Skip to content

Security for small clinics and health practices

You hold health records — the most regulated and most valuable category of personal data there is — usually with no dedicated IT staff, let alone a security team.

What it actually looks like when it happens

At a single-practitioner Alberta practice, someone answered an email that looked like it came from Microsoft. Four days later the mailbox belonged to somebody else, and every contact in it received a request to buy gift cards. The practice found out from its own patients. 207 of them had to be notified, and the two-factor authentication that would have stopped it was turned on afterwards — on most accounts.

Read the decision, and what the Commissioner said about it →

Documented cases at clinics and health practices

Cases →

Email is where we start: 82% of Canadian clinics with a website publish nothing that stops mail impersonating them — the weakest of any sector we measured.

It is one of the first things the free Snapshot checks — from the outside, nothing to install.

See what we’d find on your domain — get the free Security Snapshot →

The controls they check for

The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.

Multi-factor authentication, enforced

Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.

An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.

Backups you have restored from

At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.

Patching what faces the internet

Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.

An incident-response plan you have tested

Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.

And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →

Our Service →

What you are already required to do

Information and Privacy Commissioner of Ontario · PHIPA

If you do not report and notify, PHIPA allows a fine of up to $200,000 and up to a year’s imprisonment against an individual, and up to $1 million against the organisation.

The rule Who it binds If you don’t Source
What the Act provides for, on conviction An individual custodian, and an organisation A statutory maximum of $200,000 and up to one year’s imprisonment for an individual; $1,000,000 for an organisation
Statutory maximum on conviction — state it as a maximum, never as a typical outcome.
Information and Privacy Commissioner of Ontario — potential consequences of a breach under PHIPA
The duty to report a theft Every health information custodian A reporting duty triggered by the incident itself Information and Privacy Commissioner of Ontario — reporting a privacy breach
A separate duty to tell the patients Every health information custodian Independent of whether the IPC must be notified Information and Privacy Commissioner of Ontario — reporting a privacy breach
An annual filing, with a date Every health information custodian Due every 1 March, for the previous calendar year Information and Privacy Commissioner of Ontario — annual reporting of privacy breach statistics
A partner’s conditions, signed before you connect Any custodian using the provincial electronic health record Safeguards are a term of the agreement, not a recommendation
A contractual duty owed to Ontario Health, separate from PHIPA — the obligation arrives from a partner, not the Commissioner.
Ontario Health — EHR agreements with health information custodians and coroners
Report a breach that could seriously harm someone Every organisation subject to PIPEDA Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. PIPEDA s.10.1(1) — report to Commissioner
Notify the people affected Every organisation subject to PIPEDA The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. Privacy Commissioner of Canada
Keep a record of EVERY breach for two years Every organisation subject to PIPEDA Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. Breach of Security Safeguards Regulations, s. 6(1)
Make those records good enough to audit Every organisation subject to PIPEDA A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. Privacy Commissioner of Canada
Satisfy your insurer before you need to claim Any firm that wants cyber cover A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. Coalition Insurance Solutions Canada — cyber questionnaire
Answer your client’s regulator, not just your own Any firm holding a federally regulated client’s data A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024)
An individual found guilty of committing an offence under PHIPA can be liable for a fine of up to $200,000 or up to one year in prison, or both. An organization or institution can be liable for a fine of up to $1,000,000.

Information and Privacy Commissioner of Ontario — potential consequences of a breach under PHIPA

Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.

Every one of these duties begins the same way: you notice. A duty to report presupposes detection, and nothing in the legislation makes detection happen on its own.

Would your patients find out before you did?

No cost, no obligation — you keep the findings either way.

  1. Tell us your domain

    One short form. No access to your systems, no software to install.

  2. We look from the outside

    Passive, publicly observable checks only — the same view an attacker gets.

  3. You get one page

    Your top findings in plain English — one page, no meeting required.