By
Adam Simmons
· Last checked
August 2026
The Ontario privacy commissioner's published position on emailing clients is "where feasible, custodians should use encryption for email communication with patients" (IPC fact sheet).
That is softer than a requirement and firmer than a suggestion, and the rest of the fact sheet explains what to do when encryption is not feasible — which, for most solo practices communicating with clients who use ordinary consumer email, it is not.
"If encryption is not feasible, custodians should determine whether it is reasonable to communicate with their patients through unencrypted email," and it sets out six things to weigh: the characteristics of the information, the volume and frequency, the purpose of the transmission, what the client expects, the availability of alternative methods, and whether the circumstances are urgent. Then: "Having considered all of the above, the custodian must be satisfied that the use of unencrypted email is reasonable. If a custodian is not satisfied that it is reasonable, then the custodian should not communicate with patients by this method."
So the practical answer for most practices is not "buy encrypted email." It is "decide what may travel by ordinary email, write that down, tell clients, and stick to it."
The Ontario privacy commissioner's published position on emailing clients is "where feasible, custodians should use encryption for email communication with patients" (IPC fact sheet).
That is softer than a requirement and firmer than a suggestion, and the rest of the fact sheet explains what to do when encryption is not feasible — which, for most solo practices communicating with clients who use ordinary consumer email, it is not.
"If encryption is not feasible, custodians should determine whether it is reasonable to communicate with their patients through unencrypted email," and it sets out six things to weigh: the characteristics of the information, the volume and frequency, the purpose of the transmission, what the client expects, the availability of alternative methods, and whether the circumstances are urgent. Then: "Having considered all of the above, the custodian must be satisfied that the use of unencrypted email is reasonable. If a custodian is not satisfied that it is reasonable, then the custodian should not communicate with patients by this method."
So the practical answer for most practices is not "buy encrypted email." It is "decide what may travel by ordinary email, write that down, tell clients, and stick to it."
What the commissioner expects if you use ordinary email
Three things, all quoted.
A written policy. "Custodians should develop and implement a written policy for sending and receiving personal health information by email. The policy should address when, how and the purposes for which this information may be sent and received by email, as well as any conditions or restrictions on doing so."
Notice and consent. "Custodians must notify their patients about their written email policy and obtain their consent prior to the use of unencrypted email. The consent should be in plain language and indicate the types of information that may or may not be communicated by unencrypted email, the risks of using unencrypted email and the circumstances where the custodian will use unencrypted email."
Data minimisation. "Even if a patient agrees to communicate by email, this does not mean that all personal health information should be sent by this method. The custodian still has a duty to limit the amount and type of personal health information included in an email."
The fact sheet's own worked example is the one most practitioners land on: "custodians may limit the use of unencrypted email to the scheduling of appointments only and have a policy of not sending or receiving any clinical information via unencrypted email."
Does a College require encryption?
One of them does, in plain words. Most do not, and the ones that do not say something softer that is easy to over-read.
Ontario's psychotherapy standard requires registrants to "take reasonable steps to ensure that the technology employed is secure, confidential, and appropriate, given the needs of the client" (CRPO 3.4.3), and the College's guideline names encryption as an example rather than a rule: "Using technologies and/or devices that provide encryption, require a password, or which possess other features designed to prevent data loss, unauthorized use and access are examples of reasonable measures a registrant can employ" (CRPO Electronic Practice Guideline).
The Ontario social work practice notes point members at the commissioner rather than setting a technical standard of their own: members "are strongly advised to review and follow any recommendations/advisories from the Office of the Information and Privacy Commissioner (IPC) which may be applicable to their practices," naming this exact fact sheet (OCSWSSW).
Elsewhere the wording gets firmer, and in one case considerably so.
Ontario psychology states it as a requirement rather than as a factor to weigh: "Electronic records must be encrypted before transmission. Registrants must verify the practices of their technology provider and seek guidance from relevant authorities (for example, the relevant Information and Privacy Commissioner) if uncertain about the current minimum requirements" (CPBAO Standard 9.5(c)). That is the firmest published line of the lot, and note the second sentence — it puts checking your provider's practices on you, by name.
Alberta psychology folds it into a list of safeguards an electronic client record must have, one of which is that "appropriate password and encryption controls are used" (CAP §7.6.2).
Ontario social work sets the floor at passwords rather than encryption: "Hard copies shall be secured by lock and key and electronic records shall be password protected" (OCSWSSW 4.2.6).
Nova Scotia psychology says the thing about email that most people assume is already handled for them: "Typically, regular email accounts are often not encrypted unless specifically setup with encryption settings" (NSRP, Use of Technology by Psychologists).
British Columbia publishes no encryption requirement in its communications standard at all. The rule there is that electronic communications are used "only when appropriate in the context of the Ethics and Practice Standards and when the expectations of the Standards can be met through their use" (CHCPBC, Practice Standard: Communications).
Why encrypted email is harder than it sounds
The obstacle is not on your side. It is that email encryption generally requires something of the recipient too, and your recipient is a client using whatever email they already have.
Practitioners describe three patterns.
A secure portal with email notifications. The message never actually travels by email; the email just says there is something to read. This is how most practice-management software solves it, and it is the closest thing to a real answer.
A "secure send" feature that emails a link plus a password. Works, but adds a step the client has to complete, and clients frequently do not.
Ordinary email, narrowly scoped, with consent. The commissioner's documented fallback. Cheapest, most common, and entirely defensible if the scope really is narrow.
The honest recommendation
For a solo practice, the highest-value move is usually not buying an encryption product. It is removing the reason to email clinical content at all.
If scheduling happens in a booking tool, intake happens on a form, and clinical conversation happens in session, then the only thing left in email is logistics — and the commissioner's guidance already tells you how to handle logistics by ordinary email.
If your practice genuinely needs to exchange documents with clients — reports, assessments, letters — then a portal is the thing to look for, and encrypted email is the second-best version of it.
One thing worth doing today
The commissioner's list of administrative safeguards includes an item that costs nothing: "communicating by email from professional, rather than personal accounts (personal accounts may have weaker security levels and may be more susceptible to compromise)."
A separate practice email address, used only for the practice, is the single cheapest improvement available.
About Rivet
Rivet is a Canadian practice line built for therapists — a separate number for calls, texts and voicemail, with video sessions and clinical tools in the same place. Your data stays in Canada, and transcription runs on Rivet's own hardware rather than a third-party AI service.
One plan, $65 CAD a month, everything included. Fourteen-day trial, no card.