Skip to content
STRUCTURA HEALTH
All articles

PHIPA vs HIPAA: Why US Compliance Tools Don't Make Your Ontario Clinic Compliant

Vanta, Drata, and Accountable HQ are built for HIPAA — US federal law. Ontario clinics are governed by PHIPA, a fundamentally different regime. Here is exactly what US tools miss, and why the gap matters after Ontario's first PHIPA fine.

By Structura Health · Last verified

If you searched for "health privacy compliance software" this year, most of what you found was built for the United States. Vanta, Drata, Accountable HQ, Medcurity: all excellent tools for the American market, where the dominant framework is HIPAA.

Ontario clinics operate under PHIPA, the Personal Health Information Protection Act, enforced by the Information and Privacy Commissioner of Ontario. The two laws share vocabulary. They do not share requirements. Using a HIPAA-focused tool to manage PHIPA compliance isn't just insufficient. It hands you a false sense of security, and after the IPC's first enforcement action in August 2025, that is a riskier thing to lean on than it used to be.

The foundational difference: consent vs. permitted use

HIPAA runs on a "permitted uses" model. It defines categories where protected health information may be used or disclosed without patient consent (treatment, payment, healthcare operations).

PHIPA runs on a consent-first model. The default is that personal health information may only be collected, used, or disclosed with the patient's knowledge and consent, or as specifically authorised by the Act. Custodians have to be able to demonstrate that each use or disclosure had a valid basis.

That shapes how consent forms are structured, how referrals work, how information moves between providers, and how clinics document the basis for every disclosure. A HIPAA tool is built around HIPAA's framework. It has no mechanism for PHIPA's consent-tracking obligations.

Jurisdiction: one law, one province, one regulator

HIPAA is US federal law, enforced by the HHS Office for Civil Rights. PHIPA is Ontario provincial law, enforced by the IPC, which issues binding decisions and, as of August 2025, imposes AMPs up to $500,000 per organisation.

A US tool can produce SOC 2 reports, HIPAA attestations, and BAA workflows. None of these mean anything to the IPC. HIPAA applies to a Canadian clinic only in one narrow case: if it handles PHI for a US covered entity as a Business Associate. For most Ontario clinics, HIPAA simply does not apply.

The layered Canadian framework

  • PHIPA governs health information custodians in Ontario — physicians, dentists, physiotherapists, chiropractors, nurse practitioners, pharmacies, hospitals.
  • PIPEDA (federal) applies to cross-provincial and cross-border transfers of personal information; PHIPA is deemed substantially similar for within-province PHI.
  • Law 25 is Quebec's private-sector privacy law. If you treat Quebec patients, or your software processes Quebec residents' data, Law 25 applies, with penalties up to CAD $25 million or 4% of global turnover.

A US HIPAA tool is unaware of this framework entirely.

What US tools miss: the PHIPA-specific gap list

1. Health information custodian designation — a specific PHIPA legal category with defined obligations. 2. Designated contact person — PHIPA s.15 requires a designated privacy contact, publicly available. 3. IPC breach notification — at "the first reasonable opportunity" (Ontario sets no fixed hour count), serious breaches reported to the IPC. 4. Annual breach statistics report — filed with the IPC by early March each year. No HIPAA equivalent. 5. Consent-based disclosure documentation — demonstrating the basis for each use or disclosure. 6. Ontario-specific IPC guidance and decisions — including Decision 298, which define how obligations are interpreted.

What this means in practice

A HIPAA certification does not protect you under PHIPA. The IPC does not recognise HIPAA attestations, and the documentation a US tool generates is not what an IPC investigator expects. Now that Decision 298 has established that AMPs are real and reach small clinics, relying on the wrong framework carries materially more risk. None of this is a failure of the US tools. They do exactly what they were designed to do. It is a mismatch of jurisdiction.

A PHIPA-native system

Structura Health was built for the Ontario framework: gap assessments mapped to PHIPA's actual requirements, IPC breach workflows built around PHIPA’s "first reasonable opportunity" standard and the March 1 annual reporting deadline, consent documentation aligned with PHIPA's consent-first model, and coverage of PHIPA (Ontario), PIPEDA (federal), and Law 25 (Quebec) in a single system.

Find out where your clinic stands — free, no login required

Take the free PHIPA scorecard →


Sources: PHIPA, SO 2004, c 3, Sched A (ontario.ca/laws) · IPC Decision 298 (CanLII) · IPC managing breaches guidance · Law 25 guidance.

Keep reading: Ontario's first PHIPA fine: what the IPC found missing · DIY PHIPA compliance: why the spreadsheet approach breaks · Structura vs Vanta: why US GRC doesn't fit ON clinics · take the free scorecard

Check your clinic's PHIPA gaps — free, no login

Map your current practices against the six areas Decision 298 puts a custodian on the hook for. About three minutes, no account required.

Take the free PHIPA scorecard

Turn what you just read into documented governance.

Structura converts obligations like these into assigned, dated, evidenced tasks for your clinic.