You're the custodian. That word does a lot of work.
Under PHIPA, a health information custodian is personally responsible for safeguarding client information — wherever it lives, however it got there. Not your software vendor. Not your landlord's Wi-Fi. You.
The rules grew teeth
Since January 2024, Ontario's privacy commissioner can issue administrative monetary penalties directly — no court required. Enforcement against individual practitioners is no longer hypothetical. The question a custodian has to be able to answer is simple: where does client information live, who can touch it, and can you prove it?
What "reasonable safeguards" looks like at your size
You don't need a hospital's security department. You need: one known home for client files, encryption, access limited to each person's caseload, working backups, trained staff, and records showing all of it. That's the whole list — and it's exactly the list this service exists to check off.
Your vendors are your problem too
PHIPA holds custodians responsible for the agents and services they use. Every tool that touches client data should be able to tell you where the data is and sign an agreement saying so. Mine does, and I'll help you ask the same question of everything else in your stack.
I'm an IT provider, not a lawyer — this page is orientation, not legal advice.