Electronic Health Record Agreements with Health Information Custodians and Coroners Policy and Procedures

Policy Level Approval: Chief Executive Officer

Policy Category: Enterprise Policy

Policy Number: INF-010.02-PP

Policy Sponsor (or Sponsors): Chief, Strategy, Planning, Privacy & Analytics

Original Date of Approval: November 11, 2021

Date of Posting: May 15, 2026

Version Approval Date: April 9, 2026

1. Purpose, Objectives and Scope

1.1 Purpose

1.1.1 This Policy and its procedures establish the process to be followed with respect to agreements with Health Information Custodians (HICs) and Coroners who provide Personal Health Information (PHI) to the Electronic Health Record (EHR) or Collect PHI by means of the EHR developed or maintained by Ontario Health as a Prescribed Organization (PO).

1.2 Objectives

1.2.1 To enable Ontario Health to comply with the Personal Health Information Protection Act, 2004 (PHIPA) and the requirements set out in the Information and Privacy Commissioner of Ontario’s (IPC) Manual for the Review and Approval of Prescribed Organizations (IPC PO Manual) with respect to agreements with HICs and Coroners who provide PHI to the EHR or collect PHI by means of the EHR developed or maintained by Ontario Health as a PO.

1.3 Scope

1.3.1 This Policy applies to Ontario Health in its capacity as a PO.

1.3.2 This Policy applies to non-union Employees, people leaders, board members, unionized Employees, secondees, consultants, other individuals acting on behalf of Ontario Health (Ontario Health Agents).

1.4 Compliance, Audit and Enforcement

1.4.1 Compliance with this Policy in its entirety is mandatory unless an exception to a specific section is approved by the Chief Privacy Officer (CPO) or delegate in writing. Failure to comply with the requirements of this Policy, without a written exception, may result in disciplinary action up to and including revocation of appointment, termination of employment or termination of contract without notice or compensation.

1.4.2 Compliance will be audited in accordance with and as per the frequency outlined in the Privacy Audit and Compliance Policy.

1.4.3 At the first reasonable opportunity upon identifying or becoming aware of a breach of this Policy, Employees and other Ontario Health Agents, must notify Ontario Health’s Privacy Office by reporting the breach to the Enterprise Service Desk by Phone: 1-866-250-1554; or Email: oh-servicedesk@ontariohealth.ca

1.4.4 Breaches of this Policy will be managed in accordance with the Privacy Incident Management Policy and Procedure.

1.4.5 Compliance will be enforced in accordance with the Progressive Discipline Policy.

1.5 Terminology

1.5.1 The words “include” and “including” when used are not intended to be exclusive and mean, respectively, “include, without limitation,” and “including, but not limited to”.

1.5.2 Words and terms in this Policy that have meanings differing from the commonly accepted definitions are capitalized and their meanings are set out in the Definition and Acronyms section (Section 5).

2. Policy for Agreements with HICs and Coroners

2.1 Requirement for Agreements with HICs and Coroners

2.1.1 Ontario Health must ensure that the HIC and Coroner under whose authority PHI is provided to the EHR or collected by means of the EHR acknowledges and agrees to comply with the relevant Ontario Health contributor or access services agreement that addresses the matters set out in the IPC PO Manual with respect to End User agreements.

2.2 End Users

2.2.1 The agreement between Ontario Health and the HIC or Coroner must require the HIC or Coroner under whose authority PHI is provided to the EHR or collected by means of the EHR to ensure the compliance of each of its agents (End Users) with the terms of the agreement.

2.3 Timing of Agreements

2.3.1 At a minimum, each HIC and Coroner under whose authority PHI is provided to the EHR or collected by means of the EHR must acknowledge and agree to comply with the relevant Ontario Health contributor or access services agreement prior to providing PHI to the EHR or collecting PHI via the EHR for the first time.

2.4 Content of the Agreement

2.4.1 The agreement between Ontario Health and the HIC or Coroner under whose authority PHI will be provided to the EHR or collected by means of the EHR must address the matters set out in Appendix “A” to this Policy.

3. Process

3.1 Agreements with HICs and Coroners under whose authority PHI will be provided to the EHR or collected by means of the EHR

3.1.1 Legal Services, in consultation with Privacy, is responsible for ensuring that the Ontario Health contributor or access services agreement addresses the matters set out in Appendix “A” to this Policy.

3.1.2 The Director, Account Management, Digital Excellence in Health Portfolio is responsible for ensuring that each HIC or Coroner under whose authority PHI will be provided to the EHR or collected by means of the EHR acknowledges and agrees to comply with the relevant OH contributor or access services agreement that addresses the matters set out in the IPC PO Manual with respect to End User agreements.

3.1.3 The Director, Account Management, Digital Excellence in Health Portfolio or delegate is responsible for providing the HIC or Coroner with a Client Information Form (CIF) which the HIC or Coroner must complete and return to Account Management. The CIF requires the organization to confirm its authority to provide PHI to the EHR or collect PHI by means of the EHR as a HIC or Coroner pursuant to PHIPA.

3.1.4 Upon receipt of the CIF, the Director, Account Management, Digital Excellence in Health Portfolio or delegate is responsible for reviewing the CIF to ensure it is complete and using the information provided by the HIC or Coroner to prepare the relevant contributor or access services agreements for execution by OH and the HIC or Coroner. The Director, Account Management, Digital Excellence in Health Portfolio is responsible for engaging Legal Services and Privacy to advise on the appropriate form of the agreement and whether any agreements require replacement.

3.1.5 The Senior Vice-President, Digital Health Data and Services, or the Digital Excellence in Health Portfolio Executive, as applicable, is responsible for signing the relevant contributor or access services agreement on behalf of Ontario Health.

3.1.6 Prior to enabling the HIC or Coroner and their respective agents to provide PHI to the EHR or collect PHI by means of the EHR, the Director, Account Management, Digital Excellence in Health Portfolio must ensure that the HIC or Coroner under whose authority PHI will be provided or collected has signed the relevant Ontario Health contributor or access services agreement.

3.1.7 The Director, Account Management, Digital Excellence in Health Portfolio or delegate is responsible for logging each agreement in accordance with the requirements set out in Appendix “B” to this Policy.

3.2 Tracking Agreements with HICs and Coroners under whose authority PHI will be provided to the EHR or collected by means of the EHR

3.2.1 The Director, Account Management, Digital Excellence in Health Portfolio or delegate is responsible for:

  • Identifying HICs and Coroners who will be providing PHI to the EHR or collecting PHI by means of the EHR who have not acknowledged and agreed to comply with the relevant Ontario Health contributor or access services agreements and ensuring that the HIC or Coroner does so as soon as reasonably possible;
  • Following the procedure identified in section 3.1 where a HIC or Coroner has not signed the relevant Ontario Health contributor or access services agreement; and
  • Logging and tracking each executed agreement and maintaining the accuracy of the log of all agreements acknowledged and agreed to by HICs and Coroners under whose authority PHI will be provided to the EHR or collected by means of the EHR in accordance with the requirements set out in Appendix “B”.

3.3 Retention

3.3.1 The Director, Account Management, Digital Excellence in Health Portfolio is responsible for ensuring that agreements with HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR are retained by Ontario Health in accordance with the EHR Retention Policy.

3.3.2 The Director, Account Management, Digital Excellence in Health Portfolio is responsible for ensuring that Ontario Health’s log of agreements with HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR is retained by Ontario Health in accordance with the EHR Retention Policy.

3.3.3 All agreements with HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR must be retained in a secure location managed by Account Management, Digital Excellence in Health Portfolio.

3.3.4 Ontario Health’s log of agreements with HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR must be retained in a secure location managed by Account Management, Digital Excellence in Health Portfolio.

3.4 Audits of HICs and Coroners that Provide or Collect PHI by Means of the EHR

3.4.1 Ontario Health conducts audits of a subset of the HICs and Coroners that provide PHI to or collect PHI by means of the EHR to ensure compliance with the relevant Ontario Health contributor or access services agreements executed with Ontario Health. The scope, frequency and nature of such audits is determined by Ontario Health’s CPO.

3.4.2 Ontario Health may conduct an audit in the following circumstances:

  • At any time at the direction of Ontario Health’s CPO and in accordance with the scope and nature set by Ontario Health’s CPO;
  • If Ontario Health has reason to believe that the HIC or Coroner has breached the terms of the relevant Ontario Health contributor or access services agreement executed with Ontario Health;
  • If Ontario Health is notified of a Privacy Incident or Breach involving the HIC or Coroner (or one of their agents); or
  • If Ontario Health receives a privacy complaint related to the HIC or Coroner (or one of their agents).

3.4.3 Ontario Health’s CPO or delegate is responsible for designating members of the Ontario Health Privacy Office to conduct audits in accordance with this policy.

3.4.4 Where an audit indicates non-compliance with the relevant Ontario Health contributor or access services agreements, Ontario Health’s CPO is responsible for engaging Ontario Health Legal and other relevant internal stakeholders to prepare notice to the HIC or Coroner and determine the appropriate actions that should be taken by Ontario Health as a result of the HIC or Coroner’s non-compliance. Such actions shall be in accordance with the terms of the relevant OH contributor or access services agreement executed with Ontario Health.

3.4.5 Ontario Health retains documentation related to audits of HICs and Coroners in the privacy secure drive in accordance with the EHR Retention Policy.

4. Responsibilities

4.1 Director, Account Management, Digital Excellence in Health Portfolio

  • Responsible for ensuring that each HIC or Coroner under whose authority PHI will be provided to the EHR or collected by means of the EHR acknowledges and agrees to comply with the relevant Ontario Health contributor or access services agreement.
  • Responsible for identifying HICs and Coroners who will be providing PHI to the EHR or collecting PHI by means of the EHR who have not acknowledged and agreed to comply with the relevant Ontario Health contributor or access services agreements and ensuring that the HIC or Coroner does so as soon as reasonably possible.
  • Responsible for following the procedure identified in section 3.1 where a HIC or Coroner has not signed the relevant Ontario Health contributor or access services agreement.
  • Responsible for logging and tracking each executed agreement in accordance with the requirements set out in Appendix “B” to this Policy or delegating such logging to an Employee or other Ontario Health Agent.
  • Responsible for maintaining the accuracy of the log of all agreements acknowledged and agreed to by HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR in accordance with the requirements set out in Appendix “B” to this Policy.
  • Responsible for ensuring that agreements with HICs and Coroners under whose authority PHI is provided to the EHR or collected by means of the EHR and related logging are retained by Ontario Health in accordance with the EHR Retention Policy.

4.2 Employees and Other Ontario Health Agents

  • Responsible for complying with this Policy and its procedures.
  • If delegated by the Director, Account Management, Digital Excellence in Health Portfolio, Employees and other Ontario Health Agents are responsible for logging each agreement in accordance with the requirements set out in Appendix “B” to this Policy.
  • At the first reasonable opportunity upon identifying or becoming aware of a breach of this Policy, Employees and other Ontario Health Agents are responsible for notifying Ontario Health’s Privacy Office by reporting the breach to the Enterprise Service Desk.

5. Definitions and Acronyms

Defined terms are capitalized through this document

CIF: Client Information Form

Collect: Has the meaning set out in section 2 of PHIPA with respect to PHI; and in respect of PI has the same meaning.

“Collect” means to gather, acquire, receive, or obtain the information by any means from any source, and “Collection” and “Collected” has a corresponding meaning.

Coroner: Means the Chief Coroner for Ontario, a Deputy Chief Coroner for Ontario, a regional coroner or a coroner appointed under section 5 of the Coroners Act, as set out in section 1 of the Coroners Act.

CPO: Chief Privacy Officer

EHR or Electronic Health Record: Has the meaning set out in s. 55.1 of PHIPA and generally means the electronic systems that are developed and maintained by Ontario Health pursuant to Part V.1 of PHIPA for the purpose of enabling HICs to Collect, Use and Disclose PHI by means of the systems.

Employee: A person employed and compensated by Ontario Health as an Employee, and is classified as either permanent full-time, permanent part-time, temporary full-time, temporary part-time, paid student or casual, as set out in the Employee Classification Guideline. A consultant or contractor is not an Employee.

End User: An individual that provides PHI to or collects PHI by means of the EHR developed or maintained by Ontario Health as an agent of a HIC or Coroner.

HIC or Health Information Custodian: Has the meaning set out in s. 3 of PHIPA and generally means a person or organization that has custody or control of personal health information for the purpose of health care or other health-related duties. Examples include physicians, hospitals, pharmacies, laboratories and the MOH, but does not include Ontario Health.

IPC: Information and Privacy Commissioner of Ontario

IPC PO Manual: IPC Manual for the Review and Approval of Prescribed Organizations

Minister: Minister of Health

Ontario Health: The agency of the Government of Ontario to which this Policy applies.

Ontario Health Agent: A person that acts for or on behalf of OH for the purposes of OH, and not for the Agent’s own purposes, whether or not the Agent has the authority to bind OH, whether or not the Agent is employed by OH, and whether or not the Agent is being remunerated.

O. Reg. 329/04: Ontario Regulation 329/04 made under PHIPA

PHI or Personal Health Information: Has the meaning set out in section 4 of PHIPA. Specifically, it is “identifying information” in oral or recorded form about an individual that:

  • Relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family;
  • Relates to the provision of health care to the individual, including the identification of a person as a provider of health care to the individual;
  • Is a plan that sets out the home and community care services for the individual to be provided by a health service provider or Ontario Health Team pursuant to funding under section 21 of the Connecting Care Act, 2019;
  • Relates to payments or eligibility for health care or eligibility for coverage for health care in respect of the individual;
  • Relates to the donation by the individual of any body part or bodily substance of the individual or that is derived from the testing or examination of any such body part or bodily substance;
  • Is the individual’s health number;
  • Identifies an individual’s substitute decision-maker; or
  • Is the individual’s digital health identifier or other identifying information related to the creation of the digital health identifier

PHI also includes identifying information about an individual that is not PHI listed above but that is contained in a record that includes PHI listed above.

Information is “identifying” when it identifies an individual or when it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.

PHIPA or Personal Health Information Protection Act, 2004: The Ontario health privacy law. It establishes rules for the management of PHI and the protection of the confidentiality of that information, while facilitating the effective delivery of healthcare services. References to PHIPA include the regulation made thereunder, as may be amended or replaced from time to time.

Prescribed Organization or PO: The organization prescribed in Ontario Regulation 329/04 as the organization for the purposes of PHIPA. The Prescribed Organization has the power and the duty to develop and maintain the EHR in accordance with Part V.1 of PHIPA and to carry out digital health identifier activities in accordance with Part V.2 of PHIPA.

Privacy Incident: Any event where the Privacy Office is notified or becomes aware that a Privacy Breach may have occurred. This includes events that are reviewed/investigated and are:

  1. Confirmed to be a Privacy Breach;
  2. Confirmed not to be a Privacy Breach; or
  3. It cannot or has not been determined if a Privacy Breach occurred (Suspected Privacy Breach).

Note: Privacy Incidents include events involving PI and PHI, as well as De-identified Information and Business Identity Information as these events require investigation in accordance with this Policy to confirm if they are Privacy Breaches as defined below. OH shall investigate these incidents involving De-identified Data and Business Identity Information, considering factors such as the 1) risk of re-identification and related de-identification guidelines for De-identified Data, as well as 2) the context for handling data that OH received as Business Identity Information, to confirm that it does not constitute PI, respectively.

Privacy Breach: A Privacy Breach includes:

1. Privacy Breach of PHI or PI (Privacy PHI/PI Breach) means an event where:

  1. The Collection, Use or Disclosure of PHI or PI is not in compliance with PHIPA or its regulation, or with FIPPA or its regulations (i.e. without legal authority); and/or
  2. The Viewing, handling or otherwise dealing with PHI provided to OH is not in compliance with PHIPA, or its regulation;
  3. PHI or PI is stolen, lost or subject to unauthorized Collection, Use or Disclosure or where records of PHI or PI are subject to unauthorized copying, modification, or disposal.

Note: A Privacy PHI/PI Breach does not include a breach of De-identified Information, or Business Identity Information, if the event does involve PI or PHI.

2. Privacy Breach of Privacy Policy or Agreement (Privacy Policy/Agreement Breach) means an event where:

  • There is a contravention of Ontario Health’s privacy policies, procedures or practices; and/or
  • There is a contravention of a privacy-related term or condition in a:
    • data sharing agreements,
    • research agreements,
    • confidentiality agreements, or
    • agreements with third party service providers retained by Ontario Health to handle PHI or PI,
    • written acknowledgements acknowledging and agreeing not to use PHI or PI which has been de-identified and/or aggregated, to identify an individual; and
  • Does not include a privacy breach of PHI or PI

Note: A Privacy Policy/Agreement Breach may include a breach that involves De-identified Information or Business Identity Information, if the breach relates to privacy controls in an agreement or a privacy policy, procedure or practice related to handling of De-identified Information or Business Identity Information.

6. Review Cycle

This Policy is to be reviewed by Ontario Health at least within 3 years of its effective date or earlier if required in accordance with the Privacy Audit and Compliance Policy.

7. References and/or Key Implementation Documents

View references and documents

  • PHIPA and O. Reg. 329/04
  • IPC PO Manual
  • Privacy Audit and Compliance Policy
  • Privacy Incident Management Policy and Procedure
  • EHR Retention Policy

8. Appendices

  • Appendix “A”: Minimum Content Required in Agreements with HICs and Coroners under whose authority PHI is provided to or Collected by means of the EHR
  • Appendix “B”: Minimum Content Required in Logging

9. Policy Consultations

The following were consulted in the development of this Policy:

  • Staff from the Privacy Office and other OH Agents responsible for drafting, maintaining, and/or reviewing the privacy policies in reference to OH’s privacy requirements; and
  • Working Group members of the Privacy Program Advisory Committee (version 1 of the policy)

10. Policy Review History

April 2026: The policy was reviewed and updated in April 20265. It was approved on April 9, 2026, by the Ontario Health Chief Executive Officer.

Appendix A: Minimum Content required in agreements with HICs and Coroners under whose authority PHI is provided to or Collected by means of the EHR

The agreement between Ontario Health and the HIC or Coroner under whose authority PHI will be provided to or Collected by means of the EHR must address the matters set out below:

  • The purposes for which the HIC or Coroner is permitted to provide PHI to or to Collect, Use or Disclose PHI by means of the EHR;
  • Each provision, Collection, Use or Disclosure identified in the agreement must be permitted by PHIPA and its regulations;
  • The administrative, technical and physical safeguards that the HIC or Coroner and its agents is required to implement and adhere to protect the PHI that the HIC or Coroner provides to or Collects, Uses, or Discloses via the EHR;
  • Outline the consequences of breach of the agreement and must address the manner in which compliance with the agreement will be enforced;
  • Stipulate that compliance with the agreement will be audited and must address the manner in which compliance will be audited;
  • Require the HIC or Coroner to acknowledge and agree:
    • To provide, Collect, Use, Disclose, view, handle or otherwise deal with PHI via the EHR only in accordance with the terms of the agreement and PHIPA and its regulations;
    • To implement and comply with the administrative, technical and physical safeguards set out in the agreement;
    • To provide the notifications required by the agreement and PHIPA and its regulations; and
    • To comply with PHIPA and its regulations and the terms of the agreement.

Appendix B: Minimum Content Required in Logging

Ontario Health must maintain a log of all Ontario Health contributor and access services agreements acknowledged and agreed to by HICs and Coroners under whose authority PHI is provided to or Collected by means of the EHR.

At a minimum, the log must set out:

  • The name of each HIC or Coroner under whose authority PHI will be provided to or Collected by means of the EHR; and
  • The dates that the relevant Ontario Health contributor or access services agreement was acknowledged and agreed to.

More Like This

Last Updated: June 04, 2026