Blog

Small Leaks: Everyday Ways Ontario Therapists Can Fall Short of PHIPA Without Realizing It

Amanda Carver, R.P., M.Ed., RYT-200, EMDRIA Certified Therapist and Consultant in Training; Clinical Director Vistas Psychotherapy & Wellness
October 9, 2026

Last reviewed October 2026

This post is for general education only. It isn't legal advice or clinical supervision, and I don't speak for CRPO or the IPC. Please read the linked sources and consult your college, legal counsel, or supervisor about your own situation. A full scope note appears at the end.

The short version

  • PHIPA asks for safeguards that are reasonable in the circumstances, and therapy notes sit at the sensitive end of the scale.
  • Rough notes can live outside the clinical record under CRPO's standards, but they're still personal health information, so they still need protecting and secure destruction.
  • Shared devices, unsecured networks, and unlocked bags are among the most common gaps, and the easiest to fix.
  • PHIPA also has paperwork requirements many sole practitioners don't know about, like a written public statement about your information practices.

In our last post, we called email a postcard: easy to send, easy for anyone along the route to read. (If you missed it, Email Is a Postcard covers encryption, Canadian servers, and secure client messaging.)

Email is the leak most therapists have heard about. This post is about the quieter ones.

Think of your practice as a house with good plumbing. You've done the big things: a secure practice-management platform, a locked filing cabinet, a consent form that mentions confidentiality. The pipes are sound.

Most privacy problems don't arrive as a burst pipe. They're drips. A notebook in a tote bag. A laptop the kids borrow for homework. A café's free Wi-Fi. None of these feels like a breach while it's happening, which is exactly what makes them easy to miss.

Here's a room-by-room walk through the house, so you can check for drips yourself.

First, the yardstick: what PHIPA actually requires

In Ontario, the Personal Health Information Protection Act (PHIPA) is the main law for therapists in private practice, because Registered Psychotherapists are health information custodians. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) points in the same direction, asking that safeguards match the sensitivity of the information.

The central test sits in section 12(1) of PHIPA: take steps that are reasonable in the circumstances to protect personal health information against theft, loss, and unauthorized use or disclosure. Section 13(1) adds that records must be retained, transferred, and disposed of securely.

PHIPA rarely says "use this lock" or "buy that shredder." It asks whether a thoughtful custodian would consider your safeguards reasonable, given how sensitive the information is. For psychotherapy notes, that bar sits high.

That's the yardstick for everything below. Some items are clear legal requirements; others are widely recommended practice. We'll say which is which.

A router representing a potential privacy breach
Poorly secured networks can accidentally breach privacy

The pipes into the house: home Wi-Fi, routers, and public networks

Your home router

If you see clients virtually or chart from home, your router is the water main. Many routers still run on the default settings they shipped with, including an admin password printed on a sticker.

A few low-effort fixes:

  • Change the router's admin password from the default.
  • Use WPA2 or, better, WPA3 encryption with a strong Wi-Fi password.
  • Turn on automatic firmware updates, or check for updates a few times a year.
  • Put visitors and smart-home gadgets on a separate guest network.

Public Wi-Fi

Charting from a café or an airport lounge feels efficient. Most practice platforms encrypt their connections, which lowers the risk compared with a decade ago. The drips that remain are real, though: look-alike hotspots set up to capture logins, other people on the network, and a screen anyone in line can read.

If you work away from home or the office, a phone hotspot is usually a safer choice than public Wi-Fi. A reputable VPN adds another layer. A privacy screen filter handles the person behind you.

The taps: securing your computer, laptop, and phone

The family computer

If a partner, child, roommate, or guest uses the computer you use to reach client files or platforms like Owl or Jane, that's a drip, even if they never open anything clinical.

The risks are mundane. A browser that remembers your login. A session left open. A downloaded intake form sitting in the Downloads folder. A child installing a game that brings malware along with it.

The cleanest fix is a computer used only for practice. If that's not possible:

  • Give yourself a separate, password-protected user account on the computer, and keep all practice work there.
  • Don't let the browser save practice passwords. Use a password manager instead.
  • Turn on two-factor authentication for every practice platform.
  • Set the screen to lock automatically after a few minutes.

Device encryption

The IPC has long said that personal health information stored on mobile devices, such as laptops, phones, and USB keys, should be encrypted. On most modern computers this is a setting you switch on: FileVault on a Mac, BitLocker or Device Encryption on Windows. Most current phones are encrypted once you set a passcode.

Encryption is what turns a stolen laptop from a privacy breach into an inconvenience.

Your phone

Phones leak in ways we rarely notice:

  • Client names saved in contacts sync to iCloud or Google, and sometimes into messaging and social apps.
  • A photo of a client's worksheet lands in your camera roll and backs up to the cloud.
  • Lock-screen previews show the first line of a client text to anyone at the table.
  • Calendar apps with full client names sync to every device you own.

Use initials or a code in your phone's contacts and calendar, keep clinical content in your practice platform's app rather than your camera roll or texts, and turn off message previews on the lock screen.

Old devices

Before selling, donating, or recycling a computer or phone, wipe it with a full factory reset (after confirming its encryption was on), or have the drive physically destroyed.

an open notebook and an unlocked file cabinet in an office showing poorly secured confidential information
Files drawers and notebooks should be carefully locked in homes, office and transit

The storage closet: paper records and rough session notes

The session notebook

Many of us jot notes by hand during or after sessions. CRPO's Standard 5.1 allows for this: rough notes don't have to be kept in the clinical record, though they can be.

Here's the catch. A rough note that identifies a client is still personal health information under PHIPA. It needs the same protection as the chart while it exists, and secure destruction when you're done with it.

The notebook also creates a quieter problem. CRPO's commentary says the complete clinical record should be stored together, to avoid incomplete or lost information. If anything in the notebook is actually record content, such as the only account of a risk assessment or a key clinical decision, it belongs in the file. Otherwise, part of the record is living in a tote bag.

Not sure what belongs in the record and what can stay in your rough notes? The Goldilocks Approach to Note Writing looks at how to write clinical records that are neither too thin nor too detailed.

One notebook, many clients

A single notebook holding notes for several clients multiplies every drip:

  • Lose it once, breach many times. One forgotten bag affects every client on those pages.
  • You can't destroy one client's notes without touching another's. Pages don't line up neatly with people.
  • Access requests get complicated. Under PHIPA, clients can generally request access to records of their personal health information in your custody. If a rough note still exists when a client asks, separating it from other clients' notes on the same page becomes a redaction exercise.

A tidier habit: use one loose sheet per client per session, transfer anything clinically relevant into the record promptly, and shred the sheet.

Moving between home and office

PHIPA's section 13 applies to records being transferred, which includes notes travelling in your bag. Keep paper in a locked case, keep that case with you, and don't leave it in the car, even briefly. If you can avoid carrying paper at all, even better.

Storage: the double lock

The "double lock" (a locked cabinet inside a locked room) is widely taught as a reasonable standard for paper records. PHIPA doesn't name it explicitly, but it's a useful way to meet the reasonable-steps test. A locked drawer in an unlocked shared office, or a locked room with an open shelf, is a single lock.

Shredding

The recycling bin is not destruction. The IPC's guidance on secure destruction calls for methods that make records unreadable and impossible to reconstruct. In practice, that means a cross-cut or micro-cut shredder, or a bonded shredding service that gives you a certificate of destruction.

Note the difference in timing. Rough notes can be shredded once their content is in the record. The clinical record itself must be kept for at least 10 years from the last interaction, or 10 years from the client's 18th birthday, whichever is later (CRPO Standard 5.1).

The thin walls: privacy in home and shared offices

Virtual sessions from home

Sound travels. When you see clients from home, check what can be heard from the hallway, the kitchen, or the next apartment. Headphones keep the client's side of the conversation private, and a white-noise machine outside the door helps with yours.

Smart speakers and voice assistants are designed to listen for a wake word. Turn them off or move them out of the room during sessions.

Virtual work raises a second question when a client joins from outside Ontario. Privacy is only part of it; licensing matters too. Can Ontario Therapists Practice in BC? walks through the cross-border rules.

Shared and rented offices

If you rent space by the day or share a suite, look for the small drips:

  • Printouts waiting on a shared printer.
  • A sign-in sheet or day calendar with client names in the waiting area.
  • Sound carrying through doors and walls.
  • A shared computer at the front desk with someone else's login still active.

Voicemail

Keep voicemail messages to clients minimal: your first name and a callback number, without the practice name if the client hasn't said that's okay. Ask at intake which number is safe to call and whether you can leave a message. Your own voicemail greeting can include crisis information and a reminder that messages aren't monitored for emergencies.

The appliances: email, cloud storage, video, and AI tools

laptop, phone, and cloud use as possible means of privacy breach
Our tech and tools may also present breaches if not used carefully

Email and texting

We covered email in Email Is a Postcard. Ordinary text messages (SMS) work much the same way: they aren't encrypted end to end, they sit on the client's phone, and they're easy to misdirect. The same rule applies to both: scheduling with consent, and clinical content through a secure platform.

Personal cloud storage

Saving intake forms or session notes to a personal Google Drive, Dropbox, or iCloud account is a common drip. These services are convenient, but a personal consumer account usually comes without the agreements and controls PHIPA expects from anyone handling health information for you, and the data is often stored outside Canada. Keep client documents inside your practice platform, or in a service set up for health information with an appropriate agreement in place.

Video platforms

Free consumer versions of video tools may not offer the security, data-storage, or contractual terms suited to therapy. CRPO's guide to selecting a communications platform is a good checklist before you choose one.

AI tools

This is the newest drip, and it's spreading fast. Pasting session details into a general-purpose AI chatbot to draft a note or a letter discloses personal health information to that company, often under terms that allow data retention or use beyond your purpose.

AI scribes built for health care are a different conversation. In January 2026, the IPC released AI Scribes: Key Considerations for the Health Sector, with a companion checklist. It asks custodians to assess vendors carefully, set clear contractual safeguards, keep a trained human reviewing the output, and be transparent with clients. If you're considering an AI scribe, read both documents first and talk with clients about it as part of informed consent.

The house papers: PHIPA requirements many therapists miss

Some PHIPA requirements aren't about locks at all. They're paperwork, and sole practitioners often don't know they apply.

A contact person (section 15). Every custodian needs someone who handles privacy questions and access requests. In a solo practice, that's usually you.

A written public statement (section 16). Custodians must make available a plain-language description of their information practices, how to reach the contact person, and how to request access, request a correction, or complain to the IPC. For most practices, this lives on the website as a privacy statement.

Agents (section 17). Anyone handling personal health information on your behalf, such as an administrative assistant, a bookkeeper, or a practicum student, is acting as your agent. You remain responsible for what they do, so they need training, clear instructions, and usually a written confidentiality agreement.

A breach plan. Section 12(2) requires notifying the affected client at the first reasonable opportunity if their information is lost, stolen, or used or disclosed without authority. Some breaches must also be reported to the IPC. Knowing your steps before a misdirected email or a lost notebook saves a lot of scrambling afterwards.

Annual breach statistics. If you had any privacy breach during a calendar year, PHIPA requires you to report statistics to the IPC by March 1 of the following year, including breaches you didn't have to report at the time. Custodians in private practice with no breaches that year don't have to file.

Consultation and supervision. Bringing cases to consultation is good practice. Share only what's needed, and de-identify wherever you can. Online peer groups, including private ones, are not an appropriate place for identifiable client details. If you're looking for a structured, confidential space for case discussion, see our clinical supervision and EMDR consultation services.

A room-by-room PHIPA self-check for therapists

  • My router has a changed admin password, strong encryption, and current firmware.
  • I avoid public Wi-Fi for practice work, or use a hotspot or VPN.
  • Nobody else uses the device or account I use for client files.
  • My laptop and phone are encrypted, auto-lock, and use two-factor authentication.
  • Client names don't appear in my phone's contacts, calendar, or camera roll.
  • Rough notes are one client per page, moved into the record promptly, and shredded.
  • Paper travels in a locked case that stays with me.
  • Paper records are kept behind two locks.
  • My shredder is cross-cut, or I use a bonded service.
  • Sessions at home can't be overheard, and smart speakers are off.
  • I don't put client information into personal cloud accounts or general AI chatbots.
  • I have a written public statement, a breach plan, and agreements with anyone acting as my agent.

Back to the plumbing

None of this is about perfection. Every house has the odd drip, and PHIPA asks for reasonable steps, not a vault.

The point is to know where your pipes run.

Walk through the house once with this list, fix the easy drips first, and put the rest on your calendar. Your clients will never see most of this work. That's rather the point.

Related reading on the Vistas blog

Purpose and scope

This post is for informational and educational purposes only. It offers a general overview of CRPO standards, Ontario and federal privacy legislation, and guidance from the Information and Privacy Commissioner of Ontario. It is not legal advice or a legal opinion, and it is not clinical supervision or a substitute for it. If you have a clinical supervisor, consult them before making changes to your practice.

Regulatory compliance is an individual professional responsibility. Each clinician must verify how these requirements apply to their own registration, practice setting, and the tools they use.

Laws, regulatory policies, and technology change without notice. This post was last reviewed in October 2026. Please confirm current requirements with CRPO and the IPC directly.

This content is written for therapists. It is not therapy, and it does not establish a therapeutic, supervisory, or consultative relationship.

If you're experiencing distress, please reach out to a qualified mental health professional. If you are in immediate distress or at risk of harm, in Canada you can call or text 9-8-8 or call 9-1-1. Outside Canada, FindAHelpline.com lists free, confidential support in your region.

Sources and further reading

Frequently asked questions

Do therapists in Ontario have to follow PHIPA?

Yes. Registered Psychotherapists in Ontario are health information custodians under the Personal Health Information Protection Act (PHIPA). That means they must take reasonable steps to protect client information, keep and destroy records securely, and meet PHIPA's administrative requirements.

Are rough session notes part of the clinical record?

Not necessarily. CRPO's Standard 5.1 allows rough notes to be kept outside the clinical record. They are still personal health information under PHIPA, though, so they must be protected while they exist and securely destroyed afterward. Anything clinically important, such as a risk assessment, belongs in the record.

Do I need to encrypt my laptop and phone if I see clients?

The Information and Privacy Commissioner of Ontario (IPC) has long said that personal health information on mobile devices should be encrypted. On most computers this is a built-in setting: FileVault on a Mac, BitLocker or Device Encryption on Windows. Most current phones are encrypted once a passcode is set.

Can I store client notes in my personal Google Drive, Dropbox, or iCloud?

It's generally not recommended. Personal consumer accounts usually lack the agreements and controls PHIPA expects from services that handle health information, and data is often stored outside Canada. Keep client documents in your practice-management platform or a service set up for health information.

Can therapists use ChatGPT or other AI chatbots to write session notes?

Pasting identifiable session details into a general-purpose AI chatbot discloses personal health information to that company. AI scribes built for health care are different. The IPC's 2026 guidance on AI scribes asks custodians to assess vendors, set contractual safeguards, review all output, and be transparent with clients.

Does a solo private-practice therapist need a privacy statement?

Yes. Section 16 of PHIPA requires every custodian to make a written public statement available. It must describe your information practices, how to reach your privacy contact, how to request access or correction, and how to complain to the IPC. Most practices post it on their website.

What should I do if a client notebook or laptop is lost?

Treat it as a possible privacy breach. PHIPA requires notifying affected clients at the first reasonable opportunity, and some breaches must also be reported to the IPC. Any breach also counts toward your annual breach statistics report, due to the IPC by March 1 of the following year.

How long do psychotherapists in Ontario have to keep records?

Under CRPO Standard 5.1, clinical records must be kept for at least 10 years from the last interaction with the client. For clients who were minors, records must be kept for at least 10 years after their 18th birthday, whichever date is later.

‍

Copied