Compliance & Privacy

Why PHIPA Matters for Your Ontario Practice

If you're a regulated health professional in Ontario, PHIPA governs every tool that touches patient data — including your phone system. Here's what you need to know, and how Vocatively keeps you compliant.

PHIPA vs HIPAA: Key Differences

PHIPA (Ontario)

Personal Health Information Protection Act, 2004

  • Applies to all health information custodians in Ontario
  • Requires Canadian data residency (Section 10(3))
  • Covers dentists, chiropractors, physiotherapists, optometrists, RMTs, naturopaths, and more
  • Breach notification required to IPC Ontario
  • Fines up to $200,000 for individuals, $1,000,000 for organizations

HIPAA (USA)

Health Insurance Portability and Accountability Act, 1996

  • Applies to covered entities and business associates in the US
  • No data residency requirement — data can be stored anywhere
  • Requires Business Associate Agreements (BAAs)
  • Breach notification required to HHS
  • Fines up to $1.5M per violation category per year

The bottom line: HIPAA compliance alone is not sufficient for Ontario practices. PHIPA's data residency requirement means your tools must store patient data in Canada — and most US-based AI receptionist providers do not.

Who Must Comply with PHIPA?

PHIPA applies to every "health information custodian" in Ontario. This includes:

Dentists
Chiropractors
Physiotherapists
Optometrists
Naturopaths
Registered Massage Therapists
Physicians & Surgeons
Psychologists

Plus hospitals, labs, pharmacies, community health centres, and any person or organization described in PHIPA Section 3(1).

How Vocatively Meets PHIPA Requirements

Canadian Data Residency

All data stored in DigitalOcean Toronto (TOR1), ca-central region. No patient data crosses the border. Meets PHIPA Section 10(3) without patient consent requirements.

No Transcripts Stored

Raw call transcripts and audio recordings are never stored. Vapi transcript storage and recording are disabled in code. Only structured metadata is retained.

Hashed Phone Numbers

Caller phone numbers are HMAC-SHA256 hashed before storage. The raw number is never persisted — even our team cannot reverse the hash to identify callers.

No PHI in Emails

Email notifications contain only contact information and a generic call type. All detailed call content is accessible only through your authenticated, encrypted dashboard.

3-Tier Retention

Detailed call records anonymized after 90 days. Anonymized analytics retained for account-level trends. Aggregate statistics (no PII) retained indefinitely for industry research. PHIPA's data minimization principle is enforced by design, not policy.

Published Data Flow

A full data flow document describing how patient data moves through Vocatively is available upon request. Transparency is a core part of PHIPA compliance.

Frequently Asked Questions

What is PHIPA and who does it apply to?

PHIPA (Personal Health Information Protection Act, 2004) is Ontario's health privacy law. It applies to every health information custodian in Ontario — including dentists, chiropractors, physiotherapists, optometrists, naturopaths, RMTs, physicians, and other regulated health professionals. If your practice collects, uses, or discloses personal health information, PHIPA governs how you must handle that data.

How is PHIPA different from HIPAA?

HIPAA is the US federal health privacy law; PHIPA is Ontario-specific and in many ways stricter. The key difference: PHIPA requires that personal health information about Ontario residents be stored in Canada unless the individual consents to cross-border transfer (Section 10(3)). HIPAA has no equivalent data residency requirement. Both require encryption, access controls, and breach notification — but PHIPA's data residency rule means US-hosted tools may not be compliant for Ontario practices without explicit patient consent.

Does Vocatively store patient data in Canada?

Yes. All Vocatively data is stored in Canadian data centres (Toronto, ca-central). Our primary database is hosted in DigitalOcean Toronto (TOR1). No patient data is transferred to or stored in the United States. This meets PHIPA Section 10(3) data residency requirements without needing patient consent for cross-border transfer.

What personal health information does Vocatively collect?

Vocatively minimizes data collection by design. We do not store raw call transcripts or audio recordings. Caller phone numbers are cryptographically hashed (HMAC-SHA256) — even our team cannot reverse them. We store only structured call metadata: duration, category, sentiment, and an AI-generated summary. Email notifications contain only contact information and a generic call type — never protected health information.

Is PIPEDA different from PHIPA?

Yes. PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal privacy law for private-sector organizations. PHIPA specifically governs personal health information in Ontario and takes precedence for health information custodians. Vocatively complies with both — PHIPA for Ontario health data and PIPEDA for general personal information across Canada.

Keep Your Practice PHIPA Compliant

Join Ontario practices already using Vocatively for PHIPA-compliant call handling.

← Back to Vocatively Home