Does PHIPA actually apply to my clinic? If your dental practice is in Ontario, yes, PHIPA is Ontario’s health-privacy law, and Ontario dentists fall under it directly. If your clinic is outside Ontario, a provincial equivalent usually applies instead; for example, British Columbia practices should look to BC’s privacy framework and federal privacy rules rather than PHIPA itself.
For Canadian dentists comparing privacy laws, it is also worth reading our HIPAA for Dental Practices article to understand why U.S. HIPAA language is often used online but does not automatically govern Canadian clinics.
The phrase PHIPA for dental practices matters because dental clinics handle sensitive personal health information every day: medical histories, radiographs, treatment plans, prescriptions, billing details, consent forms, and patient communications. The legal names change by province, but the practical duty is consistent: collect carefully, secure records properly, and disclose information only when permitted.

Does PHIPA Apply to Your Practice?
Ontario dentists are treated as health information custodians under PHIPA, and the law is overseen by the Information and Privacy Commissioner of Ontario (IPC). Ontario’s Personal Health Information Protection Act sets rules for the collection, use, and disclosure of personal health information.
If your practice is in BC, PHIPA does not apply directly. BC clinics should look to BC’s Office of the Information and Privacy Commissioner and BC’s Personal Information Protection Act (PIPA), while federal questions may involve the Office of the Privacy Commissioner of Canada and PIPEDA.
That said, the practical duties are similar across provinces: protect patient information, limit access, keep records accurate, and respond properly when patients request access or when a breach occurs.
What PHIPA Requires of Dentists
PHIPA requires dentists and dental clinics to treat patient information as confidential clinical data, not ordinary business information. In plain terms, you should collect only the personal health information needed for care, keep records accurate and secure, allow patients to access and request correction of their records, and name a contact person responsible for privacy questions. The IPC Guide to PHIPA describes PHIPA as a framework for the rights and obligations of health information custodians regarding personal health information.
Within the “circle of care,” dentists can often rely on implied consent to share relevant information for treatment purposes, such as communicating with another health information custodian involved in the patient’s care, unless the patient has expressly withheld or withdrawn consent. This is an area clinics often misunderstand: implied consent does not mean unlimited sharing; it means sharing necessary information for care within legally recognized limits.
The RCDSO reinforces similar record-keeping duties for Ontario dentists, including protecting patient confidentiality, securing records, and ensuring personal health information is collected, used, and disclosed only with consent or as permitted or required by PHIPA.
Breaches and What They Cost
If a privacy breach happens, the clinic should act quickly: contain the incident, identify what information was affected, notify the affected patient at the first reasonable opportunity, and report to the IPC in defined cases. A dental office should have a written breach-response protocol before anything happens, because trying to build one during a breach usually leads to confusion, delays, and inconsistent communication.
The consequences can be serious. On prosecution, PHIPA offences can lead to penalties of up to $200,000 and up to one year in jail for an individual, and up to $1,000,000 for an organization. Since January 1, 2024, the IPC has also had authority to issue administrative monetary penalties under PHIPA, with maximums of $50,000 for individuals and $500,000 for organizations.

Conclusion
PHIPA compliance for dentists is not just a legal checkbox. It affects how your clinic collects forms, stores records, trains staff, sends information, handles reviews, uses patient photos, and responds to access requests or breaches. Ontario clinics must treat PHIPA as a direct obligation, while clinics in other provinces should follow the equivalent provincial and federal privacy rules.
For dental practices, the safest approach is to build privacy into daily operations: written policies, staff training, secure systems, controlled access, patient consent workflows, and a clear breach-response plan.
FAQ
These questions address the situations dental clinics most often misunderstand when applying health privacy rules to real practice workflows.
Does PHIPA apply outside Ontario?
No, PHIPA is Ontario’s health-privacy law. Clinics outside Ontario generally follow their own provincial privacy law and, where applicable, PIPEDA. BC clinics, for example, should look to BC privacy rules rather than PHIPA directly.
Can I post before-and-after photos?
Only with proper patient consent. Before-and-after images can identify a patient, especially when combined with dates, treatment details, or facial features, so clinics should use clear written consent and explain where the images will appear.
Are dentists health information custodians?
In Ontario, yes. Dentists practising in Ontario are governed by PHIPA for the collection, use, and disclosure of personal health information, and RCDSO materials also reinforce the duty to protect patient records.



