SOC 2 and PHIPA for Ontario health tech
Ontario hospitals and clinics ask software vendors for a SOC 2 report because it is the artifact they know how to read. PHIPA asks for things a SOC 2 report does not contain, and the gap between the two is where vendor reviews stall.
A SOC 2 report and PHIPA compliance are different things, and a health information custodian who asks for the first still has obligations that only the second satisfies. SOC 2 is an attestation about controls you chose, tested by a CPA firm against criteria you selected. PHIPA is an Ontario statute that imposes specific duties, and for most software vendors those duties arrive through the custodian's contract rather than directly.
The overlap is real and it is partial. Roughly, a SOC 2 Type 2 covers the security safeguards a custodian has to satisfy itself about, and it does not cover the statutory mechanics: what role you occupy under the Act, what you must tell the custodian and when, what you have to log, and what assessment you owe them in writing.
First work out which role you are in
Almost every PHIPA question a vendor has is downstream of this, and vendors routinely get it wrong in both directions.
- Health information custodian
- The hospital, clinic, practitioner, pharmacy or laboratory. Custodians hold the primary duties under the Act. A software company is rarely one.
- Agent of a custodian
- A person or organization authorised by the custodian to deal with personal health information on its behalf and for its purposes. Most vendors processing PHI for a hospital are here. Your permissions are the custodian's permissions, and you may only do what it has authorised.
- Electronic service provider
- A vendor supplying goods or services that let a custodian use electronic means to collect, use, disclose, modify, retain or dispose of PHI. Hosting, EMR modules and messaging platforms sit here, and an electronic service provider may not use PHI except as necessary to provide the services.
- Health information network provider
- Defined in section 6(2) of O. Reg. 329/04: a person providing services to two or more custodians, primarily to enable those custodians to use electronic means to disclose PHI to one another. Any platform connecting multiple custodians should test itself against this definition carefully, because the obligations attached to it are the heaviest in the regulation and they fall on the provider directly.
The practical consequence: a single-hospital deployment and a multi-custodian exchange can be the same software with materially different duties. Decide which one you are before a security review decides for you.
What a network provider owes, directly
If you meet the network provider definition, section 6 of O. Reg. 329/04 places obligations on you regardless of what your contract says. The ones that surprise vendors:
- A written threat and risk assessment. You must perform an assessment of the services with respect to threats, vulnerabilities and risks to the security and integrity of PHI, and how the services may affect the privacy of the individuals concerned, and provide each custodian with a written copy of the results. A SOC 2 report is not this document. It is a different artifact answering a different question.
- Notice to custodians at the first reasonable opportunity where an unauthorised person accessed PHI, or where you accessed it for an unauthorised purpose.
- Flow-down to third parties. Any third party you retain to help provide the services has to agree to the restrictions and conditions you need in order to meet your own obligations. Your subprocessors are in scope.
- A plain-language description of your services and the safeguards in place, available to custodians and, through them, to the public.
The one that catches people
The threat and risk assessment is a deliverable owed to each custodian, in writing. Vendors who have a SOC 2 report often assume it discharges this. It does not, and a hospital privacy office that knows the regulation will ask for the assessment by name.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Where SOC 2 and PHIPA actually overlap
The overlap is worth being precise about, because it is what lets you reuse work rather than run two programs.
| What PHIPA expects | Covered by a SOC 2 Type 2? | What closes the gap |
|---|---|---|
| Reasonable security safeguards against theft, loss and unauthorised use | Largely yes | The Security criteria map closely. This is the part the report genuinely evidences. |
| Access limited to what is necessary, on a need-to-know basis | Yes, if scoped in | Logical access controls are core CC6 territory. Confirm the report period covers it. |
| An electronic audit log of who accessed what and when | Partly | PHIPA expects access logging at the record level for PHI. Generic system logging may not reach that granularity. |
| Notice to the custodian of a breach at the first reasonable opportunity | No | A contractual and operational commitment with a defined trigger and timeline, tested. |
| Written threat and risk assessment provided to custodians | No | A separate deliverable. Reuse the SOC 2 evidence, write the assessment. |
| Restrictions on use of PHI beyond providing the service | No | Contract terms, plus controls that make the restriction real rather than promised. |
| Retention, secure disposal and return of PHI | Partly | Often in scope as a control, rarely at the specificity a custodian's agreement requires. |
| Statutory roles, privacy officer, complaint handling | No | Privacy program work. The Privacy criterion helps and is not a substitute. |
Two readings follow from that table. A SOC 2 Type 2 with Security alone carries most of the safeguards conversation and none of the statutory mechanics. Adding the Privacy criterion narrows the gap and does not close it, because PHIPA's requirements are specific in ways the Trust Services Criteria are not.
What an Ontario hospital actually asks for
Vendor reviews in Ontario health care are more structured than in most commercial software procurement, and the questions come in a predictable order.
- Which role do you occupy under PHIPA? Agent, electronic service provider, network provider, or none. Answer this in one sentence and the rest of the review goes faster.
- Where is the PHI stored and processed? Region, and whether any of it leaves Canada, including for support access and backups. Ontario health buyers ask this early and expect a specific answer.
- Can we see your threat and risk assessment? By name, if you are a network provider. Custodians increasingly ask even when you are not.
- What is your breach notification commitment? Trigger, timeline, and who is called. The custodian carries its own duty to notify the individual and, in prescribed circumstances, the Information and Privacy Commissioner of Ontario, so your timeline has to fit inside theirs.
- What does your access log capture? Record-level access to PHI, retained for how long, and whether the custodian can query it.
- What independent assurance do you have? Where the SOC 2 report arrives, along with the penetration test and the remediation evidence.
What is actually at stake
PHIPA's enforcement has sharpened. Offence fines under section 72 are up to $200,000 for an individual, with imprisonment of up to a year, and up to $1,000,000 for an organization. Since 1 January 2024 the Information and Privacy Commissioner of Ontario can also issue administrative monetary penalties, to a maximum of $50,000 for an individual and $500,000 for an organization, without going through a prosecution. An individual affected by conduct leading to a conviction may seek damages, including up to $10,000 for mental anguish where the harm was caused by wilful or reckless misconduct.
Those are the custodian's exposures in the first instance, which is exactly why a hospital's review of your software is thorough. Their liability runs through your product.
A sensible order of work
For an Ontario health tech company selling to custodians, the order that wastes the least money:
- Settle your PHIPA role and write it down. One page, with the reasoning. It determines everything downstream and it is the first thing a privacy office asks.
- Do the threat and risk assessment. Required if you are a network provider, useful if you are not, and it produces the gap list that scopes everything else.
- Close the safeguards gaps, then run the SOC 2. The assessment above tells you what the examination would have found, and fixing it first is cheaper than fixing it during fieldwork. See what SOC 2 actually requires.
- Write the vendor-facing pack. Role statement, assessment summary, breach commitment, logging description, data residency, subprocessor list. This is what shortens every review after the first.
Done in that order, the SOC 2 report becomes the assurance layer over a program that already answers the statutory questions. Done in the reverse order, you get a report that impresses a procurement team and a privacy office that still has six questions.
Does a SOC 2 report make us PHIPA compliant?
No. It evidences that the controls you selected operated over a period. PHIPA imposes duties that no SOC 2 report addresses, including the written threat and risk assessment owed by a network provider and the notification commitments a custodian needs from you.
Is PHIPA just Ontario's version of PIPEDA?
No. PHIPA is health-specific and has been declared substantially similar to PIPEDA for health information custodians in Ontario, which means it applies instead of PIPEDA for that information. The duties, the roles and the oversight body are different. See SOC 2 and PIPEDA for the federal side.
Are we a health information network provider?
You are if you provide services to two or more custodians, primarily to enable them to use electronic means to disclose PHI to one another. Test it against section 6(2) of O. Reg. 329/04 rather than against how you describe your product, and get advice if it is close.
Does Type 1 or Type 2 matter for a hospital?
Type 2 in almost every case, because it covers operation over a period rather than design on a date, and a custodian relying on you wants evidence that the controls kept working. A Type 1 can carry a first review while a Type 2 window runs.
Find firms that have done this in Ontario
Describe the scope once, including that PHI is involved, and it goes to firms in this directory that work with Ontario health custodians.
Get matched