Electronic Health Record Policy for Receiving Personal Health Information (PHI)
Policy Level Approval: Chief Executive Officer
Policy Category: Enterprise Policy
Policy Number: INF-005.02-P
Policy Sponsor (or Sponsors): Chief, Strategy, Planning, Privacy & Analytics
Original Date of Approval: November 11, 2021
Date of Posting: May 16, 2026
Version Approval Date: April 9, 2026
1. Purpose, Objectives and Scope
1.1 Purpose
1.1.1 This Policy and its procedures, in respect of Personal Health Information (PHI) received by Ontario Health for the purposes of developing and maintain the Electronic Health Record (EHR), identifies:
- The purpose for which PHI will be received;
- The nature of the PHI that will be received,
- From whom the PHI will typically be received;
- The process for Ontario Health’s receipt of such PHI; and
- The process for creating, reviewing, amending and approving the descriptions of types of PHI received.
1.2 Objectives
1.2.1 To enable Ontario Health as a Prescribed Organization to:
- Meet its obligations under the Personal Health Information Protection Act, 2004 (PHIPA);
- Meet its obligations under the Information and Privacy Commissioner’s (IPCs) Manual for the Review and Approval of Prescribed Organizations; and
- Protect the privacy of individuals and the confidentiality of their PHI.
1.3 Scope
1.3.1 This policy applies to non-union Employees, people leaders, board members, unionized Employees, secondees, consultants, individuals acting on behalf of Ontario Health ‘Ontario Health Agents’, and Health Information Custodians (HICs) that provide or access PHI in the EHR.
1.3.2 This Policy applies to PHI received by Ontario Health under its authority as a Prescribed Organization.
1.3.3 This Policy does not set out the secure manner in which PHI will be received. This is documented in Ontario Health’s Secure Transfer of Sensitive Information Standard.
1.4 Compliance, Audit, Enforcement and Exemptions
1.4.1 Compliance with this Policy in its entirety is mandatory unless an exception to a specific section is approved by the Chief Privacy Officer (CPO) or delegate in writing. Failure to comply with the requirements of this Policy may result in disciplinary action up to and including revocation of appointment, termination of employment or termination of contract without notice or compensation.
1.4.2 Compliance will be audited in accordance with and as per the frequency outlined in the Privacy Audit and Compliance Policy.
1.4.3 At the first reasonable opportunity upon identifying or becoming aware of a breach of this Policy, Employee(s) or other Ontario Health Agents, and HICs t notify the Privacy Office by reporting the breach to Enterprise Service Desk by phone: 1-866-250-1554; or email: oh-servicedesk@ontariohealth.ca.
1.4.4 Breaches of this Policy will be managed in accordance with the Privacy Incident Management Policy and Procedure.
1.4.5 Compliance will be enforced in accordance with the Progressive Discipline Policy.
1.5 Terminology
1.5.1 The words “include” and “including” when used are not intended to be exclusive and mean, respectively, “include, without limitation,” and “including, but not limited to”.
1.5.2 Words and terms in this Policy that have meanings differing from the commonly accepted definitions are capitalized and their meanings are set out in the Definition and Acronyms section (Section 5).
2. Policy
2.1 Purpose, Nature and Source of PHI Received
2.1.1 Ontario Health receives PHI for the purpose of developing and maintaining the EHR in accordance with Part V.1 of PHIPA.
2.1.2 Ontario Health receives PHI that classes of HICs or specific HICs are required to provide to Ontario Health pursuant to regulations made under PHIPA.
2.1.3 Ontario Health creates, reviews and maintains the EHR Description and List of Repositories that sets out the following with respect to the PHI that Ontario Health receives:
- Descriptions of the PHI (e.g., requisitions, orders, results);
- An up-to-date list of the types of PHI (e.g., demographic, laboratory, drugs);
- The source(s) of the PHI (e.g., Minister, laboratories, hospitals);
- The repository in which the PHI is contained; and
- Whether or not the PHI is received pursuant the regulations.
2.1.4 The CPO has been delegated the day-to-day authority to:
- Manage the privacy program with respect to the descriptions of types of PHI received; and
- Review, on an ongoing basis, the descriptions of the types of PHI to ensure they are accurate and that the PHI received for the purpose of developing or maintaining the EHR is still necessary for the identified purpose.
2.1.5 The EHR Description and List of Repositories is made available to HICs who provide Ontario Health with PHI for the purposes of the EHR, and to the public through the Ontario Health privacy website.
2.2 Limiting the PHI that Ontario Health Receives
2.2.1 Ontario Health takes reasonable steps to limit the PHI it receives to that which is reasonably necessary for developing and maintaining the EHR.
2.2.2 Where a change is proposed to the nature of PHI received by Ontario Health (e.g., where a new clinical domain is contemplated), Ontario Health conducts a privacy impact assessment (PIA) in accordance with the PIA Standard to ensure that the PHI Ontario Health receives is limited to that which is reasonably necessary for developing and maintaining the EHR..
3. Procedures
3.1 Identifying New or Proposed Changes to PHI that Ontario Health Receives
3.1.1 Where a new or proposed change to the nature of PHI received by Ontario Health, the Director of the relevant business unit (program area or project team) is responsible for ensuring that the Privacy Office is engaged by completing and submitting a Privacy Intake Form.
3.2 Reviewing the Proposed Receipt of PHI
3.2.1 When a Privacy Intake Form is received by the Privacy Office, in accordance with the PIA Standard, a member of the Privacy Office or individual acting on behalf of the Privacy Office (Designated Privacy Specialist) is responsible for reviewing the new or proposed changes to the PHI that Ontario Health receives. The Designated Privacy Specialist determines if a PIA is required in accordance with the PIA Standard.
3.2.2 Where a change is proposed to the nature of PHI received by Ontario Health, such as a new clinical domain, a PIA will be conducted in accordance with the PIA Standard to ensure that there are controls in place to protect the privacy of individuals and the confidentiality of their PHI.
- Any proposed addition or removal of data elements to a clinical domain will be reviewed by the Privacy Office to determine if it is a change to the nature of the PHI and thus requires a PIA to be completed. Conversely, the review could determine that the addition or deletion of data element(s) from an existing EHR clinical domain may not qualify as a change to the nature of PHI received by Ontario Health and thus will not require a PIA to be conducted.
- Onboarding of a new HIC contributor following previously privacy assessed technology and processes does not require a PIA to be conducted.
3.2.3 In conducting the PIA, the Designated Privacy Specialist will consider:
- Whether Ontario Health has the authority under PHIPA to receive the PHI for the purposes of developing and maintaining the EHR;
- Whether any and all conditions or restrictions set out in PHIPA and its regulations or by the Minister if Health have been satisfied;
- Whether other information, namely de-identified and/or aggregate information, would serve the identified purpose and whether more PHI is being requested than is reasonably necessary to develop and maintain the EHR. Whether reasonable controls are in place to protect the PHI that Ontario Health will receive;
- If existing PHI transfer agreements are in place between the HIC and Ontario Health governing the HIC’s provision of PHI to Ontario Health; and
- If the EHR Description and List of Repositories requires updating to reflect changed or new PHI received by Ontario Health.
3.2.4 The results of the Designated Privacy Specialist’s review will be documented in the PIA, including any risks identified with respect to privacy.
3.3 PIA Approval
3.3.1 In approving the PIA, the Director of the relevant business unit considers and determines if the PHI that is proposed to be received by Ontario Health is limited to only what is necessary for Ontario Health to develop and maintain the EHR and if other information, namely de-identified and/or aggregate information, could serve the identified purpose.
3.3.2 The PIA requires CPO or delegate approval prior to Ontario Health receiving the proposed PHI. In reviewing and approving the PIA, the CPO or delegate considers the information set out in s. 3.2.3 of this Policy.
3.3.3 Once all required approvals are obtained, the PIA will be provided to the Director of the relevant business unit and communicated to the Senior Vice President (SVP), Digital Health Data and Services or the Digital Excellence in Health Executive who is responsible for executing the PHI transfer agreement.
3.3.4 Periodic reviews of the PHI to be received by Ontario Health will occur as part of the review of PIAs, in a frequency set out by the PIA Review Schedule that is established in accordance with the PIA Standard.
3.4 Agreements and Approval to Receive the PHI
3.4.1 The SVP Digital Excellence in Health Portfolio Executive, as applicable, is responsible for reviewing the PIA and other relevant documentation and determining whether to approve the receipt of PHI as proposed for the purpose of developing or maintaining the EHR. In reviewing and determining whether to approve the receipt of PHI, at a minimum, the following criteria require attention:
- Whether the receipt of PHI is permitted by PHIPA and its regulations;
- Whether any and all conditions or restrictions set out in PHIPA and its regulation or by the Minister have been satisfied; and
- Whether the PHI proposed to be received by Ontario Health is limited to that which is reasonably necessary for the purpose of developing or maintaining the EHR, and if other information, namely de-identified and/or aggregate information, could serve the identified purpose.
3.4.2 Where the receipt of PHI is approved, the SVP Digital Excellence in Health Portfolio Executive, as applicable, documents their approval by signing the applicable PHI transfer agreement.
3.4.3 Conditions or restrictions on the receipt of PHI are documented in a PHI transfer agreement between Ontario Health and the relevant HIC providing the PHI to Ontario Health. At a minimum, the following is included in the PHI transfer agreement:
- The nature and type of PHI that Ontario Health will receive which may be described by reference to the applicable EHR Data-In Interface Specification;
- The authority under PHIPA for Ontario Health to receive the PHI;
- The permitted purposes for which Ontario Health may receive the PHI;
- Relevant security and privacy requirements, including:
- That the HIC providing the PHI agrees to adhere to Ontario Health’s policies and procedures applicable to the EHR;
- Restrictions on Ontario Health’s receipt of the PHI;
- Provisions related to acceptable use by Ontario Health and HICs that collect PHI accessible by means of the EHR;
- Requirements with respect to end-user agreements, where applicable;
- Provisions with respect to breach notification, audit and compliance.
3.4.4 Ontario Health requires a PHI transfer agreement to be executed between Ontario Health and the relevant HIC prior to Ontario Health receiving the relevant PHI.
3.4.5 The PHI transfer agreement requires signature(s) from Ontario Health’s SVP, Digital Health Data and Services or the Digital Excellence in Health Executive on behalf of Ontario Health. By signing the PHI transfer agreement, the SVP, Digital Health Data and Services or the Digital Excellence in Health Executive, as applicable, indicates their approval of the receipt of PHI by Ontario Health. The Project Lead/Account Manager is responsible for ensuring that a PHI transfer agreement is executed between Ontario Health and the relevant HIC prior to Ontario Health receiving the relevant PHI.
3.5 Onboarding HICs to Provide PHI to Ontario Health
3.5.1 Where the receipt of PHI is approved and prior to Ontario Health receiving the PHI, the HIC is required to complete standard onboarding documentation and procedures for EHR contribution, including but not limited to completion of privacy assessment(s) as applicable.
3.6 Descriptions of Types of PHI Received
3.6.1 Once the PHI transfer agreement has been executed, the Designated Privacy Specialist is responsible for updating the EHR Description and List of Repositories as required, to identify the PHI that Ontario Health will receive for the purposes of developing and maintaining the EHR, and the sources of PHI from whom Ontario Health typically receives PHI.
3.6.2 The EHR Description and List of Repositories are updated in accordance with section 2.1.2 of this Policy.
3.6.3 When reviewing and updating the EHR Description and List of Repositories, consideration will be given to the information documented in the PIA.
3.6.4 The CPO or delegate is responsible for reviewing and approving the EHR Description and List of Repositories, and all revisions made to it.
3.6.5 The Designated Privacy Specialist will work with the Ontario Health Communications team to ensure the updated EHR Description is posted on the Ontario Health privacy website.
3.6.6 The EHR Description and List of Repositories requires CPO (or delegate) review on a regular basis, and at a minimum once every three years in accordance with the Privacy Audit and Compliance Policy and/or when a PIA is conducted in respect of the EHR.
3.6.7 In reviewing and/or in amending the EHR Description and List of Repositories, the CPO or delegate consults with the Director of the relevant Business Unit that is responsible for overseeing management of the respective EHR repository.
3.6.8 The EHR Description and List of Repositories are reviewed in accordance with the review process for privacy policies as set out in the Privacy Audit and Compliance Policy. At a minimum, it will be reviewed once every three years and when new or change to the nature of the PHI that Ontario Health receives is proposed.
4. Responsibilities
4.1 Chief Privacy Officer
4.1.1 Oversees all general aspects of this Policy, including updates and revisions
4.1.2 Approves initiation and results of PIAs
4.1.3 Approves the EHR Description and List of Repositories and any revisions made to it.
4.2 SVP, Digital Excellence in Health Executive
4.2.1 Reviews the PIA and other relevant documentation and determines whether to approve the receipt of PHI as proposed for the purpose of developing or maintaining the EHR.
4.2.2 Documents their approval by signing the applicable PHI transfer agreement.
4.3 Ontario Health Communications
Posts the EHR Description and List of Repositories on the Ontario Health privacy website.
4.4 The Project Lead/Account Manager
4.4.1 Ensures that a PHI transfer agreement is executed between Ontario Health and the relevant HIC prior to Ontario Health receiving the relevant PHI.
4.5 Director, Business Unit
4.5.1 Engages the Privacy Office to review any new or proposed change to the nature of PHI received by Ontario Health.
4.5.2 Approves the business content in the PIA;
4.5.3 Ensures the Risk Treatment Plan is complete or sign off on Risk Acceptance Form where appropriate in alignment with Risk Management Policy; and
4.5.4 Determines if the PHI that is proposed to be received by Ontario Health is limited to only what is necessary for Ontario Health to develop and maintain the EHR, and if other information, namely de-identified and/or aggregate information, could serve the identified purpose.
4.6 Privacy Office Staff
4.6.1 Determines if a PIA is required in accordance with this Policy and the PIA Standard.
4.6.2 Conducts the PIA and communicates the results to the Director of the relevant Business Unit and to the SVP, Digital Health Data and Services or the Executive Lead, Digital Excellence in Health Portfolio who is responsible for executing the PHI transfer agreement.
4.6.3 Conducts PIA reviews in accordance with the PIA Standard
4.6.4 Reviews and determines if amendments are required to the EHR Description and List of Repositories in accordance with this Policy, drafts such amendments and provides the amendments to the CPO for review and approval, and requests the Communications team to post the amended EHR Description and List of Repositories to the Ontario Health Privacy Website.
5. Definitions and Acronyms
Defined terms are capitalized through this document
Collect: Has the meaning set out in section 2 of PHIPA with respect to PHI; and in respect of PI has the same meaning. “Collect” means to gather, acquire, receive, or obtain the information by any means from any source, and “Collection” and “Collected” has a corresponding meaning.
CPO: Chief Privacy Officer
DSA: Data Sharing Agreement
Data Steward: A person who is accountable for ensuring that privacy, security, and data quality requirements are met for Data Holdings under their stewardship, and for maintaining an inventory of the Data Holding.
Disclose: Has the meaning set out in s. 2 of PHIPA with respect to PHI in the control of a HIC or a person; and in respect of PI has the same meaning. “Disclose” means to make the information available or to release it to another HIC or to another person, but does not include to Use the information, and “Disclosure” has a corresponding meaning.
EHR or Electronic Health Record: Has the meaning set out in s. 55.1 of PHIPA and generally means the electronic systems that are developed and maintained by Ontario Health pursuant to Part V.1 of PHIPA for the purpose of enabling HICs to Collect, Use and Disclose PHI by means of the systems.
Employee: A person employed and compensated by Ontario Health as an Employee, and is classified as either permanent full-time, permanent part-time, temporary full-time, temporary part-time, paid student or casual, as set out in the Employee Classification Guideline. A consultant or contractor is not an Employee.
HIC or Health Information Custodian: Has the meaning set out in s. 3 of PHIPA and generally means a person or organization that has custody or control of personal health information for the purpose of health care or other health-related duties. Examples include physicians, hospitals, pharmacies, laboratories and the MOH, but does not include Ontario Health.
IPC: Information and Privacy Commissioner of Ontario
IPC PO Manual: IPC Manual for the Review and Approval of Prescribed Organizations
Minister: Minister of Health
MOH: Ontario Ministry of Health
O. Reg. 329/04: Ontario Regulation 329/04 made under PHIPA
Ontario Health: The agency of the Government of Ontario to which this Policy applies.
Ontario Health Agent: A person that acts for or on behalf of Ontario Health for the purposes of Ontario Health , and not for the person’s own purposes, whether or not the person has the authority to bind Ontario Health , whether or not the person is an Employee, and whether or not the person is being remunerated.
PHI or Personal Health Information: Has the meaning set out in s. 4 of PHIPA. Specifically, it is “identifying information” in oral or recorded form about an individual that:
- relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family;
- relates to the provision of health care to the individual, including the identification of a person as a provider of health care to the individual;
- Is a plan that sets out the home and community care services for the individual to be provided by a health service provider or Ontario Health Team pursuant to funding under section 21 of the Connecting Care Act, 2019;
- relates to payments or eligibility for health care or eligibility for coverage for health care, in respect of the individual;
- relates to the donation by the individual of any body part or bodily substance of the individual or that is derived from the testing or examination of any such body part or bodily substance;
- is the individual’s health number;
- identifies an individual’s substitute decision-maker; or
- is the individual’s digital health identifier or other identifying information related to the creation of the digital health identifier.
PHI includes identifying information about an individual that is not listed above but that is contained in a record that includes PHI listed above.
Information is “identifying” when it identifies an individual or when it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.
PHIPA or Personal Health Information Protection Act, 2004: The Ontario health privacy law. It establishes rules for the management of PHI and the protection of the confidentiality of that information, while facilitating the effective delivery of healthcare services. References to PHIPA include the regulation made thereunder, as may be amended or replaced from time to time.
PIA: Privacy Impact Assessment
Prescribed Organization or PO: The organization prescribed in Ontario Regulation 329/04 as the organization for the purposes of PHIPA. The Prescribed Organization has the power and the duty to develop and maintain the EHR in accordance with Part V.1 of PHIPA, and the power to carry out digital health identifier activities in accordance with Part V.2 of PHIPA.
Privacy Incident: Any event where the Privacy Office is notified or becomes aware that a Privacy Breach may have occurred. This includes events that are reviewed/investigated and are:
- Confirmed to be a Privacy Breach;
- Confirmed not to be a Privacy Breach; or
- It cannot or has not been determined if a Privacy Breach occurred (Suspected Privacy Breach).
Note: Privacy Incidents include events involving PI and PHI, as well as De-identified Information and Business Identity Information as these events require investigation in accordance with this Policy to confirm if they are Privacy Breaches as defined below. Ontario Health shall investigate these incidents involving De-identified Data and Business Identity Information, considering factors such as the 1) risk of re-identification and related de-identification guidelines for De-identified Data, as well as 2) the context for handling data that Ontario Health received as Business Identity Information, to confirm that it does not constitute PI, respectively.
Privacy Breach: A Privacy Breach includes:
1) Privacy Breach of PHI or PI (Privacy PHI/PI Breach) means an event where:
- The Collection, Use or Disclosure of PHI or PI is not in compliance with PHIPA or its regulation, or with FIPPA or its regulations (i.e. without legal authority); and/or
- The Viewing, handling or otherwise dealing with PHI provided to Ontario Health is not in compliance with PHIPA, or its regulation;
- PHI or PI is stolen, lost or subject to unauthorized Collection, Use or Disclosure or where records of PHI or PI are subject to unauthorized copying, modification, or disposal.
Note: A Privacy PHI/PI Breach does not include a breach of De-identified Information, or Business Identity Information, if the event does involve PI or PHI.
2) Privacy Breach of Privacy Policy or Agreement (Privacy Policy/Agreement Breach) means an event where:
- There is a contravention of Ontario Health’s privacy policies, procedures or practices; and/or
- There is a contravention of a privacy-related term or condition in a:
- data sharing agreements,
- research agreements,
- confidentiality agreements, or
- agreements with third party service providers retained by Ontario Health to handle PHI or PI,
- written acknowledgements acknowledging and agreeing not to use PHI or PI which has been de-identified and/or aggregated, to identify an individual; and
- Does not include a privacy breach of PHI or PI
Note: A Privacy Policy/Agreement Breach may include a breach that involves De-identified Information or Business Identity Information, if the breach relates to privacy controls in an agreement or a privacy policy, procedure or practice related to handling of De-identified Information or Business Identity Information.
SVP: Senior Vice President
Use: In relation to PHI or PI in the custody or under the control of a HIC or a person, “Use” means to view, handle or otherwise deal with the information, but does not include to Disclose the information, and “Use”, as a noun, has a corresponding meaning. For the purposes of PHIPA, the providing of PHI between a HIC and an agent of the HIC is a Use by the HIC, and not a Disclosure by the person providing the information or a Collection by the person to whom the information is provided.
6. Review Cycle
This Policy is to be reviewed by Ontario Health at least within 3 years of its effective date or earlier if required in accordance with the Privacy Audit and Compliance Policy.
7. References and/or Key Implementation Documents
- PHIPA and O. Reg. 329/04
- IPC’s Manual for the Review and Approval of Prescribed Organizations
- PIA Standard
- EHR Description and List of Repositories
- Secure Transfer of Sensitive Information Standard
- Privacy Audit and Compliance Policy
- Privacy Incident Management Policy and Procedure
- EHR Assurance Policy
- Privacy Intake Form
8. Appendices
N/A
9. Policy Consultations
The following were consulted in the development of this Policy:
- Staff from the Privacy Office and other Ontario Health Agents responsible for drafting, maintaining and/or reviewing the privacy policies in reference to Ontario Health’s privacy requirements.
- Working Group members of the Privacy Program Advisory Committee (version 1 of the Policy)
10. Policy Review History
April 2026: This version of the policy was approved on April 9, 20265, by the Ontario Health Chief Executive Officer.
More Like This
Last Updated: June 04, 2026