Electronic Health Record Request for Correction to Personal Health Information Policy and Procedure
Policy Level Approval: Chief Executive Officer
Policy Category: Enterprise Policy
Policy Number: INF-008.02-PP
Policy Sponsor (or Sponsors): Chief, Strategy, Planning, Privacy & Analytics
Original Date of Approval: September 30, 2020
Date of Posting: July 28, 2026
Version Approval Date: April 9, 2026
Table of Contents
1. Purpose, Objectives and Scope
1.1 Purpose
1.1.1 This policy and procedures outline Ontario Health’s practices for facilitating a response to correction requests made by an Individual or that Individual’s Substitute Decision-Maker (SDM) to a Health Information Custodian (HIC) under Part V of the Personal Health Information Protection Act, 2004 (PHIPA), in respect of the Individual’s record of personal health information (PHI) that is accessible by means of the electronic health record (EHR).
1.2 Objectives
1.2.1 To enable Ontario Health as a Prescribed Organization to:
- Meet its obligations under the PHIPA and associated regulations;
- Meet its obligations under the Information and Privacy Commissioner of Ontario (IPC) Manual for the Review and Approval of Prescribed Organizations; and
- Protect the privacy of Individuals and the confidentiality of their PHI.
1.3 Scope
1.3.1 This Policy applies to Ontario Health when it acts under its authority as the PO for the purposes of Part V.1 of PHIPA.
1.3.2 This Policy applies to non-union Employees, people leaders, board members, unionized employees, secondees, consultants, and individuals acting on behalf of Ontario Health (Ontario Health Agents) and HICs who provide PHI to Ontario Health for the purposes of developing and maintain the EHR.
1.3.3 This Policy applies to correction requests related to PHI that is accessible by means of the EHR that is developed and maintained by Ontario Health as a Prescribed Organization pursuant to Ontario Regulation 329/04 (O. Reg. 329/04). The EHR Description and List of Repositories is available on the Ontario Health Privacy Website. Where a correction request is related to PHI that is not accessible by means of the EHR, the Individual or SDM may be directed to contact the HIC(s) with custody or control of the record(s) or their PHIPA Agent.
1.3.4 This Policy does not apply to Ontario Health when it acts in accordance with subsections 51(5) and (6) of PHIPA.
1.4 Compliance and Enforcement
1.4.1 Compliance with this Policy in its entirety is mandatory unless an exception to a specific section is approved by Ontario Health’s Chief Privacy Officer (CPO) or delegate in writing. Failure to comply with the requirements of this Policy may result in disciplinary action up to and including revocation of appointment, termination of employment or termination of contract without notice or compensation.
1.4.2 Compliance will be audited in accordance with and as per the frequency outlined in the Privacy Audit and Compliance Policy.
1.4.3 At the first reasonable opportunity upon identifying or becoming aware of a breach of this Policy, employee(s), other Ontario Health Agents as well as HICs must notify the Ontario Health Privacy Office by reporting the breach to Enterprise Service Desk Phone: 1-866-250-1554; or Email: OH-servicedesk@ontariohealth.ca
1.4.4 Breaches of this Policy will be managed in accordance with the Privacy Incident Management Policy and Procedure and EHR Privacy Incident Management Policy and Procedure.
1.4.5 Compliance with Ontario Health policies will be enforced in accordance with the Progressive Discipline Policy.
1.5 Terminology
1.5.1 The words “include” and “including” when used are not intended to be exclusive and mean, respectively, “include, without limitation,” and “including, but not limited to”.
1.5.2 Words and terms in this Policy that have meanings differing from the commonly accepted definitions are capitalized and their meanings are set out in the Definition and Acronyms section (Section 5).
2. Policy
2.1 Approval of Policy by Minister of Health
2.1.1 In accordance with s. 55.3 (18) of PHIPA, this policy and procedures must be approved by the Minister of Health (Minister).
2.1.2 The Minister’s delegate has provided written confirmation to Ontario Health indicating the Minister’s approval of this Policy and procedures as of September 23, 2021.
2.2 Right to Request Correction to PHI
2.2.1 If a HIC has granted access to a record of PHI and if the Individual believes that the record of PHI is inaccurate or incomplete with respect to the purposes for which the HIC uses the information or has used the information, the Individual has a right to:
- Request that the HIC correct the PHI;
- Receive a written notice/decision from the HIC within the timeframe under PHIPA;
- Request a written notice of the requested correction, to the extent reasonably possible, be sent to those to whom the HIC disclosed the information, except if it will have no effect on the provision of health care or other benefits to the Individual;
- Require the HIC to attach a statement of disagreement to the information if the requested correction was not made and to disclose the statement of disagreement whenever the HIC discloses the information at issue; and
- File a complaint with the IPC if the Individual is unsatisfied with the outcome of a request for correction.
2.3 Ontario Health’s role as a PHIPA Agent
2.3.1 Acting as a PHIPA Agent to the HICs that provide PHI to Ontario Health as a Prescribed Organization, Ontario Health may facilitate a response to correction requests. Facilitating includes: receiving correction requests, collecting relevant documentation required to identify the records, forwarding relevant documentation to the HIC that provided the PHI to Ontario Health to further process and respond to the request, and providing procedural information to the Individual or SDM making the correction request.
2.3.2 Ontario Health is not authorized to provide guidance or advice to HICs, Individuals, or SDMs or assume any responsibility for determining the legal authority of the Individual or SDM to make the request or for making decisions about whether the record will be corrected. In accordance with PHIPA, these obligations rest solely with the HIC that has custody or control of the record.
2.4 Notice to the Public
2.4.1 Ontario Health provides the public with information about the right of individuals to access to their records of PHI that are accessible by means of the EHR. This policy is made available to the public on the Ontario Health Privacy Website. Individuals may also contact Ontario Health’s Privacy Office by telephone, mail or email to obtain information about this Policy and Ontario Health’s practices related to facilitating access requests.
2.4.2 Instructions for making an access request, including the required documentation and the title, mailing address and contact information for the employee(s) or other Ontario Health Agents to whom the documentation must be provided is noted on the Electronic Health Record Request for Access and Correction to Personal Health Information Form available on the Ontario Health Privacy Website.
2.5 Intake of correction requests from Individuals and SDMs
2.5.1 Correction requests related to repositories identified in Section 4 of the EHR Request for Access and Correction to Personal Health Information Form will be processed by Ontario Health in accordance with section 3 of this Policy.
2.5.2 Ontario Health does not intake correction requests related to specified repositories as identified in Section 5 of the EHR Request for Access and Correction to Personal Health Information Form. Upon receipt of an access request related to one or more of these repositories, Ontario Health will re-direct the Individual or SDM as identified in the EHR Request for Access and Correction to Personal Health Information Form.
2.6 Corrections to PHI in the EHR
2.6.1 As a Prescribed Organization, Ontario Health does not make any corrections to PHI in the EHR, however, as a PHIPA Agent to the HIC that provided the PHI to the EHR and at the direction of the HIC, Ontario Health may:
- Attach a statement of disagreement to the Individual’s record in accordance with the instructions provided by the HIC and applicable agreement(s); and/or
- Assist or facilitate the HIC in replacing records of PHI in the EHR, in accordance with applicable law and agreement(s).
2.7 Response obligations of the HIC that provided PHI to Ontario Health under PHIPA
2.7.1 Upon receipt of correction request documentation from Ontario Health or directly from the Individual or SDM, the HIC must comply with their obligations under Part V of PHIPA, including the following:
- Confirm the legal authority of the Individual or SDM who submitted the request in accordance with sections 23-26 of PHIPA;
- Respond to the Individual or SDM within 30 calendar days of receiving the correction request under PHIPA. However, the custodian may extend this time limit for a further period of not more than 30 calendar days if the requirements set out in section 54(3) and (4) of PHIPA are satisfied;
- Comply with annual reporting obligations to the IPC;
- Instruct Ontario Health if any corrections to PHI in the EHR are required in accordance with the terms and conditions of the applicable agreement(s).
2.8 Tracking and logging of correction requests
2.8.1 Ontario Health maintains a log of correction requests that relate to its responsibilities as a PHIPA Agent for HICs in facilitating a response to a request. Refer to “Appendix A: Log of Access and Correction Requests” for details that are captured in the log. Members of the Ontario Health Privacy Office team are responsible for updating and maintaining the log.
2.9 Retention of correction request documentation
2.9.1 Ontario Health’s Privacy Office Team retains relevant correction request documentation within the privacy secured drive, in accordance with the EHR Retention Policy and Procedure.
3. Procedures
3.1 Correction request made directly to a HIC for PHI provided to the EHR by one or more HICs
3.1.1 Where a HIC receives a correction request from an Individual or SDM for PHI provided to the EHR by one or more other HICs, the HIC receiving the request must at the first reasonable opportunity and no later than five (5) calendar days direct the Individual or SDM to make the correction request as instructed in the EHR Request for Access and Correction to Personal Health Information Form.
3.2 Correction request made to Ontario Health related to the repositories identified in Section 4 of the EHR Request for Access and Correction to Personal Health Information Form
3.2.1 Upon receipt of an EHR Request for Access and Correction to Personal Health Information Form from an Individual or SDM in relation to the repositories identified in Section 4 of that Form, a member of the Ontario Health Privacy Office Team:
- Ensures relevant correction request documentation is complete and seeks clarification as required from the Individual or SDM submitting the request;
- Initiates tracking and logging of the correction request (see Appendix A: Log of Access and Correction Requests);
- Ensures relevant correction related documentation is retained in a secure manner;
- Locates and retrieves the responsive records in the EHR;
- As soon as possible, but no later than ten (10) calendar days following receipt of the request, forwards the encrypted record(s) along with the correction request documentation to each relevant HIC for response in accordance with Part V of PHIPA; and
- As soon as possible, but no later than ten (10) calendar days following receipt of the request, provides written notification to the Individual or SDM. The notification includes:
- An acknowledgement of the receipt of the access request by Ontario Health;
- That Ontario Health is facilitating the request; and
- That the request has been forwarded to the applicable HIC(s) for response under PHIPA.
3.2.2 Upon receipt of the forwarded request from Ontario Health, the applicable HIC must respond to the request in accordance with the provisions of Part V of PHIPA and Section 2.7.1 of this Policy.
3.3 Correction request related to the repositories identified in Section 5 of the EHR Request for Access and Correction to Personal Health Information Form
3.3.1 For requests made to the Ministry of Health (MOH) for OLIS, the MOH re-directs the Individual or SDM to the HIC who provided the PHI to the MOH.
4. Responsibilities
4.1 Privacy Office
4.1.1 Authoring and maintaining this Policy
4.1.2 Facilitating correction requests as per this Policy.
4.1.3 Logging correction requests in the Log of Access and Correction Requests.
4.2 Employees and other Ontario Health Agents
4.2.1 Notifying the Privacy Office at the first reasonable opportunity upon receipt of a correction request related to the EHR.
4.3 HICs who provide PHI to Ontario Health
4.3.1 Notifying and cooperating with Ontario Heath upon receipt of correction requests related to the EHR as per this Policy.
4.3.2 Responding to access requests in compliance with PHIPA and this Policy.
5. Definitions and Acronyms
Defined terms are capitalized through this document
Collect: Has the meaning set out in section 2 of PHIPA with respect to PHI; and in respect of PI has the same meaning.
“Collect” means to gather, acquire, receive, or obtain the information by any means from any source, and “Collection” and “Collected” has a corresponding meaning.
CPO: Chief Privacy Officer
Disclose: Has the meaning set out in s. 2 of PHIPA with respect to PHI in the control of a HIC or a person; and in respect of PI has the same meaning.
“Disclose” means to make the information available or to release it to another HIC or to another person, but does not include to Use the information, and “Disclosure” has a corresponding meaning.
EHR or Electronic Health Record: Has the meaning set out in s. 55.1 of PHIPA and generally means the electronic systems that are developed and maintained by Ontario Health pursuant to Part V.1 of PHIPA for the purpose of enabling HICs to Collect, Use and Disclose PHI by means of the systems.
Employee: A person employed and compensated by Ontario Health as an Employee, and is classified as either permanent full-time, permanent part-time, temporary full-time, temporary part-time, paid student or casual, as set out in the Employee Classification Guideline. A consultant or contractor is not an Employee.
HIC or Health Information Custodian: Has the meaning set out in s. 3 of PHIPA and generally means a person or organization that has custody or control of personal health information for the purpose of health care or other health-related duties. Examples include physicians, hospitals, pharmacies, laboratories and the MOH, but does not include Ontario Health.
Individual: Has the meaning set out in section 2 of PHIPA with respect to PHI; and in respect of PI has the same meaning.
“Individual” means the individual, whether living or deceased, with respect to whom the information was or is being collected or created.
IPC: Information and Privacy Commissioner of Ontario
Minister: Minister of Health
MOH: Ontario Ministry of Health
O. Reg. 329/04: Ontario Regulation 329/04 made under PHIPA
Ontario Health: Ontario Health, the agency of the Government of Ontario to which this Policy applies.
Ontario Health Agent: A person that acts for or on behalf of Ontario Health for the purposes of Ontario Health, and not for the Agent’s own purposes, whether or not the Agent has the authority to bind Ontario Health, whether or not the Agent is employed by Ontario Health, and whether or not the Agent is being remunerated.
PHI or Personal Health Information: Has the meaning set out in s. 4 of PHIPA. Specifically, it is “identifying information” in oral or recorded form about an individual that:
- relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family;
- relates to the provision of health care to the individual, including the identification of a person as a provider of health care to the individual;
- is a plan that sets out the home and community care services for the individual to be provided by a health service provider or Ontario Health Team pursuant to funding under section 21 of the Connecting Care Act, 2019;
- relates to payments or eligibility for health care or eligibility for coverage for health care in respect of the individual;
- relates to the donation by the individual of any body part or bodily substance of the individual or that is derived from the testing or examination of any such body part or bodily substance;
- is the individual’s health number;
- identifies an individual’s substitute decision-maker; or
- is the individual’s digital health identifier or other identifying information related to the creation of the digital health identifier.
PHI includes identifying information about an individual that is not listed above but that is contained in a record that includes PHI listed above.
Information is “identifying” when it identifies an individual or when it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual.
PHIPA or Personal Health Information Protection Act, 2004: The Ontario health privacy law. It establishes rules for the management of PHI and the protection of the confidentiality of that information, while facilitating the effective delivery of healthcare services. References to PHIPA include the regulation made thereunder, as may be amended or replaced from time to time.
PHIPA Agent: In relation to a HIC, means a person that, with the authorization of the HIC, acts for or on behalf of the custodian in respect of PHI for the purposes of the HIC, and not the agent’s own purposes, whether or not the agent has the authority to bind the HIC, whether or not the agent is employed by the HIC and whether or not the agent is being remunerated.
Prescribed Organization or PO: The organization prescribed in Ontario Regulation 329/04 as the organization for the purposes of PHIPA. The Prescribed Organization has the power and the duty to develop and maintain the EHR in accordance with Part V.1 of PHIPA, and the power to carry out digital health identifier activities in accordance with Part V.2 of PHIPA.
Privacy Breach: A Privacy Breach includes:
1. Privacy Breach of PHI or PI (Privacy PHI/PI Breach) means an event where:
- The Collection, Use or Disclosure of PHI or PI is not in compliance with PHIPA or its regulation, or with FIPPA or its regulations (i.e. without legal authority); and/or
- The Viewing, handling or otherwise dealing with PHI provided to Ontario Health is not in compliance with PHIPA, or its regulation;
- PHI or PI is stolen, lost or subject to unauthorized Collection, Use or Disclosure or where records of PHI or PI are subject to unauthorized copying, modification, or disposal.
Note: A Privacy PHI/PI Breach does not include a breach of De-identified Information, or Business Identity Information, if the event does involve PI or PHI.
2. Privacy Breach of Privacy Policy or Agreement (Privacy Policy/Agreement Breach) means an event where:
- There is a contravention of Ontario Health’s privacy policies, procedures or practices; and/or
- There is a contravention of a privacy-related term or condition in a:
- data sharing agreements,
- research agreements,
- confidentiality agreements, or
- agreements with third party service providers retained by Ontario Health to handle PHI or PI,
- written acknowledgements acknowledging and agreeing not to use PHI or PI which has been de-identified and/or aggregated, to identify an individual; and
- Does not include a privacy breach of PHI or PI
Note: A Privacy Policy/Agreement Breach may include a breach that involves De-identified Information or Business Identity Information, if the breach relates to privacy controls in an agreement or a privacy policy, procedure or practice related to handling of De-identified Information or Business Identity Information.
Privacy Incident: Any event where the Privacy Office is notified or becomes aware that a Privacy Breach may have occurred. This includes events that are reviewed/investigated and are:
- Confirmed to be a Privacy Breach;
- Confirmed not to be a Privacy Breach; or
- It cannot or has not been determined if a Privacy Breach occurred (Suspected Privacy Breach).
Note: Privacy Incidents include events involving PI and PHI, as well as De-identified Information and Business Identity Information as these events require investigation in accordance with this Policy to confirm if they are Privacy Breaches as defined below. Ontario Health shall investigate these incidents involving De-identified Data and Business Identity Information, considering factors such as the 1) risk of re-identification and related de-identification guidelines for De-identified Data, as well as 2) the context for handling data that Ontario Health received as Business Identity Information, to confirm that it does not constitute PI, respectively.
SDM or Substitute Decision Maker: Has the meaning set out in s. 5 of PHIPA and in relation to an individual, means, unless the context requires otherwise, a person who is authorized under PHIPA to consent on behalf of the individual to the collection, use or disclosure of PHI about the individual.
Use: In relation to PHI or PI in the custody or under the control of a HIC or a person, “Use” means to view, handle or otherwise deal with the information, but does not include to Disclose the information, and “Use”, as a noun, has a corresponding meaning. For the purposes of PHIPA, the providing of PHI between a HIC and an agent of the HIC is a Use by the HIC, and not a Disclosure by the person providing the information or a Collection by the person to whom the information is provided.
6. Review Cycle
This Policy is to be reviewed by Ontario Health at least within 3 years of its effective date or earlier if required in accordance with the Privacy Audit and Compliance Policy.
7. References and/or Key Implementation Documents
View references and documents
- Personal Health Information Protection Act, 2004; Ontario Regulation, 329/04
- Manual for the Review and Approval of Prescribed Organizations
- EHR Description and List of EHR Repositories
- Privacy Audit and Compliance Policy
- Privacy Incident Management Policy and Procedure and EHR Privacy Incident Management Policy and Procedure
- Electronic Health Record Request for Access and Correction to Personal Health Information Form
8. Appendices
Appendix A: Log of Access and Correction Requests
9. Policy Consultations
The following were consulted in the development of this Policy:
- Staff from the Privacy Office and other Ontario Health Agents responsible for drafting, maintaining and/or reviewing the privacy policies in reference to Ontario Health’s privacy requirements.
- Working Group members of the Privacy Program Advisory Committee (version 1 of the Policy)
- Information and Privacy Commissioner of Ontario
- Ministry of Health
10. Policy Review History
April 2026: The policy was reviewed and updated in April 2026. It was approved on April 9, 2026, by the Ontario Health Chief Executive Officer.
11. Appendix A: Log of Access and Correction Requests
Note: This log is maintained by Ontario Health’s Privacy Office contains information that relates to Ontario Health’s responsibilities as a PHIPA Agent for the HIC that contribute PHI to the EHR, in facilitating a response to an access or correction request.
Where Ontario Health responds to or facilitates a response to a request for access or correction received on behalf of a HIC, the log includes the following, to the extent that they are known to Ontario Health:
- The date the request was received;
- The name and contact information for the Individual to whom the information relates;
- The type of request (i.e., access or correction);
- A description of the request;
- A description of the PHI that is the subject of the request;
- The Employee(s) or other person(s) that received and reviewed the request;
- The names of any member of the College of Physicians and Surgeons of Ontario or member of the College of Psychologists of Ontario who were consulted regarding whether granting access could reasonably be expected to result in a risk of serious bodily harm to the treatment or recovery of the Individual or risk of serious bodily harm to the Individual or another person;
- If the time limit for responding was extended, the reason for the extension, and the length of the extension;
- If a request was made for expedited access, whether the request was granted;
- The HIC’s employee(s) or agent for deciding whether to grant the request, if applicable;
- The decision that was made (granted, granted in part, or refused)
- The reason for the refusal, where applicable;
- The person responsible for communicating the decision to the Individual;
- The date the decision was communicated to the Individual;
- Where a decision was made to grant the request, the person responsible for implementing the decision;
- The date the decision was implemented;
- The amount of fees charged to respond to the request, if any;
- Where a statement of disagreement is attached, the employee(s) or other person(s) acting on behalf of Ontario Health responsible for receiving and attaching the statement of disagreement;
- The date the statement of disagreement was attached;
- The employee(s) or other person(s) acting on behalf of Ontario Health responsible for notifying others about a correction or a statement of disagreement; and
- The date others were notified about a correction or a statement of disagreement.
- The name and contact information for the HIC to whom the request was made; and
- A description of each decision that was made or action that was taken by Ontario Health in responding to or facilitating the response on behalf of the HIC.
More Like This
Last Updated: August 10, 2026