By

Adam Simmons

· Last checked

August 2026

Who can see my client communications?

Who can see my client communications?

Who can see my client communications?

More people than the marketing implies and fewer than the anxiety suggests. Here is the actual list — carrier, vendor, sub-processors, courts — and what the rules say each of them may do.

More people than the marketing implies and fewer than the anxiety suggests. Here is the actual list — carrier, vendor, sub-processors, courts — and what the rules say each of them may do.

More people than the marketing implies and fewer than the anxiety suggests. Here is the actual list — carrier, vendor, sub-processors, courts — and what the rules say each of them may do.

Five categories of people, in descending order of how often they actually look: you, the client's own household, the companies delivering the service, anyone who compromises a device or account, and — rarely but consequentially — a court.

The category people worry about most is the third. The category that causes the most real harm is the second.

An unlocked phone on a kitchen table is a more likely route to disclosure than a data centre. That is not a reason to ignore the vendor question, but it is worth holding the proportions.

Five categories of people, in descending order of how often they actually look: you, the client's own household, the companies delivering the service, anyone who compromises a device or account, and — rarely but consequentially — a court.

The category people worry about most is the third. The category that causes the most real harm is the second.

An unlocked phone on a kitchen table is a more likely route to disclosure than a data centre. That is not a reason to ignore the vendor question, but it is worth holding the proportions.

Your service providers, and what they are allowed to do

Ontario's regulation constrains a supplier of electronic services to a custodian in three specific ways. The person "shall not use any personal health information to which it has access in the course of providing the services for the health information custodian except as necessary in the course of providing the services"; "shall not disclose any personal health information to which it has access in the course of providing the services"; and "shall not permit its employees or any person acting on its behalf to be able to have access to the information unless the employee or person acting on its behalf agrees to comply with the restrictions" (O. Reg. 329/04, s. 6(1)).

Note what that permits: staff at a vendor can access client information where it is necessary to provide the service. Support, debugging and data recovery all qualify. What the rule constrains is purpose, not possibility.

Where a vendor is your agent rather than an outside supplier, the statute makes you responsible for what they do and requires you to "take steps that are reasonable in the circumstances" to ensure they handle information properly (PHIPA, s. 17(3)).

The suppliers behind your supplier

This is the part most people miss. A practice tool is usually assembled from other companies' services — telephony, hosting, email delivery, push notifications, payments — and each of those handles some slice of the information.

The regulation anticipates this for certain providers, requiring that the provider "ensure that any third party it retains to assist in providing services to a health information custodian agrees to comply with the restrictions and conditions that are necessary to enable the provider to comply with this section" (s. 6(3)).

In practice, that is why a sub-processor list matters. Not because any one name on it is alarming, but because a vendor who cannot produce one has not thought about the chain.

The telephony layer deserves particular attention if your practice uses calls or texts. Voice and SMS are almost always delivered by a specialist carrier platform, and call recordings and message logs sit there on that company's retention schedule — often longer than you would guess, and independently of whatever your own tool deletes.

The channel itself

Ordinary text and email are not private channels in the way a session is. The Ontario commissioner lists the ways an email goes wrong: it "can be inadvertently sent to the wrong recipient, for example, by mistyping an email address or using the autocomplete feature"; it is "often accessed on portable devices... which are vulnerable to theft and loss"; it "can also be forwarded or changed without the knowledge or permission of the original sender"; and it "may also be vulnerable to interception and hacking by unauthorized third parties" (IPC fact sheet).

Text messages share most of those properties, with an additional one: they usually appear on a lock screen.

Anyone you have given administrative help to

If someone answers your phone or manages your calendar, they can see who is contacting you, which is itself sensitive. Ontario's psychotherapy standard addresses this directly: "Registrants relying on others to provide reception or other administrative support train and supervise them on matters of confidentiality and privacy" (CRPO 3.1.3).

The training part is the obligation. The supervising part is the one people forget after the first week.

Courts, and lawful demands

Records held by you, and records held by your vendors, can be compelled. This is not a security failure; it is how the system works, and it applies to a filing cabinet as much as to software.

What varies is scope. A demand aimed at your practice records reaches your practice records. A demand aimed at a device reaches the whole device — which is one of the practical arguments for keeping practice communications off a personal handset in the first place.

The specifics of what can be compelled, from whom, and what protections apply to therapy records are genuinely complicated and jurisdiction-specific. That is a question for a lawyer, and a better one to ask before a demand arrives than after.

One published rule is worth carrying now, because it governs the gap between hearing that a demand is coming and receiving it. The CCPA standards state that counsellors "never destroy records or counselling/therapy notes after they receive a subpoena or have reason to expect receiving one. This action could be judged to be an obstruction of justice and it could result in being held in contempt of court" (CCPA Standards of Practice).

Read "or have reason to expect receiving one." The obligation starts before the paperwork does — which means a routine deletion schedule needs a way to be paused, and an automatic one you cannot pause is a liability rather than a convenience.

The short version

Assume the following are true, and design around them: your vendor's staff can technically reach your data and are constrained by rules rather than by impossibility; every vendor has vendors; the phone network sees message metadata regardless; and a lock screen is a disclosure surface.

Then ask the two questions that actually move the needle. Who is on the sub-processor list, and what is the retention at the telephony layer? Those two answers tell you more than any certification badge.

About Rivet

Rivet is a Canadian practice line built for therapists — a separate number for calls, texts and voicemail, with video sessions and clinical tools in the same place. Your data stays in Canada, and transcription runs on Rivet's own hardware rather than a third-party AI service.

One plan, $65 CAD a month, everything included. Fourteen-day trial, no card.

See what's included · Start the trial

Where this comes from

Where this comes from

Where this comes from

See what’s included

See what’s included

See what’s included