power off a workstation showing a ransom note?

No. Cyber Centre guidance in ITSAP.00.099 is to isolate by pulling cables and disabling Wi-Fi while leaving the device powered. A hard power-off destroys memory-resident evidence, including encryption keys and the artefacts that decide whether data was exfiltrated.

Do I have to report a ransomware incident to CPSO?

PHIPA section 17.1(2) requires written notice to a College within 30 days, but only where an employed practitioner is terminated, suspended, disciplined, or resigns over a privacy event. Ransomware alone does not trigger it. Where records were unavailable and care was affected, a member-services call inside week one is still the right move.

Should a clinic pay the ransom?

Cyber Centre and RCMP guidance both advise against payment. It does not guarantee key recovery, does not stop a double-extortion leak, and signals that the clinic will pay again. With immutable offline backups verified inside 90 days, recovery without payment is achievable inside 72 hours.

How much does a four-physician clinic ransomware incident cost?

In the engagement described here the all-in figure was about CA$187,000, of which roughly CA$124,000 was covered by cyber insurance and about CA$63,000 came out of pocket. Without immutable backups the same event costs far more, driven by lost clinical revenue across an 11-to-21-day recovery.

Does PHIPA require multi-factor authentication?

Not by name. Neither PHIPA nor Ontario Regulation 329/04 contains the words multi-factor or two-factor. The hook is section 12(1), reasonable steps. In 2026 a clinic running EMR and email without MFA will struggle to argue its steps were reasonable, and most cyber insurers make it a condition of cover.

What is the annual March 1 report every Ontario clinic owes?

Ontario Regulation 329/04 section 6.4(1) requires every custodian to give the Commissioner, on or before March 1, a count of each theft, loss, unauthorized use, unauthorized disclosure, and unauthorized electronic-health-record collection from the previous year. It covers all such events, not only reported ones.

What should a clinic ask an MSP before an incident happens?

Ask four things. Who answers the after-hours line, and inside what window. Whether backups are immutable, and when the last restore test ran. Whether the MSP will sit in a tabletop drill with your physicians. And whether they will speak directly to your cyber insurer and privacy counsel during an incident. Fusion Computing answers all four in writing.

How much does clinic-grade IT security cost in Ontario?

Managed cybersecurity for a small Ontario clinic runs CA$180 to CA$250+ per user per month, depending on endpoint count, EMR hosting model, and whether the clinic needs monitored detection around the clock. Full managed IT with that security layer included starts at CA$180 per user per month.

Further reading and primary sources

[ORIGINAL DATA] HOW THIS GUIDANCE WAS ASSEMBLED.

This article draws on Fusion Computing anonymized client data from Ontario clinic engagements between 2022 and 2026, plus an FC internal benchmark covering breach SOP rollout and backup verification. Statutory text was read from the Ontario e-Laws consolidations of PHIPA and Ontario Regulation 329/04, not from secondary guidance, and layered over it is first-person field observation from CEO Mike Pearlstein, CISSP.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611