Discover
Workshop with the health information custodian and key staff. We map your data, vendors, and current controls.
Service
Be ready for the privacy audit you hope never comes — and confident if it does.
What you get
A clear, plain-language report of where your clinic stands against PHIPA — and exactly what to fix, in priority order.
Done right and on file before you adopt new software, switch EMRs, or move to the cloud.
Privacy policy, breach response plan, acceptable use, mobile device policy, retention schedule — all the documents an auditor asks for.
Annual PHIPA training with certificates. Required for every employee, contractor, and locum.
A tested 72-hour playbook covering containment, IPC notification, affected-patient notification, and documentation.
In practice
We deliver the written privacy policy, breach response plan, acceptable use policy, and mobile device policy the IPC expects — in plain language, dated, versioned, and specific to how your clinic actually operates.
How it works
Workshop with the health information custodian and key staff. We map your data, vendors, and current controls.
We produce a PHIPA gap report, deliver written policies, and build your breach response plan.
Annual reviews, refreshed training, and updates whenever the IPC issues new guidance.
On the ground
PHIPA compliance isn't a PDF — it's a conversation with the health information custodian about vendors, staff, and workflows. We run that workshop and turn the answers into a defensible compliance program.
Yes. Under PHIPA, health information custodians must take steps that are reasonable in the circumstances to ensure personal health information is protected. The IPC has been clear that this includes administrative, technical, and physical safeguards — and documentation of them.
PHIPA requires custodians to have written agreements with IT providers that handle PHI. We provide a compliant agreement as part of every engagement.
Ontario healthcare clinics
trust Northline for
Every clinic in Canada runs on patient trust. The moment that data is exposed, that trust — and the practice — is at risk.
Generic IT providers treat a medical clinic like any other small business. We don't. Northline exists to make PHIPA-grade security and compliance achievable for clinics of every size, from solo practitioners to multi-location groups.
We're building the IT partner Canadian healthcare actually deserves — one that understands the law, keeps your data in Canada, and lets you focus on patients instead of passwords.

Ready for the audit you hope never comes.
Gap assessment, Privacy Impact Assessments, staff training records, ESP agreements, and a tested breach playbook — all filed and refreshed annually so nothing goes stale between audits.
Book a free 30-minute call. We'll walk through your clinic's setup, answer your questions, and tell you honestly whether we're a fit.