If you run a clinic in Ontario, there is a reasonable chance your PHIPA compliance system looks something like this: a shared drive folder with a privacy policy (last updated in 2021), a spreadsheet where someone entered staff training dates once, a signed confidentiality agreement template in a filing cabinet, and a vague understanding that "the EMR handles the records."
This is not unusual. It is also not what the Information and Privacy Commissioner of Ontario will accept if your clinic is investigated.
What the IPC actually expects
In August 2025, the IPC issued its first administrative monetary penalties under PHIPA (Decision 298). The dollar amounts were modest — $7,500 for the clinic — but the decision defined a demanding standard: "a repeatable and demonstrable system of data governance whereby organisations can show regulators more concretely, backed by evidence, how they meet their legal requirements in practice."
The operative words are repeatable, demonstrable, and evidence. A folder on a shared drive can hold a document. What it cannot do is demonstrate repeatability, produce evidence of ongoing compliance, or prove that the version the IPC is looking at is the current one.
The five ways the spreadsheet approach fails
1. Version control doesn't exist
Privacy policies must reflect current practices. When you changed cloud providers in 2023, did the policy get updated? A shared folder has no verifiable version history. A row that says "Policy reviewed — March 2024" proves nothing about what the policy said or whether it changed after.
2. Training records are a snapshot, not a system
PHIPA requires custodians to ensure every agent is aware of their obligations, with annual renewal and individual completion records. A spreadsheet of names and dates is not verifiable evidence that training occurred, what it covered, or when the date was entered.
3. Your EMR is not your compliance system
Your EMR (OSCAR, PS Suite, Accuro, Jane App) manages and stores personal health information. It was never designed to document that your policy is current, track vendor agreements, walk staff through a breach, generate an IPC-ready export, or track confidentiality renewals. PHIPA makes the custodian responsible for all of that.
4. Vendor agreements fall through the cracks
Every third party that handles PHI on your behalf is an agent under PHIPA, and each one needs a data processing agreement. That covers your EMR vendor, your cloud backup, IT support, the billing service. Clinics on the DIY model almost universally lack these, because tracking them isn't anyone's job. When a vendor causes a breach, the IPC's first question is whether the custodian had an agreement in place.
5. Breach response requires a system that works under pressure
When a breach happens, you have hours, not days. The IPC expects immediate containment, notification at "the first reasonable opportunity" (roughly 72 hours in most cases), and annual reporting of all breaches. A clinic that has never written its breach response down will not handle this well under stress.
What a working compliance system looks like
The IPC's "repeatable and demonstrable" standard means your system should work the same way every time, no matter which staff member is involved, and you should be able to produce evidence at any point. In practice:
- A living policy vault that is versioned, shows who reviewed what and when, and keeps previous versions locked read-only.
- Individual training logs covering what each staff member completed, when, in what format, and when it's next due, with automatic renewal reminders.
- Vendor agreement tracking that puts every vendor touching PHI in a register, with agreement status and expiry.
- A breach response workflow any staff member can execute, with the IPC protocol stages built in and notification letters templated.
- Audit log review as a regular, documented process for spotting anomalies in access logs.
- An IPC-ready export so you can produce, at any time, a compliance summary that matches what an investigator expects.
The DIY alternative isn't wrong. It's incomplete.
Compliance under the IPC's standard requires continuous, evidenced operation. A spreadsheet is a static record, not an operating system. A good system shouldn't add work. It should make compliance happen in the background, with documentation that builds itself, so the clinic can get back to patients.
Where to start: your free PHIPA gap assessment
Structura Health's free PHIPA scorecard takes about three minutes, requires no login, and maps your current practices against the six areas Decision 298 puts a custodian on the hook for. You get back a prioritised list of your highest-risk gaps.
Take the free PHIPA scorecard →
Keep reading: Ontario's first PHIPA fine: what the IPC found missing · PHIPA vs HIPAA: why US tools don't cover you · the platform that replaces the spreadsheet · take the free scorecard