Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

PHIPA Readiness Self-Assessment

Twelve questions on Ontario's Personal Health Information Protection Act, 2004. Built for health information custodians and for the agents and electronic service providers that handle personal health information on their behalf.

Start by knowing which one you are

PHIPA hangs almost every duty off your role, so the answer changes what applies to you.

A health information custodian holds personal health information in connection with delivering health care. Clinics, hospitals, pharmacies, laboratories, long-term care homes and individual practitioners are the usual examples. The custodian carries the primary statutory duties.

An agent acts for a custodian, with the custodian's authority, and handles personal health information on its behalf. An agent may only do what the custodian permits and what PHIPA allows, and the custodian remains responsible for it.

An electronic service provider supplies the goods or services that let a custodian collect, use, modify, disclose, retain or dispose of personal health information by electronic means. Most health software vendors, integrators and hosting providers land here. PHIPA is the hook, and O. Reg. 329/04 s.6(3) sets out the duties that follow, including not using the information except as necessary to provide the service, not disclosing it, keeping an electronic record of accesses and transfers, and telling the custodian about unauthorized handling. A fourth role sits on top of that one: connect two or more custodians to each other and you may also be a health information network provider, which carries its own duties. Our PHIPA compliance guide works through all four in detail.

0%

What to fix

    This is a self-assessment, not legal advice. PHIPA duties turn on your exact role and holdings, and a privacy impact assessment or advice from counsel is the right instrument for a binding answer.

    Not ready for a call yet?

    Get the health privacy playbook

    A few short notes from Jacob on running PHIPA, PIPEDA and SOC 2 together without doing the same work three times. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    Outsourced Privacy Officer

    A named contact person for privacy, with the breach and access processes behind them.

    Explore Outsourced Privacy Officer →

    Ontario health data, done properly

    Most firms will run you a SOC 2 and call the health privacy question answered. We work to Canadian law: PHIPA for Ontario personal health information, PIPEDA where it still reaches you, and HIPAA if you sell into the United States as well. See our healthcare and healthtech practice.

    See our health practice Book a call

    Frequently asked questions

    What is PHIPA?

    PHIPA is Ontario's Personal Health Information Protection Act, 2004. It governs how personal health information is collected, used, disclosed, retained and disposed of in Ontario, and it is overseen by the Information and Privacy Commissioner of Ontario. It applies on its own terms, not as a Canadian version of HIPAA.

    Am I a health information custodian, an agent, or an electronic service provider?

    A health information custodian is the organization or practitioner that holds personal health information in connection with delivering health care, such as a clinic, hospital, pharmacy or practitioner. An agent acts for a custodian and handles personal health information on the custodian's behalf and with its authority. An electronic service provider supplies goods or services that let a custodian handle personal health information electronically, which is where most health software vendors and hosting providers land. A vendor that only stores or transmits the information without viewing it for its own purposes is generally an electronic service provider rather than a custodian, and O. Reg. 329/04 s.6(3) sets out the duties that follow.

    Does PHIPA replace PIPEDA?

    For health information custodians in Ontario, PHIPA has been declared substantially similar to PIPEDA, so PHIPA governs personal health information collected, used and disclosed within the province. PIPEDA can still reach commercial activity that falls outside that, including some cross-border disclosures and information that is not personal health information, such as employee or customer data held by a private company. Most health technology companies end up needing to satisfy both, which is why the two are assessed together.

    Does a SOC 2 or ISO 27001 report make us PHIPA compliant?

    No. SOC 2 and ISO 27001 evidence a security programme, and they carry a large share of the safeguards work PHIPA s.12 requires, so the overlap is real and worth reusing. Neither one covers the statutory duties: the custodian and agent relationships, consent and the lockbox, notification of the individual and the Information and Privacy Commissioner of Ontario, the annual report to the Commissioner, or the access and correction rights. Those have to be built on top.

    How accurate is this self-assessment?

    It gives a directional read from the answers you provide. It is not legal advice and it is not a substitute for a privacy impact assessment or advice from counsel on your specific role and holdings. Use it to find the obvious gaps and to frame the conversation.

    Want the full picture?

    This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

    Start your free assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.