PHIPA — ONTARIO · INFORMATIONAL GUIDE

PHIPA compliance checklist for Ontario clinics

Ten concrete things to weigh when your clinic chooses tools that touch patient information — including a phone answering service. For each item, here's how Callara can support you.

Read first: This is general information, not legal advice. PHIPA has no “certification.” Your clinic remains the health information custodian; Callara is a service provider (agent) and does not certify your clinic's compliance.
1

Know your role: custodian vs. agent

Under PHIPA, your clinic is the health information custodian. Any vendor that handles personal health information on your behalf is an agent. Confirm in writing which party is which, and that the agent only uses the information for the purposes you authorize.

With Callara: Callara acts as your agent, not a custodian — your clinic remains the custodian. Callara does not decide how to use patient information; it follows your instructions and provides an Agent Agreement on request.

2

Keep data in Canada

Decide where personal health information is stored and processed, and confirm your vendors keep it in Canada where possible to reduce cross-border exposure.

With Callara: Callara stores data in Canada (Supabase, Toronto region). Your data does not leave the country in normal operation.

3

Encrypt data in transit and at rest

Personal health information should be encrypted while moving over networks and while stored. Ask each vendor which standards they use.

With Callara: Callara encrypts data in transit (TLS 1.3) and at rest (AES-256).

4

Control access and keep audit logs

Limit who can see patient information, and keep logs of access so you can review who saw what and when.

With Callara: Callara keeps full audit logs of access and supports role-based access to your account.

5

Put a written agreement in place with each vendor

Have a written agreement with any service provider that handles personal health information, setting out safeguards, permitted uses, and responsibilities.

With Callara: Callara provides an Agent Agreement and a Data Processing Addendum (DPA) on request for Ontario clinics.

6

Collect only what you need, with consent

Limit collection to what's needed for the purpose, and handle consent for how information is collected and used.

With Callara: You configure what Callara asks callers for, so it collects only the details your intake needs — no more.

7

Have a breach-response process

Know how you'll detect, contain, and report a privacy breach, and how your vendors will notify you if one occurs on their side.

With Callara: Callara notifies your Privacy Officer if a breach affecting your data is identified, so your clinic can meet its own reporting obligations. Ask us for the specifics in writing.

8

Set retention and deletion rules

Decide how long information is kept and confirm you can have it deleted when it's no longer needed or on request.

With Callara: Callara deletes your records on request. Confirm the timelines that fit your retention policy with us in writing.

9

Support patient access and correction

Patients have the right to access and request correction of their records. Make sure you can retrieve information held by your vendors.

With Callara: Callara can export the records associated with your account on request so you can respond to patient access requests.

10

Train your team and document your safeguards

Train staff on privacy handling and keep documentation (like a Privacy Impact Assessment) of the safeguards you and your vendors have in place.

With Callara: Callara can provide documentation to support your Privacy Impact Assessment (PIA). Training your own staff remains your clinic's responsibility.

FAQ

Is this checklist legal advice?

No. It's general, educational information to help Ontario health practices think through PHIPA when choosing tools and vendors. For advice specific to your clinic, consult a privacy professional or lawyer, and see the Ontario IPC's official guidance.

Is Callara "PHIPA compliant" or certified?

PHIPA does not have a certification. Compliance is a property of your practice and how it operates — not something a vendor certifies on your behalf. Callara is a service provider (agent) that offers concrete safeguards — Canadian data residency, encryption, audit logs, and an Agent Agreement/DPA on request — to support your own PHIPA obligations.

Does Callara replace our privacy program?

No. Your clinic remains the health information custodian and is responsible for its own policies, staff training, and reporting. Callara supports specific technical and contractual safeguards as your agent.

How do we get the Agent Agreement and DPA?

Email privacy@callara.ca and mention that you're an Ontario clinic. We'll share the Agent Agreement and PHIPA Data Processing Addendum, plus documentation for your Privacy Impact Assessment.

An Ontario clinic evaluating an AI answering service?

Ask for our Agent Agreement and PHIPA DPA at privacy@callara.ca — or start a 7-day free trial.

PHIPA Compliance Checklist for Ontario Clinics | Callara