By
Adam Simmons
· Last checked
August 2026
Three things happen in order: contain it, notify the person whose information it was, and work out whether the regulator has to hear about it. The third question is the one people get stuck on, and for most small incidents in Ontario the answer is no — while the second is almost always yes.
Ontario's health privacy act sets the notification duty without a harm threshold. If personal health information "is stolen or lost or if it is used or disclosed without authority," the custodian shall "notify the individual at the first reasonable opportunity of the theft or loss or of the unauthorized use or disclosure" and "include in the notice a statement that the individual is entitled to make a complaint to the Commissioner" (PHIPA, s. 12(2)).
A text sent to the wrong client is a breach. So is a laptop left on a train. The size of the incident affects what you do about it, not whether it counts.
Three things happen in order: contain it, notify the person whose information it was, and work out whether the regulator has to hear about it. The third question is the one people get stuck on, and for most small incidents in Ontario the answer is no — while the second is almost always yes.
Ontario's health privacy act sets the notification duty without a harm threshold. If personal health information "is stolen or lost or if it is used or disclosed without authority," the custodian shall "notify the individual at the first reasonable opportunity of the theft or loss or of the unauthorized use or disclosure" and "include in the notice a statement that the individual is entitled to make a complaint to the Commissioner" (PHIPA, s. 12(2)).
A text sent to the wrong client is a breach. So is a laptop left on a train. The size of the incident affects what you do about it, not whether it counts.
What the commissioner says to do first
The Ontario commissioner's published guidance sets out four steps: notify staff and other custodians, identify the scope and contain it, notify the affected individuals and where required the IPC and the Colleges, then investigate and remediate. In a solo practice the first step collapses into the second.
On containment: "Identify the scope of the breach, including individuals or organizations who may have been involved with or are responsible for the breach, and the nature and quantity of PHI that is affected." Then "retrieve any copies of PHI that have been disclosed" and "ensure that no copies of PHI have been made or retained by anyone who was not authorized to receive the information. Record the person's contact information in case follow-up is required" (IPC, Responding to a Health Privacy Breach).
What goes in the notification
The commissioner's guidance lists what to tell the person, and having the list in front of you makes a hard phone call much easier:
"where appropriate, the name of the agent responsible for the unauthorized access"
"the date of the breach"
"a description of the nature and scope of the breach"
"a description of the PHI that was subject to the breach"
"the measures implemented to contain the breach"
"the name and contact information of the person in your organization who can address inquiries"
Plus the statutory line: "Notice to affected individuals must include a statement letting them know they are entitled to make a complaint to the IPC."
The guidance also notes the notification does not have to be a letter: "Notification can be by telephone or in writing. Depending on the circumstances, you can make a notation in the individual's file to discuss at their next appointment."
When does the Ontario commissioner have to be told?
Only in prescribed circumstances, and the commissioner's own guidance is refreshingly clear about what falls outside them.
"You generally do not need to notify the IPC when the breach is accidental, for example, if information is inadvertently sent by email or courier to the wrong person, or a letter is placed in the wrong envelope. Also, you do not need to notify the IPC when a person who is permitted to access patient information accidentally accesses the wrong patient record. However, you must report even accidental privacy breaches if they fall into one of the other categories" (IPC, Reporting a Privacy Breach to the IPC).
The categories themselves are in the regulation — seven of them, including where information "was used or disclosed without authority by a person who knew or ought to have known that they were using or disclosing the information without authority"; where it "was stolen"; where after an initial breach the information "was or will be further used or disclosed without authority"; where the incident "is part of a pattern of similar losses"; and where the custodian "determines that the loss or unauthorized use or disclosure... is significant after considering all relevant circumstances" (O. Reg. 329/04, s. 6.3).
The report, where required, goes "at the first reasonable opportunity."
The annual count almost nobody knows about
Separate from any individual incident: "On or before March 1 in each year... a health information custodian shall provide the Commissioner with a report setting out the number of times in the previous calendar year" that information was stolen, lost, used without authority, or disclosed without authority (O. Reg. 329/04, s. 6.4).
The commissioner's guidance adds: "You must also count every breach in your annual statistics report to the IPC."
This is a count, not a narrative. It is also a good reason to keep a simple running log rather than trying to reconstruct the year in February.
Outside Ontario
Quebec's threshold and mechanics are different. A person who "has cause to believe that a confidentiality incident... has occurred must take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature." Where the incident "presents a risk of serious injury," they "must promptly notify the Commission d'accès à l'information" and "any person whose personal information is concerned by the incident." There is also a standing obligation to "keep a register of confidentiality incidents" (P-39.1, ss. 3.5–3.8).
For British Columbia, Alberta and the Atlantic provinces the trigger and the recipient differ again, and the threshold is published by each province's own commissioner rather than by anyone else. The offices are named in privacy law for therapists outside Ontario.
Two things do travel. The federal threshold is harm-based: an organization must "report to the OPC any privacy breaches that pose a real risk of significant harm to an individual," and "anytime you determine that a breach of security safeguards poses a real risk of significant harm to an individual, you must notify the individual(s) concerned." Significant harm is defined broadly, and includes "humiliation, damage to reputation or relationships" alongside financial loss and identity theft.
And there is a record-keeping duty that catches almost everybody: "The law requires you to keep breach records of all breaches of security safeguards for two years" (OPC). All breaches — not only the reportable ones. Which is the same conclusion the Ontario annual count arrives at from the other direction: keep a log.
Your College may add its own expectation on top. British Columbia's regulator asks licensees to "Take prompt steps to contain a privacy breach and prevent a reoccurrence," and to report a breach in the manner privacy legislation requires — pointing at the statute rather than restating it (CHCPBC, Practice Standard: Privacy and Confidentiality). Nova Scotia's psychology guidance asks registrants to have settled it in advance: "Have a plan if a breach of privacy ever occurs. In other words, who needs to be notified? What sort of notification would be provided? What other remedial steps should be taken?" (NSRP).
Whether your College also needs to know
Separate question, and one of the seven Ontario reporting circumstances is tied to it — a custodian must notify the commissioner where they are "required to give notice to a College" of an event relating to a loss or unauthorised disclosure.
What Ontario's psychotherapy College publishes is the statutory duty restated as a professional one. Registrants demonstrate the confidentiality standard by "Promptly notifying the client and, if applicable, the Information and Privacy Commissioner (IPC) when the client's personal health information is stolen or lost or when it is used or disclosed without authority" (CRPO Standard 3.1).
Read what that does and does not do. It makes the notification you already owe under the statute enforceable through the College as well. It does not create a separate duty to report yourself to the College. Whether one exists for your profession is a question the practice advisory line answers in a single call, and it is a much better call to make before you need it.
The practical version
Write down what happened, in order, with times, on the day. Contain first. Tell the client early rather than once you have a complete account — the standard is "first reasonable opportunity," not "once the investigation is finished."
Then change the thing that made it possible. A pattern of small accidental breaches is itself a reportable category, precisely because a pattern means the fix never happened.
About Rivet
Rivet is a Canadian practice line built for therapists — a separate number for calls, texts and voicemail, with video sessions and clinical tools in the same place. Your data stays in Canada, and transcription runs on Rivet's own hardware rather than a third-party AI service.
One plan, $65 CAD a month, everything included. Fourteen-day trial, no card.