Electronic Health Record Privacy Incident Management Policy and Procedure
Policy Level Approval: Chief Executive Officer
Policy Category: Enterprise Policy
Policy Number: INF-006.02-PP
Policy Sponsor (or Sponsors): Chief, Strategy, Planning, Privacy & Analytics
Original Date of Approval: September 30, 2020
Date of Posting: August 05, 2026
Version Approval Date: April 9, 2026
- 1. Purpose, Objectives and Scope
- 2. General
- 3. Process for Managing Privacy Incidents
- 4. Responsibilities
- 5. Definitions and Acronyms
- 6. Review Cycle
- 7. References and/or Key Implementation Documents
- 8. Appendices
- 9. Policy Consultations
- 10. Policy Review History
- Appendix A: Privacy Breach Severity Levels
- Appendix B: Privacy Breach Notification Form
1. Purpose, Objectives and Scope
1.1 Purpose
1.1.1 To provide guidance to Health Information Custodians (HICs) and Coroners with respect to their obligations for the identification, reporting, containment, notification, investigation and remediation of Privacy Incidents related to Personal Health Information (PHI) received by Ontario Health as the Prescribed Organization (PO) for the purpose of developing or maintaining the Electronic Health Record (EHR).
1.2 Objectives
1.2.1 To enable Ontario Health, HICs and Coroners to comply with the Privacy Incident management requirements set out in the following, as applicable:
- The Personal Health Information Protection Act, 2004 (PHIPA) and its regulations;
- The Information and Privacy Commissioner of Ontario’s (IPC) Manual for the Review and Approval of Prescribed Organizations (IPC PO Manual);
- Guidelines issued by the IPC, including Responding to a Health Privacy Breach: Guidelines for the Health Sector; and
- Any directions issued by the Minister of Health (Minister).
1.2.2 To protect the privacy of individuals and the confidentiality of their PHI.
1.3 Application and Scope
1.3.1 This Policy applies to Ontario Health when it acts under its authority as the PO for the purposes of Part V.1 of PHIPA.
1.3.2 This Policy applies to HICs that provide PHI to Ontario Health as a PO for the purpose of developing or maintaining the EHR, HICs that Collect PHI by means of the EHR, and Coroners to whom the PO provides PHI by means of the EHR.
1.3.3 This Policy applies to non-union Employees, people leaders, board members, unionized Employees, secondees, consultants, and other individuals acting on behalf of OH collectively referred to as (Ontario Health Agents).
1.3.4 Ontario Health Employees and other Ontario Health Agents must also comply with the Ontario Health Privacy Incident Management Policy and Procedure when managing Privacy Incidents, including those related to PHI received by Ontario Health as a PO for the purpose of developing or maintaining the EHR.
1.4 Compliance and Exemptions
1.4.1 Compliance with this Policy in its entirety is mandatory unless an exception to a specific section is approved by Ontario Health’s Chief Privacy Officer (CPO) or delegate in writing. Failure to comply with the requirements of this Policy, without a written exception, may result in disciplinary action up to and including revocation of appointment, termination of employment or termination of contract without notice or compensation.
1.4.2 Compliance will be audited in accordance with the roles, process and frequency outlined in the Privacy Audit & Compliance Policy.
1.4.3 At the first reasonable opportunity upon identifying or becoming aware of a breach of this Policy, Ontario Health Employees and other Ontario Health Agents, as well as HICs and Coroners must notify Ontario Health’s Privacy Office by reporting the breach to Enterprise Service Desk by Phone: 1-866-250-1554; or Email: oh-servicedesk@ontariohealth.ca
1.4.4 Compliance will be enforced in accordance with the Progressive Discipline Policy.
1.5 Terminology
1.5.0 The words “include” and “including” when used are not intended to be exclusive and mean, respectively, “include, without limitation,” and “including, but not limited to”.
1.5.1 Words and terms in this Policy that have meanings differing from the commonly accepted definitions are capitalized and their meanings are set out in the Definition and Acronyms section (Section 5).
2. General
2.1 Background
2.1.1 In accordance with this Policy and Ontario Health’s Privacy Incident Management Policy and Procedure, Ontario Health’s Privacy Office, led by the CPO, is responsible for the management of Ontario Health’s privacy program including procedures addressing identification, reporting, containment, notification, investigation and remediation of suspected and actual Privacy Breaches related to the EHR.
2.1.2 Ontario Health has systems and processes in place to audit and monitor the EHR for suspicious Collection, Use and Disclosure of PHI accessible by means of the EHR.
2.1.3 If OH becomes aware of a Privacy Incident related to the EHR, at the first reasonable opportunity and to the extent reasonably known, OH notifies:
- The HIC(s) or Coroner(s) that caused the Privacy Incident; and
- The HIC(s) that provided the PHI to OH as a PO for the purpose of developing or maintaining the EHR.
2.1.4 Ontario Health’s Privacy Office investigates, tracks, and logs Privacy Incidents in accordance with the Ontario Health Privacy Incident Management Policy and Procedure.
2.2 Policy
2.2.1 HICs and Coroners must implement and adhere to their own internal Privacy Incident management policies for the identification, reporting, containment, notification, investigation and remediation of Privacy Incidents in respect of PHI accessible by means of the EHR and are responsible for ensuring their own compliance with PHIPA, O. Reg. 329/04, OH Policies, and applicable legal agreements.
2.2.2 HICs and Coroners that Collect, Use or Disclose PHI by means of the EHR must ensure that their internal policies and procedures impose mandatory reporting requirements that ensure the HIC or Coroner’s compliance with PHIPA, O. Reg.329/04, and this Policy.
2.2.3 HICs that provide PHI to the PO for the purpose of developing or maintaining the EHR, HICs that Collect PHI by means of the EHR, and Coroners to whom the PO provides PHI by means of the EHR must notify Ontario Health at the first reasonable opportunity upon identifying or becoming aware of a Privacy Incident related to PHI accessible by means of the EHR.
Notice should be provided to Ontario Health’s Privacy Office by reporting the Privacy Incident to Enterprise Service Desk by Phone: 1-866-250-1554; or Email: oh-servicedesk@ontariohealth.ca.
2.2.4 All findings that are identified through the management and investigation of a Privacy Breach under this Policy must be communicated in writing (may include email or hardcopy i.e. letter)
HICs who provide PHI to the PO for the purpose of developing or maintaining the EHR
2.2.5 PHIPA establishes that when a HIC provides PHI to the PO, the HIC is considered not to be Disclosing the information to the PO, and the PO is considered not to be Collecting the information from the HIC.
2.2.6 PHIPA requires HICs with custody or control of PHI about an individual to notify the individual to whom the PHI relates at the first reasonable opportunity if the PHI is stolen or lost or if it is Used or Disclosed without authority, and include in the notice a statement that the individual is entitled to make a complaint to the IPC under Part VI of PHIPA. This includes Privacy Breaches related to the EHR which are caused by the PO or an Unauthorized Person.
2.2.7 If the circumstances surrounding a theft, loss or unauthorized Use or Disclosure meet the requirements prescribed in Ontario Regulation 329/04 made under PHIPA (O.Reg.329/04), the HIC must notify the IPC of the theft or loss or of the unauthorized Use or Disclosure.
HICs who Collect PHI by means of the EHR
2.2.8 If PHI about an individual is Collected without authority by means of the EHR, in addition to any notice that is required to be given in the case of an unauthorized Use or Disclosure under subsections 12 (2) and (3) of PHIPA, the HIC who is responsible for the unauthorized Collection must:
- Notify the individual at the first reasonable opportunity of the unauthorized Collection, and include in the notice a statement that the individual is entitled to make a complaint to the IPC under Part VI; and
- If the circumstances surrounding the unauthorized Collection meet the prescribed requirements, notify the IPC of the unauthorized Collection.
Coroners to whom the PO provides PHI by means of the EHR
2.2.9 O. Reg. 329/04 establishes that a Coroner to whom the PO provides PHI under subsection 55.9.1 (1) of PHIPA must, with respect to that PHI, comply with section 11.1, subsections 12 (1), (2) and (3), subsection 13 (1) and sections 17, 17.1, 30 and 31 of PHIPA as if the Coroner were a HIC.
2.2.10 A Coroner to whom the PO provides PHI under subsection 55.9.1 (1) of PHIPA may only Use or Disclose the PHI for the purpose for which the PHI was provided or for the purpose of carrying out a statutory or legal duty.
2.2.11 If a Coroner requests that the PO transmit PHI to the Coroner by means of the EHR and the PO transmits the PHI as requested, the Coroner must comply with the obligations set out in subsection 12 (1) of PHIPA with respect to the transmitted PHI, regardless of whether the Coroner has viewed, handled or otherwise dealt with the PHI.
Specifically, in accordance with subsection 12(1) of PHIPA, the Coroner must take steps that are reasonable in the circumstances to ensure that PHI in its custody or control is protected against theft, loss and unauthorized Use or Disclosure and to ensure that the records containing the PHI are protected against unauthorized copying, modification or disposal.
2.2.12 If PHI about an individual is Collected without authority by a Coroner by means of the EHR, the Coroner must:
(a) Notify the individual at the first reasonable opportunity of the unauthorized Collection and include in the notice a statement that the individual is entitled to make a complaint to the IPC under Part VI of PHIPA; and
(b) Notify the IPC of the unauthorized Collection at the first reasonable opportunity, if any circumstance exists where the Coroner would be required to notify the Commissioner if the Coroner were a HIC to which subsection 18.3 (1) of O.Reg. 329/04 applied.
2.2.13 Annual report re: theft, loss, etc.: A Coroner to whom the PO provides PHI under subsection 55.9.1 (1) of PHIPA must, in respect of that PHI, comply with section 6.4 of O.Reg.329/04, with any necessary modification, as if the Coroner were a HIC.
3. Process for Managing Privacy Incidents
3.1 Identification of Privacy Incidents by HIC or Coroner
3.1.1 HICs and Coroners may identify a Privacy Incident through a combination of formal and informal processes, including the following:
- Reports by their employees or other agents;
- Reports by other HICs or Coroners;
- Reports by members of the public;
- Privacy audits, Privacy Complaints and Privacy Inquiries.
3.1.2 Where a HIC or Coroner becomes aware of a Privacy Incident related to the EHR, the HIC or Coroner must notify Ontario Health at the first reasonable opportunity in writing by sending the Appendix A: Breach Notification Form by email to: oh-servicedesk@ontariohealth.ca. Notice may also be provided to Ontario Health verbally by telephone at: 1-866-250-1554.
3.1.3 Upon receiving notice of a Privacy Incident, Ontario Health Employees and other Ontario Health Agents will follow the Ontario Health Privacy Incident Management Policy and Procedure.
3.2 Identification of Privacy Incidents by Ontario Health
3.2.1 Where Ontario Health identifies a Privacy Incident that was caused by one or more HICs or Coroners, Ontario Health reports the Privacy Incident to the HIC(s) or Coroner(s) in accordance with the Ontario Health Privacy Incident Management Policy and Procedure.
3.3 Privacy Incidents Caused by One or More HICs or Coroners
3.3.1 Where it is confirmed that a HIC or Coroner has caused a Privacy Incident involving unauthorized Collection of PHI by means of the EHR, the HIC or Coroner must appoint an investigator no later than 7 days after becoming aware of the Privacy Incident. The investigator appointed by the HIC or Coroner must, as soon as reasonably possible, submit a written report of the investigation to Ontario Health as outlined in Appendix B: Breach Notification Form.
3.2.2 Upon receipt of the written report of the investigation, Ontario Health Employees and other Ontario Health Agents follow the Ontario Health Privacy Incident Management Policy and Procedure.
3.2.3 In addition to any notice that is required to be given in the case of an unauthorized Use or Disclosure by a HIC under subsections 12 (2) and (3) of PHIPA, if PHI about an individual is Collected without authority by means of the EHR, the HIC who is responsible for the unauthorized Collection must,
(a) notify the individual at the first reasonable opportunity of the unauthorized Collection, and include in the notice a statement that the individual is entitled to make a complaint to the IPC under Part VI of PHIPA; and
(b) if the circumstances surrounding the unauthorized Collection meet the prescribed requirements, notify the IPC of the unauthorized Collection.
3.2.4 If PHI about an individual is Collected without authority by a Coroner by means of the EHR, the Coroner must:
- Notify the individual at the first reasonable opportunity of the unauthorized Collection and include in the notice a statement that the individual is entitled to make a complaint to the IPC under Part VI of PHIPA; and
- Notify the IPC of the unauthorized Collection at the first reasonable opportunity, if any circumstance exists where the Coroner would be required to notify the IPC if the Coroner were a HIC to which subjection 18.3 (1) of O. Reg. 329/04 applied.
3.2.5 When requested or directed by the Minister, Ontario Health fulfills the following in accordance with the Ontario Health Privacy Incident Management Policy and Procedure:
- Cooperates with the HICs in developing a policy and procedure to make a determination of whether a Privacy Breach has in fact occurred and if so, to contain, investigate and remediate the Privacy Breach, and to notify individuals in circumstances where the Privacy Breach or Privacy Incident was caused by one or more HICs;
3.2.6 Assists HICs in making a determination of whether a Privacy Breach has in fact occurred and if so, assist in containing, investigating and remediating the Privacy Breach and notifying individuals in circumstances where the Privacy Breach or Privacy Incident was caused by one or more HICs; and
- Assists HICs in fulfilling their obligations to notify individuals under subsections 12(2) and 55.5(7) of PHIPA and takes into consideration any directions issued by the Minister.
3.2.7 Ontario Health’s CPO or designate is responsible for appointing members of the Ontario Health Privacy Office or other designated program area/business unit to assist the HIC(s) upon request or direction by the Minister.
3.2.8 In addition to any requests or directions issued by the Minister, Ontario Health may assist the HICs in fulfilling their obligation to notify individuals of a Privacy Breach. Ontario Health’s role in assisting a HIC may include:
- Collating a list of individuals impacted by the Privacy Incident;
- Drafting the notice to affected individual(s); and
- Supporting any other requests or directions issued by the Minister.
3.3 Privacy Incidents Caused by OH or an Unauthorized Person
3.3.1 Ontario Health follows the steps outlined in the Ontario Health Privacy Incident Management Policy and Procedure to manage Privacy Incidents caused by:
- Ontario Health Employees or other Ontario Health Agents;
- A system that retrieves, processes or integrates PHI accessible by means of the EHR;
- An unauthorized person who is not an Ontario Health Employee or other Ontario Health Agent; and
- An unauthorized person who is not an agent of a HIC.
Note: Ontario Health Privacy Incident Management Policy and Procedure stipulates the process to be followed for determining whether an event constitutes a Privacy Incident or Breach, as well as the process for containment, investigation and notification, and the documentation that must be completed, provided and/or executed by the Ontario Health Employee or other Ontario Health Agent responsible and the required content of the documentation.
4. Responsibilities
4.1 Ontario Health Chief Privacy Officer
4.1.1 Ensures compliance with FIPPA and PHIPA and ensures relevant Ontario Health policies and procedures are put in place.
4.1.2 Responsible for the overall accountability and the day-to-day operations of the Privacy Program.
4.2 Ontario Health Privacy Office
4.2.1 Responsible for authoring and maintaining this Policy and its associated processes.
4.2.2 Receives and manages notifications of Privacy Incidents.
4.2.3 Manages Privacy Incidents and Breaches in accordance with this Policy and the Ontario Health Privacy Incident Management Policy.
4.3 HICs that provide PHI to Ontario Health as a PO
4.3.1 Manage Privacy Incidents in accordance with this Policy, PHIPA, O. Reg. 329/04 and the HIC’s internal Privacy Incident Management policies, procedures and practices.
4.3.2 Responsible for notifying individuals of a Privacy Breach that relates to PHI the HIC provided to Ontario Health as a PO for the purpose of developing or maintaining the EHR in accordance with PHIPA.
4.4 Coroners to whom PHI is provided by means of the EHR
4.4.1 Manage Privacy Incidents in accordance with this Policy, PHIPA, O. Reg. 329/04 and the Coroner’s internal Privacy Incident Management policies, procedures and practices.
4.4.2 Responsible for notifying individuals and the IPC in accordance with PHIPA where the Coroner Collects PHI by means of the EHR without authority.
4.5 HICs that Collect PHI by means of the EHR
4.5.1 Manage Privacy Incidents in accordance with this Policy, PHIPA, O. Reg. 329/04 and the HIC’s internal Privacy Incident Management policies, procedures and practices.
4.5.2 Responsible for notifying individuals and the IPC in accordance with PHIPA where the HIC Collects PHI by means of the EHR without authority.
5. Definitions and Acronyms
Defined terms are capitalized through this document
Collect: Has the meaning set out in section 2 of PHIPA with respect to PHI; and in respect of PI has the same meaning. “Collect” means to gather, acquire, receive, or obtain the information by any means from any source, and “Collection” and “Collected” has a corresponding meaning.
Coroner: Means the Chief Coroner for Ontario, a Deputy Chief Coroner for Ontario, a regional coroner or a coroner appointed under section 5 of the Coroners Act, as set out in section 1 of the Coroners Act.
CPO: Chief Privacy Officer
Disclose: Has the meaning set out in s. 2 of PHIPA with respect to PHI in the control of a HIC or a person; and in respect of PI has the same meaning.
“Disclose” means to make the information available or to release it to another HIC or to another person, but does not include to Use the information, and “Disclosure” has a corresponding meaning.
EHR or Electronic Health Record: Has the meaning set out in s. 55.1 of PHIPA and generally means the electronic systems that are developed and maintained by Ontario Health pursuant to Part V.1 of PHIPA for the purpose of enabling HICs to Collect, Use and Disclose PHI by means of the systems.
Employee: A person employed and compensated by Ontario Health as an Employee, and is classified as either permanent full-time, permanent part-time, temporary full-time, temporary part-time, paid student or casual, as set out in the Employee Classification Guideline. A consultant or contractor is not an Employee.
HIC or Health Information Custodian: Has the meaning set out in s. 3 of PHIPA and generally means a person or organization that has custody or control of personal health information for the purpose of health care or other health-related duties. Examples include physicians, hospitals, pharmacies, laboratories and the MOH, but does not include Ontario Health.
IPC: Information and Privacy Commissioner of Ontario
IPC PO Manual: IPC Manual for the Review and Approval of Prescribed Organizations
Minister: Minister of Health
MOH: Ontario Ministry of Health
O.329/04: Ontario Regulation 329/04 made under PHIPA
Ontario Health: Ontario Health, the agency of the Government of Ontario to which this Policy applies.
Ontario Health Agent: A person that acts for or on behalf of Ontario Health for the purposes of Ontario Health , and not for the person’s own purposes, whether or not the person has the authority to bind Ontario Health , whether or not the person is an Employee, and whether or not the person is being remunerated.
PHI or Personal Health Information: Has the meaning set out in s. 4 of PHIPA. Specifically, it is “identifying information” in oral or recorded form about an individual that:
- relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family;
- relates to the provision of health care to the individual, including the identification of a person as a provider of health care to the individual;
- Is a plan that sets out the home and community care services for the individual to be provided by a health service provider or Ontario Health Team pursuant to funding under section 21 of the Connecting Care Act, 2019;
- relates to payments or eligibility for health care or eligibility for coverage for health care, in respect of the individual;
- relates to the donation by the individual of any body part or bodily substance of the individual or that is derived from the testing or examination of any such body part or bodily substance;
- is the individual’s health number;
- identifies an individual’s substitute decision-maker; or
- is the individual’s digital health identifier or other identifying information related to the creation of the digital health identifier.
PHI includes identifying information about an individual that is not listed above but that is contained in a record that includes PHI listed above.
Information is “identifying” when it identifies an individual or when it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.
PHIPA or Personal Health Information Protection Act, 2004: The Ontario health privacy law. It establishes rules for the management of PHI and the protection of the confidentiality of that information, while facilitating the effective delivery of healthcare services. References to PHIPA include the regulation made thereunder, as may be amended or replaced from time to time.
PI or Personal Information: Has the meaning set out in section 2 of FIPPA. Specifically, it means recorded information about an identifiable individual, including:
- information relating to the race, national or ethnic origin, colour, religion, age, sex, sexual orientation or marital or family status of the individual;
- information relating to the education or the medical, psychiatric, psychological, criminal or employment history of the individual or information relating to financial transactions in which the individual has been involved;
- any identifying number, symbol or other particular assigned to the individual;
- the address, telephone number, fingerprints or blood type of the individual;
- the personal opinions or views of the individual except where they relate to another individual;
- correspondence sent to an institution by the individual that is implicitly or explicitly of a private or confidential nature, and replies to that correspondence that would reveal the contents of the original correspondence;
- the views or opinions of another individual about the individual; and
- the individual’s name where it appears with other personal information relating to the individual or where the disclosure of the name would reveal other personal information about the individual.
Personal Information also includes information that is not recorded and that is otherwise defined as Personal Information when considering the manner of collection, notice to public, privacy impact assessments and safeguards.
Prescribed Organization or PO: The organization prescribed in Ontario Regulation 329/04 as the organization for the purposes of PHIPA. The Prescribed Organization has the power and the duty to develop and maintain the EHR in accordance with Part V.1 of PHIPA, and the power to carry out digital health identifier activities in accordance with Part V.2 of PHIPA.
Privacy Breach: A Privacy Breach includes:
1) Privacy Breach of PHI or PI (Privacy PHI/PI Breach) means an event where:
- The Collection, Use or Disclosure of PHI or PI is not in compliance with PHIPA or its regulation, or with FIPPA or its regulations (i.e. without legal authority); and/or
- The Viewing, handling or otherwise dealing with PHI provided to Ontario Health is not in compliance with PHIPA, or its regulation;
- PHI or PI is stolen, lost or subject to unauthorized Collection, Use or Disclosure or where records of PHI or PI are subject to unauthorized copying, modification, or disposal.
Note: A Privacy PHI/PI Breach does not include a breach of De-identified Information, or Business Identity Information, if the event does involve PI or PHI.
2) Privacy Breach of Privacy Policy or Agreement (Privacy Policy/Agreement Breach) means an event where:
- There is a contravention of Ontario Health’s privacy policies, procedures or practices; and/or
- There is a contravention of a privacy-related term or condition in a:
- data sharing agreements,
- research agreements,
- confidentiality agreements, or
- agreements with third party service providers retained by Ontario Health to handle PHI or PI,
- written acknowledgements acknowledging and agreeing not to use PHI or PI which has been de-identified and/or aggregated, to identify an individual; and
- Does not include a privacy breach of PHI or PI
Note: A Privacy Policy/Agreement Breach may include a breach that involves De-identified Information or Business Identity Information, if the breach relates to privacy controls in an agreement or a privacy policy, procedure or practice related to handling of De-identified Information or Business Identity Information.
Privacy Complaint: Concerns or complaints relating to:
- The privacy policies, procedures and practices implemented by Ontario Health and Ontario Health’s compliance under PHIPA, FIPPA and associated regulations; and
- Compliance of a HIC with PHIPA and its regulation in respect of PHI that is accessible by means of the EHR developed or maintained by Ontario Health.
Privacy Incident: Any event where the Privacy Office is notified or becomes aware that a Privacy Breach may have occurred. This includes events that are reviewed/investigated and are:
- Confirmed to be a Privacy Breach;
- Confirmed not to be a Privacy Breach; or
- It cannot or has not been determined if a Privacy Breach occurred (Suspected Privacy Breach).
Note: Privacy Incidents include events involving PI and PHI, as well as De-identified Information and Business Identity Information as these events require investigation in accordance with this Policy to confirm if they are Privacy Breaches as defined below. Ontario Health shall investigate these incidents involving De-identified Data and Business Identity Information, considering factors such as the 1) risk of re-identification and related de-identification guidelines for De-identified Data, as well as 2) the context for handling data that Ontario Health received as Business Identity Information, to confirm that it does not constitute PI, respectively.
Privacy Inquiry: Inquiries relating to:
- The privacy policies, procedures and practices implemented by Ontario Health and Ontario Health’s compliance under PHIPA, FIPPA and related regulations; and
- Inquiries relating to the privacy policies, procedures, and practices of a HIC, or the compliance of a HIC with PHIPA and its regulation, in respect of PHI that is accessible by means of the EHR developed or maintained by Ontario Health.
Use: In relation to PHI or PI in the custody or under the control of a HIC or a person, “Use” means to view, handle or otherwise deal with the information, but does not include to Disclose the information, and “Use”, as a noun, has a corresponding meaning. For the purposes of PHIPA, the providing of PHI between a HIC and an agent of the HIC is a Use by the HIC, and not a Disclosure by the person providing the information or a Collection by the person to whom the information is provided.
6. Review Cycle
This Policy is to be reviewed by Ontario Health at least within 3 years of its effective date or earlier if required in accordance with the Privacy Audit and Compliance Policy.
7. References and/or Key Implementation Documents
- Privacy Incident Management Policy and Procedure
- Information Security Incident Management Standard
- Electronic Health Record Logging and Auditing Policy
- Electronic Health Record Privacy Breach Report Form
- Electronic Health Record Retention Policy
- Privacy Audit and Compliance Policy
- IPC’s Responding to a Health Privacy Breach: Guidelines for the Health Sector
- Any directions issued by the Minister of Health
8. Appendices
- Appendix A: Privacy Breach Severity Report Form
- Appendix B: Privacy Breach Notification Form
9. Policy Consultations
The following were consulted in the development of this Policy:
- Managers and responsible staff members of OH business units responsible for implementing and/or complying with this Policy.
10. Policy Review History
April 2026: This version of the policy was approved on April 9, 2026, by the Ontario Health Chief Executive Officer.
Appendix A: Privacy Breach Severity Levels
High Severity:
- Significant number or volume of individuals are impacted
- Information could be used to commit identify theft or gain unauthorized access to computer systems and other sources of PHI
- Significant risk of media attention
- Will cause significant reputation harm to Ontario Health
- May cause significant harm to individuals or stakeholders
- Containment requires shutting down systems
- Information at issue is considered highly sensitive
- Information may have been disclosed in error to the public at large
- Recurring Privacy Incident
Medium Severity:
- A relatively small number of individuals are impacted
- Moderate risk of harm to individual
- Moderate risk of media attention
- Moderate risk that the information could be used to commit identify theft or gain unauthorized access to computer systems and other sources of PHI
- Containment requires shutting down some minor systems
- Information disclosed to a known individual not authorized by Ontario Health to view PHI
- A breach caused by incorrect access permissions either due to human error or technological error; access permissions are assigned incorrectly
Low Severity:
- A single record of misdirected outgoing correspondence containing PHI caused by a factor such as an incorrect address
- Unlikely to cause harm to the individual
- Unlikely risk of media attention
- Unlikely risk that the information could be used to commit identify theft or gain
- Not recurring or wi despread
- No harm to Ontario Health or Division’s systems or information
- Information disclosed to a known individual authorized by Ontario Health to view PHI
- A policy breach where the Collection, use or disclosure is in contravention of an Ontario Health policy, but does not constitute an unauthorized Collection, use or disclosure as per PHIPA (e.g. PHI sent in an email to an authorized Ontario Health recipient) and including passive Privacy Breaches.
Appendix B: Privacy Breach Notification Form
More Like This
Last Updated: August 05, 2026