Skip to content
STRUCTURA HEALTH
All articles

Ontario's first PHIPA fine: what the IPC found missing at the clinic

In August 2025, the IPC issued Ontario's first-ever PHIPA administrative monetary penalties. Here is exactly what was missing from the clinic that got fined — and the checklist every Ontario health information custodian needs to close those gaps.

By Structura Health · Last verified

On 27 August 2025, the Information and Privacy Commissioner of Ontario issued something that had never happened before: an administrative monetary penalty under the Personal Health Information Protection Act (PHIPA). The fines — $5,000 on a physician and $7,500 on his private clinic, WE Kidz Pediatrics — were modest in dollar terms. The signal they sent was not modest at all.

This post breaks down exactly what the IPC found, what was missing from the clinic that was penalised, and what every Ontario health information custodian needs to have documented before the next investigation lands on their desk.

What happened in IPC Decision 298?

Dr. Omar Afandi, a physician with privileges at Windsor Regional Hospital, misused his access to a shared electronic health record system over a three-week period in early 2024. He conducted 146 targeted searches for newborn males. He then used that information to solicit at least 91 families for circumcision services at his private clinic, WE Kidz Pediatrics, without their consent and entirely for commercial gain.

Windsor Regional Hospital filed a breach report with the IPC in May 2024. The IPC investigated and, on 27 August 2025, issued Decision 298: the first use of PHIPA's administrative monetary penalty (AMP) powers since they came into force on 1 January 2024.

The maximum penalty under PHIPA is $50,000 per individual and $500,000 per organisation. The IPC has said it will reserve AMPs for serious cases. It has been just as clear that deliberate misuse of health information for economic gain is one of them.

What did the clinic lack?

The hospital, Windsor Regional, largely had its house in order: written privacy policies, annual reviews, mandatory staff training, and confidentiality agreements for credentialed staff. The hospital was not penalised.

WE Kidz Pediatrics, a health information custodian in its own right, was a different story. The IPC's analysis pointed to what it called "systemic neglect": no documented privacy management framework, no staff training records, no breach response protocols, nothing linking staff conduct to the clinic's privacy obligations.

The IPC described the standard it expects all health information custodians to meet:

"A repeatable and demonstrable system of data governance whereby organisations can show regulators more concretely, backed by evidence, how they meet their legal requirements in practice."

The IPC is not asking whether your policies exist. It is asking whether you can prove, with documented evidence, that those policies are actually being followed, over and over, in a way you can show.

What the IPC said every custodian must do

Beyond the penalties, IPC Decision 298 included recommendations directed at all health information custodians. The IPC advised custodians to:

  • Date every privacy policy and procedure document (undated policies cannot prove currency)
  • Require printed names alongside signatures on all confidentiality agreements
  • Track annual training completion for every staff member individually
  • Document annual renewal of confidentiality commitments
  • Update professional staff bylaws and credentialing materials to include explicit references to PHIPA obligations

These are not aspirational best practices. Inside an IPC investigation, they are the difference between demonstrating compliance and demonstrating neglect.

The six things your clinic needs documented today

If the IPC asked you to demonstrate PHIPA compliance tomorrow, you would need to produce:

1. Written, dated privacy policies that reflect how your clinic actually operates, not a template downloaded in 2019.

2. Staff training records. Individual completion records, by staff member, by date, renewed annually.

3. Signed confidentiality agreements with printed names, dates, and an annual renewal process, covering everyone who touches personal health information, including contractors and IT vendors.

4. A breach response procedure that is written, tested, and known to the staff who would execute it. The IPC's protocol: Contain, Notify, Investigate, Prevent.

5. Audit log monitoring. A process for reviewing electronic health record access logs, plus evidence that the process actually runs.

6. Vendor agreements. A data processing agreement with every third party that handles personal health information on your behalf.

The "size exemption" that doesn't exist

One of the most important sentences in IPC Decision 298: "Size does not exempt a custodian from responsibility. Once an entity has custody or control of PHI, it must meet the obligations set out in PHIPA."

A solo family physician. A two-dentist practice. A physiotherapy clinic with six staff. All are health information custodians. All are subject to exactly the same obligations as a hospital.

The practical problem most clinics face

Most Ontario clinics know they are subject to PHIPA. Very few have the documentation the IPC now expects. The gap is not ignorance of the law. It is the day-to-day machinery of compliance: keeping policies current, tracking training, managing vendor agreements, maintaining audit logs, and having a breach response that holds up under pressure. A spreadsheet can hold a list. It cannot enforce deadlines, track completions, generate a tamper-evident audit trail, or walk a staff member through a breach response in real time.

That is the gap Structura Health is built to close.

Check your compliance gaps now — free, no login required

Structura Health offers a free PHIPA scorecard that maps your clinic's current practices against the six areas Decision 298 puts a custodian on the hook for. It takes about three minutes, requires no account, and gives you a ranked list of your highest-risk gaps.

Take the free PHIPA scorecard →


Sources: IPC PHIPA Decision 298 (2025 CanLII 85580) · BLG analysis · CBC News (Windsor) · IPC managing breaches guidance.

Keep reading: DIY PHIPA compliance: why the spreadsheet approach breaks · PHIPA vs HIPAA: why US tools don't cover you · the five pillars of a working compliance program · take the free scorecard

Check your clinic's PHIPA gaps — free, no login

Map your current practices against the six areas Decision 298 puts a custodian on the hook for. About three minutes, no account required.

Take the free PHIPA scorecard

Turn what you just read into documented governance.

Structura converts obligations like these into assigned, dated, evidenced tasks for your clinic.