Info, resources, advocacy. THANKS for your support!

Our rights: Health information privacy

Your Health Privacy Rights

  • Hospitals, doctors, mental health agencies etc. have obligations to protect privacy.
  • Enforced by the Information and Privacy Commission (//
  • Ontario’s health privacy legislation is the Personal Health Information Protection Act(PHIPA), establishes a set of rules regarding your personal health information (PHI).

PHIPA gives you the right to:

  • be informed of the reasons for the collection, use and disclosure of your personal health information;
  • be notified of the theft or loss or of the unauthorized use or disclosure of your personal health information;
  • refuse or give consent to the collection, use or disclosure of your personal health information, except in certain circumstances;
  • withdraw your consent by providing notice;
  • expressly instruct that your personal health information not be used or disclosed for health care purposes without your consent;
  • access a copy of your personal health information, except in limited circumstances;
  • request corrections be made to your health records;
  • complain to our office if you are refused access to your personal health information;
  • complain to our office if you are refused a correction request;
  • complain to our office about a privacy breach or potential breach; and

begin a proceeding in court for damages for actual harm suffered after an order has been issued or a person has been convicted of an offence under PHIPA.


Privacy Tip: Consent

Do you remember signing a consent or getting privacy information when you started with a new doctor, agency or health service?  Did you have a choice to sign the consent if you wanted to receive service? Consent explanations from the IPC Real CONSENT:

  • must be your consent or the consent of your substitute decision-maker
  • must be knowledgeable
  • must relate to the information that will be collected, used or disclosed
  • must not be obtained through deception or coercion

Consent should be time limited and it should only be for certain uses. For example, I want supportive housing but I might not want to have my information shared with a rehab facility. +

Privacy Principles for Health orgs

Key is consent, limited collection, limited use, and accountability / complaints process:

Principle 1 – Accountability

Principle 2 – Identifying Purposes for collecting

Principle 3 – Consent

Principle 4 – Limiting Collection

Principle 5 – Limiting Use, Disclosure, and Retention

Principle 6 – Accuracy

Principle 7 – Safeguards

Principle 8 – Openness

Principle 9 – Individual Access

Principle 10 – Challenging Compliance



April 2019 Events

April Event Guide 2019 February free events guide PDF

Bulletin 612 OPS, Privacy, Benefits

April 2019 #15 #612 DOWNLOAD and Print the paper Bulletin! DOWNLOAD Event Guide! thx Amber Graydon 1. Broken systems, changes The Ontario…

April Events 2019

April 5 Dinner with a View...Of the Rich What does $550 get you in Toronto you ask? The creators of…
Logo: 4 stylized stylized people in the middle of text: "Colour of Poverty Colour of Change"

Racialized Poverty in Health – Colour of Poverty—Colour of Change

Colour of Poverty—Colour of Change Fact sheets about poverty. The 2016 Census showed that 20.8% of peoples of colour in…

What should we include in the Food Issue?

Food Access, Advocacy, Fun

Create your own user feedback survey