Privacy and safety

PHIPA and clinical AI vendors: questions Ontario practices should ask

A vendor's security page or compliance label cannot establish a practice's PHIPA compliance. The health information custodian should understand the purpose, authority, data flow, service-provider relationship, safeguards, access and correction, retention, breach response, and evidence supporting every answer.

Reading time
3 minutes
Updated
01

Accountability and authority

Start with the workflow, not the vendor questionnaire. A tool used only to draft a note has a different purpose from one used to train models, analyze workforce performance, or contact patients. Do not let a broad contract clause silently expand the intended use.

  • Who is the health information custodian and who is the vendor acting for?
  • What PHIPA authority and consent support each collection, use, and disclosure?
  • Is the purpose necessary, appropriate, and documented?
  • Who is accountable inside the practice and at the vendor?
  • Has the organization completed the privacy impact assessment and other reviews it requires?
02

Information flow and minimization

Ask for a diagram and a written subprocessor list, then compare them with network, contract, privacy, and product documentation. “Encrypted” or “hosted in Canada” would answer only part of the lifecycle even when verified.

  • What information enters the service: audio, transcript, note, identifiers, context, metadata, logs, and support data?
  • Where is each form processed, stored, backed up, and accessed?
  • Which subprocessors or model providers receive it, and for what purpose?
  • Can the service or its providers use it for model training or product improvement?
  • Can the practice configure or enforce minimum-necessary collection?
03

Access, safeguards, and auditability

  • Does the product support unique accounts, role-based access, two-factor authentication, and timely offboarding?
  • How are data encrypted in transit and at rest, and how are keys and secrets managed?
  • What administrative access can vendor personnel obtain, and how is it approved and logged?
  • Which material user and administrative events appear in an audit history?
  • How are vulnerabilities, secure development, independent assurance, and incidents managed?
04

Access, correction, retention, and disposal

Keeping information indefinitely “just in case” increases exposure. Deleting too early can conflict with record obligations. The organization should instruct the vendor based on an approved retention schedule and understand technical exceptions.

  • Can the custodian locate and provide the relevant information for an access request?
  • How can inaccurate information be corrected while preserving required record history?
  • Which retention periods apply to audio, transcripts, drafts, finalized material, logs, and backups?
  • What is deleted on request, account closure, or contract termination, and what remains?
  • Can the vendor provide evidence of secure return or destruction?
05

Breach readiness and change management

  • How quickly must the vendor notify the custodian of a suspected incident?
  • What information and cooperation will the vendor provide for containment, assessment, notification, and reporting?
  • How are security events preserved without exposing additional patient information?
  • How much notice is provided before material changes to models, purposes, terms, or subprocessors?
  • Can the practice suspend use or exit safely if the risk changes?

Sources and further reading

Sources were checked on . External guidance can change; open the source before relying on it.

  1. Personal Health Information Protection Act, 2004Government of Ontario
  2. Privacy Management Handbook for Small Health Care OrganizationsInformation and Privacy Commissioner of Ontario
  3. Privacy Impact Assessment Guidelines for PHIPAInformation and Privacy Commissioner of Ontario

Next

Security checklist for AI clinical documentation toolsEvaluate identity, access, encryption, vendors, secure development, monitoring, incident response, retention, and recovery before using clinical documentation software.3 minPatient consent for AI scribes in OntarioWhat Ontario practices should explain, document, and prepare when asking a patient to consent to AI-assisted encounter capture.3 minAI-assisted clinical documentation in Ontario: an adoption guideA practical guide to evaluating and introducing an AI scribe or documentation assistant in an Ontario healthcare practice.3 min

Ready to see the workflow?

Keep consent, review, and follow-through in one place.

Create workspace Review plans