Examples
Worked examples
- Is an instance
A hospital-based investigator running a retrospective chart-review study submits a written research plan describing the objectives, the specific fields of personal health information needed, and safeguards; once an REB approves the plan, the investigator and the hospital (as custodian) sign a research agreement, and the hospital discloses the de-identified-where-possible records without needing to re-consent each patient.
- Is an instance
A multi-hospital Ontario study needs a separate research agreement with each participating hospital, since each is its own health information custodian under PHIPA -- REB approval of the overall research plan does not by itself authorize any one custodian to disclose its records.
Counter-examples
Looks similar, but isn't
- Not an instance
A private clinic in Alberta disclosing patient records for a local research project is not a PHIPA matter -- PHIPA is Ontario-specific; Alberta's own Health Information Act governs that disclosure instead.
- Not an instance
A university survey that recruits healthy volunteers directly and collects new data under informed consent is not using PHIPA's section 44 no-consent research pathway -- that pathway exists specifically for secondary use of existing custodian-held health information without direct patient consent.
Editorial commentary
PHIPA, the Personal Health Information Protection Act, 2004 (S.O. 2004, c. 3, Sched. A), is Ontario’s health-sector-specific privacy law. It sits alongside, and partly displaces, Canada’s federal private-sector privacy law — see our guide to PIPEDA and academic research data for how the federal and provincial regimes divide jurisdiction. Ontario’s Cabinet has designated PHIPA “substantially similar” to PIPEDA for personal health information specifically, which is why a health researcher handling clinical data in Ontario generally looks to PHIPA rather than PIPEDA for that data, even though PIPEDA remains the applicable framework for the same institution’s general commercial personal information.
Who PHIPA Applies To
PHIPA regulates “health information custodians” — a defined term covering hospitals, independent health facilities, physicians and other regulated health professionals, pharmacies, laboratories, and similar organizations or individuals that have custody or control of personal health information as part of providing health care. A university department or research unit that is not itself providing health care is not usually a custodian in its own right; in practice, research access to clinical data flows through an agreement with the custodian (a hospital or health authority) that holds it, not through the researcher’s own institution.
The Research Provision (Section 44)
PHIPA’s research provision, generally cited as section 44, sets out a specific no-consent pathway for research use of personal health information — distinct from, and stricter than, PHIPA’s general rules for using data for direct patient care. To disclose personal health information to a researcher without the patient’s consent under this pathway, a custodian must confirm that:
- The researcher has submitted a written application, including a research plan that sets out the objectives of the research, the public or scientific benefit reasonably expected, the personal health information needed and why less identifiable information will not serve the purpose, and how the information will be safeguarded.
- The research plan has been reviewed and approved by a research ethics board (REB) — see our term on the Research Ethics Board (REB) for what that review generally covers.
- The researcher and the custodian have entered into a written research agreement that binds the researcher to the terms of the approved research plan, restricts further use or disclosure of the data, and sets requirements for security safeguards and for returning or securely destroying the data once the research concludes.
This is a use-and-disclosure mechanism, not a substitute for research ethics review generally — a study relying on the section 44 pathway still needs REB approval on the same footing as any other human-participant or human-data research conducted in Ontario; PHIPA does not create a separate, lower ethics bar. Where a study instead collects new information directly from participants with informed consent, the section 44 no-consent pathway is not the applicable mechanism at all — consent-based collection proceeds under PHIPA’s general rules, not its research-specific exception.
PHIPA Is Ontario-Specific
PHIPA applies only to health information custodians operating in Ontario. Other provinces have their own, differently-worded health-privacy statutes — New Brunswick’s Personal Health Information Privacy and Access Act, Newfoundland and Labrador’s Personal Health Information Act, and Nova Scotia’s Personal Health Information Act among them — and a multi-jurisdictional study spanning several provinces needs to identify the correct custodian-level statute for each site rather than assuming PHIPA’s research pathway applies everywhere. A province without health-information-specific legislation typically leaves health data governed by its general private-sector law (or by PIPEDA directly), which will have its own, often less research-specific, consent and disclosure rules.
Frequently Asked Questions
Does PHIPA apply outside Ontario?
No. PHIPA is Ontario provincial legislation. Other provinces have their own health-privacy statutes, and a multi-site study needs to check the applicable law at each participating institution rather than assuming PHIPA’s rules travel with the data.
Does PHIPA’s research provision replace the need for REB approval?
No. REB approval of the research plan is one of the explicit requirements for using PHIPA’s no-consent research disclosure pathway, not an alternative to it.
Who counts as a health information custodian under PHIPA?
Hospitals, physicians and other regulated health professionals, pharmacies, laboratories, and similar bodies with custody or control of personal health information gathered in the course of providing health care. A university research office is not typically a custodian in its own right; access to custodian-held clinical data for research runs through an agreement with the custodian.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="PHIPA (Personal Health Information Protection Act)"
vocab-term-identifier="https://casrai.org/dictionary/term/personal-health-information-protection-act-phipa" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/personal-health-information-protection-act-phipa",
"name": "PHIPA (Personal Health Information Protection Act)",
"identifier": "https://casrai.org/dictionary/term/personal-health-information-protection-act-phipa",
"description": "PHIPA (Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A) is Ontario's health-sector-specific privacy statute. It governs how \"health information custodians\" -- hospitals, physicians, other regulated health professionals, and similar bodies that have custody or control of personal health information in the course of providing health care -- may collect, use, and disclose that information, and it is administered by Ontario's Information and Privacy Commissioner (IPC). For a use or disclosure to be described as falling \"under PHIPA\" rather than under Canada's general federal privacy law, it must involve personal health information held by a custodian carrying out a health care function in Ontario specifically; PHIPA is a provincial statute and does not apply outside Ontario. PHIPA's research provision -- generally cited as section 44 -- lets a custodian disclose personal health information to a researcher without the individual's consent, but only where the researcher has submitted a written application and a research plan describing the research's objectives and the personal health information needed, that plan has been approved by a research ethics board (REB), and the researcher and custodian have entered into a written research agreement governing how the data will be safeguarded, used, and eventually destroyed or returned. A use or disclosure that skips REB approval, or that is not governed by a research agreement meeting PHIPA's requirements, is not a valid PHIPA research disclosure, whatever else it may be.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/personal-health-information-protection-act-phipa",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-08-31T23:38:08",
"dateModified": "2026-08-31T23:38:08",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}






