How PHIPA Applies to AI: What Every Ontario Clinic Needs to Know Before Deploying AI Tools
If you run a clinic in Ontario and you are thinking about AI tools, whether that is an AI receptionist, an AI scribe, or automated appointment reminders, there is one law that governs all of it: the Personal Health Information Protection Act, 2004, better known as PHIPA.
Here is the part many clinic owners have not caught up on yet. In January 2026, the Information and Privacy Commissioner of Ontario (IPC) released its first detailed, sector-specific guidance on AI in healthcare. And since 2024, the IPC has had the power to issue administrative monetary penalties of up to $500,000 per organization for PHIPA violations. The first penalty has already been issued.
In other words, “we didn’t know the rules applied to AI” is no longer a viable position. The good news is that the rules are clearer than ever, and following them is entirely achievable for a small clinic. Here is the plain-language version.
A quick note before we start: we are an AI implementation company, not a law firm. This article is general information, not legal advice. For legal questions about your specific situation, talk to a privacy lawyer.
PHIPA already covers your AI tools
There is no separate “AI law” for Ontario healthcare, and you do not need one. PHIPA applies to personal health information no matter what technology touches it. If you are a health information custodian, which includes family physicians, dental clinics, chiropractors, pharmacies, and long-term care homes, your PHIPA obligations follow the data into any AI system you adopt.
That has a few practical consequences:
AI output is a health record. A note, summary, transcript, or message generated with AI support is protected under PHIPA the same way a handwritten chart note is. It needs the same safeguards, the same retention practices, and the same access controls.
Your vendor is your responsibility. If a technology partner handles personal health information on your behalf, they must operate under a written agreement and carry the same obligations you hold. You cannot outsource accountability. If a vendor cannot tell you where your patients’ data is stored, whether it is used to train their models, or how long they retain recordings, that is your answer about whether to work with them.
Data minimization applies to AI. PHIPA only permits collecting and using the minimum information necessary. For AI tools, the IPC has specifically flagged questions like whether you actually need to retain full audio recordings or transcripts, and how much information really needs to flow to a vendor.
What the new IPC guidance expects
The IPC’s January 2026 guidance was written for AI scribes, the tools that transcribe clinical conversations into notes. But the expectations it lays out are the template for how the regulator thinks about any AI system in a health setting, including voice agents and automation. The core requirements:
A privacy impact assessment before launch, not after. Before any AI system that handles personal health information goes live, complete a privacy impact assessment, and update it when the tool, its purpose, or the risks change.
A governance framework scaled to your size. Larger organizations are expected to establish an AI governance committee with authority to approve, pause, or decommission AI deployments. For a solo practitioner or small clinic, the IPC’s expectations scale down: you can designate yourself as the AI governance authority, document your decision to adopt the tool, and confirm your vendor agreement prohibits using your patients’ information to train the vendor’s models.
Written policies that reflect reality. Maintain documentation identifying which AI systems are authorized, what they are approved to do, what counts as a breach, and what happens when one occurs. Then review it regularly so it stays true.
Human oversight of AI outputs. AI systems make mistakes. Transcription errors and hallucinated content are known risks, and the guidance treats human review as mandatory, not optional.
Transparency and a way to ask questions. Patients should be able to find out how AI is used in your practice and get a straight answer when they ask. This is where a patient-facing transparency page comes in, which we covered in detail in our previous article on how one Ontario clinic told patients about AI before they had to ask.
The six principles behind all of it
The IPC and the Ontario Human Rights Commission jointly published six principles for responsible AI use, and the healthcare guidance is built on them. Every AI system should be:
- Valid and reliable
- Safe
- Privacy protective
- Human rights affirming
- Transparent
- Accountable
If you are evaluating an AI vendor and you want a fast filter, ask how their product supports each of these six. A serious vendor will have answers. A vendor selling you a demo will change the subject.
What this means for AI receptionists and voice agents
Most of the regulatory attention so far has focused on AI scribes, because they sit closest to clinical conversations. But an AI voice agent answering your phones touches personal health information too. A caller’s name, phone number, reason for calling, and appointment details are all covered.
The same playbook applies:
- Complete a privacy review before the agent goes live
- Put a written agreement in place with your technology partner covering data handling, retention, and breach notification
- Collect only what the call actually requires
- Ensure the agent identifies itself as AI and always offers a path to a human
- Publish a plain-language explanation for patients
- Review it all on a schedule
That last list is not just compliance. It is the difference between an AI rollout your patients trust and one they quietly resent.
The bottom line
PHIPA compliance for AI is not a wall. It is a checklist. The clinics that treat it as a checklist, done before launch and reviewed on a schedule, get the efficiency gains of AI plus something their competitors cannot buy: patients who trust how the technology is being used.
Every AI voice agent we deploy at Ajax Web AI is built around these requirements from day one. Disclosure on every call. Human handoff always available. Written agreements covering data handling. A transparency page your patients can actually read. We call it responsible AI adoption, and in an Ontario health setting, it is the only kind worth doing.
Ajax Web AI helps clinics and local businesses across Durham Region and the GTA adopt AI voice agents and automation responsibly. We automate the work, not the relationship. Questions about making your AI rollout PHIPA-ready? Contact us.
