PIPEDA for Ontario Care Providers — What Disability and LTC Agencies Need to Know (2026)

Canadian care providers operate under a two-layer privacy framework: the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Ontario health information specifically, the provincial Personal Health Information Protection Act (PHIPA). Understanding which law applies to which types of information — and what your obligations are under each — is essential for any disability support agency or long-term care home handling sensitive participant and resident data.

This article provides general information about Canadian privacy law as it applies to care providers. It is not legal advice. Consult a qualified privacy lawyer for specific obligations relevant to your organisation. Last reviewed: Aug 2026.

PIPEDA — The Federal Framework

PIPEDA applies to the collection, use, and disclosure of personal information in the course of commercial activity. For Ontario disability support agencies and LTC homes, this means PIPEDA governs how you handle information about workers, contractors, and — in most circumstances — the people you support.

PIPEDA is built around ten fair information principles:

  • Accountability — Your organisation is responsible for protecting personal information and must designate an individual responsible for privacy compliance (a Privacy Officer)
  • Identifying purposes — You must identify why you're collecting information at or before the time of collection
  • Consent — You must obtain meaningful consent for collection, use, or disclosure of personal information
  • Limiting collection — Collect only what you need for identified purposes; don't collect more than necessary
  • Limiting use, disclosure, and retention — Use information only for the purposes for which it was collected; don't retain it longer than needed
  • Accuracy — Keep personal information accurate, complete, and up to date
  • Safeguards — Protect personal information with security appropriate to its sensitivity
  • Openness — Make your privacy policies and practices publicly available
  • Individual access — Individuals must be able to access their personal information and challenge its accuracy
  • Challenging compliance — Individuals must be able to challenge your compliance with these principles

PHIPA — Ontario Health Information

PHIPA is Ontario's provincial health privacy law. It applies specifically to personal health information (PHI) — information about an individual's physical or mental health, their health care history, their eligibility for health or social services, and information used to pay for health care services.

For care providers, PHIPA is highly relevant because it governs the care records you create and store: participant progress notes, clinical observations, care plans, ADL charts, incident reports involving health-related matters, and medication records.

Who is a "Health Information Custodian" under PHIPA?

PHIPA applies to health information custodians — a defined term that includes regulated health professionals, hospitals, and certain other health facilities and programs. Whether a disability support agency or LTC home is a health information custodian under PHIPA depends on the nature of the services provided and the organisation's structure.

LTC homes in Ontario are generally considered health information custodians under PHIPA. Disability support agencies may or may not be, depending on the nature of their services. If you are unsure whether PHIPA applies to your organisation, seek legal advice specific to your services.

Key PHIPA Obligations for LTC Homes

If your LTC home is a health information custodian under PHIPA:

  • Consent for collection and use — Residents must consent to the collection and use of their personal health information. Implied consent is available for providing health care directly to the resident; express consent is required for other purposes
  • Access rights — Residents have the right to access their own health records, request corrections, and request that records not be disclosed in certain circumstances
  • No disclosure without consent — You cannot disclose a resident's health information to third parties (family members, employers, insurers) without consent, except in specific circumstances defined by PHIPA
  • Agent obligations — People who handle health information on your behalf (staff, software vendors) are your "agents" under PHIPA and must comply with your PHIPA obligations
  • Breach notification — If health information is used or disclosed without authority, you must notify affected individuals and the Information and Privacy Commissioner of Ontario (IPC)

What This Means for Software Vendors

If you use software to store participant or resident information — including scheduling software, care documentation platforms, or timesheet tools — that software vendor handles personal information on your behalf. Under PIPEDA, they are a third-party processor; under PHIPA, they may be your agent.

Before choosing a software platform, ask:

  • Where is the data stored? Is it stored in Canada or overseas? If overseas, what protections apply?
  • Is the vendor willing to enter a data processing agreement? Under PIPEDA, you remain accountable for personal information handled by third parties on your behalf
  • What security measures are in place? Encryption at rest, encryption in transit, access controls, audit logging
  • What happens to your data if you cancel? You need to be able to export your records before cancellation and have clarity on deletion timelines
  • Who has access to your data within the vendor? Staff access should be limited to what's necessary and logged

KareShift stores all Canadian customer data in AWS Sydney (ap-southeast-2, Australia). We comply with PIPEDA and PHIPA obligations. See our Privacy Policy for full details.

Consent is the cornerstone of both PIPEDA and PHIPA. In practice, this means:

  • Intake documentation must explain what information you collect and why. Service agreements, intake forms, and orientation materials should clearly describe the information you'll collect and how it will be used
  • Consent must be meaningful. Buried consent in fine print, or consent obtained without the person understanding what they're agreeing to, is not valid consent under PIPEDA
  • For health information under PHIPA, implied consent is available for direct care purposes — you don't need explicit consent each time a nurse writes a progress note. But you do need express consent to share health information with the person's employer, insurance company, or other non-care purposes
  • Individuals can withdraw consent — subject to legal or contractual restrictions. Build a process for handling withdrawal requests; you must continue to handle existing records appropriately even after consent is withdrawn
  • Document your consent. For each participant or resident, keep a record of what consents were obtained, when, and how

Data Breach Notification

Under PIPEDA (specifically the Breach of Security Safeguards Regulations, which came into force in November 2018), you must:

  • Notify the Privacy Commissioner of Canada if a breach of security safeguards involving personal information poses a real risk of significant harm to individuals
  • Notify affected individuals as soon as feasible if the breach poses a real risk of significant harm to them
  • Maintain a record of every breach of security safeguards, regardless of whether it meets the notification threshold — the Privacy Commissioner can request this record at any time

"Real risk of significant harm" includes the risk of bodily harm, humiliation, financial loss, identity theft, damage to reputation, and loss of employment. For a disability support agency or LTC home, a breach involving health information, behavioural support plans, or financial details would almost certainly meet this threshold.

Prepare now, not after an incident. Your breach response plan should include: who to notify internally, who contacts the Privacy Commissioner, who contacts affected individuals, who leads the investigation, and how you document the breach and your response.

Worker Information

PIPEDA also governs personal information about your workers. Key obligations:

  • Worker files — employment history, performance reviews, disciplinary records, health information — must be held securely and accessed only by those with a legitimate need
  • Workers have the right to access their own personal information held by the employer, subject to certain exceptions
  • Background check results (Vulnerable Sector Checks) are sensitive personal information — access should be limited and records secured
  • Video surveillance in workplaces is regulated under PIPEDA — if you use cameras in your facilities, ensure you have a clear policy, appropriate notice, and limiting use principles in place

Privacy compliance for care providers isn't just about policy documents — it's about building practices where the people you support can trust that their sensitive information is handled with care. That trust is foundational to the service relationship. Learn how KareShift helps Ontario agencies handle participant data securely.

Secure, PIPEDA-aware care management for Ontario providers

KareShift stores your participant and resident data securely with encryption at rest and in transit. 90 days free — no credit card required.

Start Free Trial