In September 2025, Ontario's Divisional Court upheld a ruling that changes the calculation for every clinic owner in the province. If ransomware encrypts your records and makes them inaccessible, even temporarily, and even where there is no evidence anyone viewed or removed a single file, your notification obligations are engaged.
There is no size exemption. A one-physician practice carries the same core duties as a hospital. Most clinic owners assume they are too small to be a target and too small to be scrutinized, and neither assumption survives contact with the actual rules. This piece sets out what PHIPA breach notification requires, what the case law now covers, what the exposure is worth, and which controls actually reduce it.
What does the law actually require of you?
If you hold patient records, you are a health information custodian, and you carry a standing duty to take reasonable steps to protect personal health information against theft, loss and unauthorized use or disclosure, and to protect records against unauthorized copying, modification or disposal. That obligation exists today, before any incident, and it is the standard you will be measured against afterwards.
When a breach happens, two separate duties arise. You must notify affected individuals at the first reasonable opportunity. Note the wording, because it is not a fixed number of days. You will see 72 hours and 60 days quoted online, often by vendors selling something. The statutory language in Ontario is first reasonable opportunity, and the practical effect is that delay must be justifiable rather than merely inside a window you read somewhere.
Separately, you must notify the Information and Privacy Commissioner in defined circumstances, including breaches involving deliberate unauthorised use or disclosure by someone who knew they lacked authority, and breaches that are significant in light of the sensitivity and volume of information and the number of individuals affected. There are seven reporting categories in total, and reading them once beforehand beats guessing during an incident. Getting PHIPA breach notification right under pressure is largely a function of having read the rules on a calm day, the same way practices that plan around system-wide staffing pressure cope better than those that do not. There is also an obligation most small practices miss entirely: an annual report of the previous year's breach statistics, due to the IPC by 1 March. That report includes breaches that never met the threshold for individual notification. Zero is still a report.
Why did the SickKids ruling change the calculation?
Because it settled what counts as a reportable event. Following the 2022 attacks on the Hospital for Sick Children and Halton Children's Aid Society, both organizations argued that notification was not required because there was no evidence the attacker had viewed, accessed or removed files. Servers had been encrypted at the container level, information was temporarily inaccessible, and nothing appeared to have been taken.
The IPC disagreed, and on 16 September 2025 the Divisional Court dismissed both applications for judicial review. Encryption that makes information unavailable to authorized users is a use, and temporary inaccessibility is a loss. A ransomware attack that locks your records therefore triggers the duty on its own. The full reasoning is public in Hospital for Sick Children v. Ontario (Information and Privacy Commissioner), 2025 ONSC 5208, and it is worth an hour of your time or your lawyer's.
How much can a breach actually cost?
The regulator now has instruments it did not have before. Since 1 January 2024, the IPC can issue **administrative monetary penalties** directly, without a prosecution, up to $50,000 for an individual and $500,000 for an organization. Either maximum can be exceeded by the value of any economic benefit obtained through the contravention. That sits alongside offence prosecutions, where fines reach $200,000 for an individual and $1 million for a corporation, and alongside civil claims, where individuals harmed can sue for actual damages plus up to $10,000 for mental anguish where a court finds wilful or reckless misconduct.
Prosecutions remain rare. Penalties are a different instrument, and the first ones have now been issued. In the first case, involving a physician who used a shared hospital record system to identify newborns and solicit business for his private clinic, the IPC imposed $5,000 on the physician and $7,500 on the clinic. The amounts are modest, and the precedent is not, particularly since the IPC specifically found the clinic unprepared to handle a breach because it had no response protocol.
Fixating on penalty maximums also misreads the risk. For most practices, the real financial damage arrives in a sequence that has nothing to do with regulators: days of downtime with no access to charts or schedules, cancelled clinics, staff hours consumed by response and notification, forensic and legal fees, insurance deductibles and future premium increases, college reporting where applicable, and the reputational cost of a notification letter landing in every affected patient's mailbox. Then add the piece owners consistently underestimate, which is that the notification itself is regulated. IPC decisions have found public breach notices non-compliant for omitting required elements. Getting breached is one problem. Botching the notice creates a second one.
Which controls actually reduce your exposure?
Start with a named privacy officer and a written breach response plan. Most practices that suffer a breach have no documented procedure, and the absence measurably worsens the outcome, as the first penalty decision made plain. You need one named person, a written protocol covering containment, investigation, notification and remediation, and a list of who gets called first. This is the cheapest item available and the one a regulator will look for.
Then fix audit logging. You are expected to be able to establish who accessed what and when. Many small practices have no application-layer logging at all, which means that after an incident you cannot demonstrate the scope of a breach or rule out insider access, and you are forced into the broadest possible notification because you cannot prove anything narrower.
Deal with email and encryption next. Unencrypted patient information in email, on laptops or on portable drives is a common and entirely avoidable failure, and a single compromised email account can constitute both unauthorized use and unauthorized disclosure. Multi-factor authentication on email and your EMR is not optional in 2026. Get backups isolated from your production network, because attackers target backups first, and test the restore, because an untested backup is a hope rather than a control.
Assess your vendors, because the duty stays with you. Your EMR host, billing platform and any AI scribe or transcription tool are all processing personal health information on your behalf, and the custodian duty does not transfer to them. Ask where data resides, what their breach notification commitments to you are, what certifications they hold, and whether patient data can be used to train models. If you are adopting AI documentation tools, a privacy impact assessment and a written acceptable use policy belong in the project plan rather than after it. Finally, rehearse once. Run a one-hour tabletop on a single scenario: ransomware hits the EMR on a Monday morning. Who is called, in what order, who speaks to patients, who decides on IPC reporting, where the backups are, and how long a restore actually takes. Practices that have run this respond in hours. Practices that have not lose days deciding what to do.
Where does this leave practices outside Ontario?
In a different regime with a similar direction of travel. This article describes the Ontario framework. Alberta operates under the Health Information Act, British Columbia under its own e-health legislation, and Quebec under Law 25, each with different thresholds and timelines. If you practise in more than one province, or outside Ontario entirely, confirm your specific obligations under the applicable provincial privacy law and treat this as a prompt to ask rather than an answer.
The uncomfortable summary is that the standard is no longer whether you got unlucky. It is whether you took reasonable steps beforehand and responded correctly afterwards. Both are decisions made on an ordinary Tuesday rather than during the incident. That logic applies across practice operations generally, from staffing pressure in emergency departments to the provincial response to the family doctor shortage and the downstream effects of specialist wait times.
Frequently Asked Questions
Does ransomware require patient notification in Ontario?
Yes, and PHIPA breach notification is now settled on this point. The Divisional Court confirmed in September 2025 that encryption making personal health information inaccessible, even temporarily and even with no evidence of viewing or exfiltration, constitutes unauthorized use and loss under PHIPA. The duty to notify affected individuals applies, and it is not subject to a minimum risk threshold.
How quickly must a clinic notify patients of a breach?
PHIPA requires notification at the first reasonable opportunity. There is no fixed statutory countdown in days, despite the numbers circulating online. In practice, any delay must be justifiable on the facts. Separate notification to the Information and Privacy Commissioner is required in seven defined circumstances.
What penalties can the IPC issue?
Since January 2024, the IPC can issue administrative monetary penalties directly, to a maximum of $50,000 for an individual and $500,000 for an organization, with either limit exceeded by the economic benefit gained. Separate offence prosecutions carry fines up to $200,000 for an individual and $1 million for a corporation.
Does a small clinic have the same obligations as a hospital?
Yes on the core duties. PHIPA contains no size threshold, so a sole practitioner holds the same safeguarding and notification obligations as a large institution. The practical difference is resourcing, which is why a named privacy officer and a short written response protocol matter disproportionately for small practices.
While you are reviewing how patient information moves through your practice, the patient-facing side deserves the same attention. You can list your clinic and manage online booking through Medimap's platform for practices.
This article is general business information for health practice owners and administrators. It is not legal advice and does not create a solicitor-client relationship. Privacy obligations vary by province and by circumstance, and you should obtain advice from a qualified lawyer or privacy professional about your own practice.
Search thousands of healthcare providers across Canada. Find walk-in clinics, specialists, and book appointments instantly.

