Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Twelve questions on Ontario's Personal Health Information Protection Act, 2004. Built for health information custodians and for the agents and electronic service providers that handle personal health information on their behalf.
PHIPA hangs almost every duty off your role, so the answer changes what applies to you.
A health information custodian holds personal health information in connection with delivering health care. Clinics, hospitals, pharmacies, laboratories, long-term care homes and individual practitioners are the usual examples. The custodian carries the primary statutory duties.
An agent acts for a custodian, with the custodian's authority, and handles personal health information on its behalf. An agent may only do what the custodian permits and what PHIPA allows, and the custodian remains responsible for it.
An electronic service provider supplies the goods or services that let a custodian collect, use, modify, disclose, retain or dispose of personal health information by electronic means. Most health software vendors, integrators and hosting providers land here. PHIPA is the hook, and O. Reg. 329/04 s.6(3) sets out the duties that follow, including not using the information except as necessary to provide the service, not disclosing it, keeping an electronic record of accesses and transfers, and telling the custodian about unauthorized handling. A fourth role sits on top of that one: connect two or more custodians to each other and you may also be a health information network provider, which carries its own duties. Our PHIPA compliance guide works through all four in detail.
This is a self-assessment, not legal advice. PHIPA duties turn on your exact role and holdings, and a privacy impact assessment or advice from counsel is the right instrument for a binding answer.
Not ready for a call yet?
A few short notes from Jacob on running PHIPA, PIPEDA and SOC 2 together without doing the same work three times. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Outsourced Privacy Officer
A named contact person for privacy, with the breach and access processes behind them.
Explore Outsourced Privacy Officer →Most firms will run you a SOC 2 and call the health privacy question answered. We work to Canadian law: PHIPA for Ontario personal health information, PIPEDA where it still reaches you, and HIPAA if you sell into the United States as well. See our healthcare and healthtech practice.
See our health practice Book a callPHIPA is Ontario's Personal Health Information Protection Act, 2004. It governs how personal health information is collected, used, disclosed, retained and disposed of in Ontario, and it is overseen by the Information and Privacy Commissioner of Ontario. It applies on its own terms, not as a Canadian version of HIPAA.
A health information custodian is the organization or practitioner that holds personal health information in connection with delivering health care, such as a clinic, hospital, pharmacy or practitioner. An agent acts for a custodian and handles personal health information on the custodian's behalf and with its authority. An electronic service provider supplies goods or services that let a custodian handle personal health information electronically, which is where most health software vendors and hosting providers land. A vendor that only stores or transmits the information without viewing it for its own purposes is generally an electronic service provider rather than a custodian, and O. Reg. 329/04 s.6(3) sets out the duties that follow.
For health information custodians in Ontario, PHIPA has been declared substantially similar to PIPEDA, so PHIPA governs personal health information collected, used and disclosed within the province. PIPEDA can still reach commercial activity that falls outside that, including some cross-border disclosures and information that is not personal health information, such as employee or customer data held by a private company. Most health technology companies end up needing to satisfy both, which is why the two are assessed together.
No. SOC 2 and ISO 27001 evidence a security programme, and they carry a large share of the safeguards work PHIPA s.12 requires, so the overlap is real and worth reusing. Neither one covers the statutory duties: the custodian and agent relationships, consent and the lockbox, notification of the individual and the Information and Privacy Commissioner of Ontario, the annual report to the Commissioner, or the access and correction rights. Those have to be built on top.
It gives a directional read from the answers you provide. It is not legal advice and it is not a substitute for a privacy impact assessment or advice from counsel on your specific role and holdings. Use it to find the obvious gaps and to frame the conversation.
This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.