The phrase that should rewire your compliance calendar
In PHIPA Decision 298, the IPC articulated expectations that many of us have been preaching without a perfect case citation. When the Commissioner questions whether a custodian’s information practices comply with PHIPA, the custodian should produce information about policies, practices, and procedures — and show that those requirements were actually met. The decision describes demonstrable accountability as a repeatable, evidence-backed system of data governance: not aspirational wording, but proof of operation.
That language should be taped above every privacy officer’s monitor. Read it beside the IPC’s public summary of the first AMP.
Two organizations, one fact pattern, different proof stories
The same broader incident produced different accountability pictures:
- Hospital environment: comprehensive privacy policies and procedures, annual review habits, training expectations, confidentiality agreements for professional/credentialed staff, and a decisive containment response when the misuse surfaced. That evidence mattered.
- Private clinic: treated as failing basic PHIPA privacy and security obligations — the kind of vacuum where policies may exist as documents but not as a management system. The clinic received a $7,500 AMP, higher than the physician’s $5,000, which should end any fantasy that “the individual did it, so the organization is fine.”
I care about this split because it maps to a common Canadian health reality: privileged clinicians operating across hospitals and private clinics with uneven program maturity. The hospital’s program cannot be assumed to cover the clinic. The clinic needs its own accountability spine.
What demonstrable accountability is not
It is not:
- A policy approved in 2019 and never tested.
- A SharePoint folder named “Privacy.”
- A once-on-hire module with no renewal.
- A breach playbook nobody has tabletopped.
- A DPIA template with zero completed examples.
- An honour system for EHR access.
- A vendor schedule that says “complies with PHIPA” without diligence.
Regulators have learned to ask for artifacts with dates, names, systems, and outcomes. If your proof cannot survive that, you do not have a control. You have a story.
Building an evidence-backed privacy management program
I use a simple ladder with health clients:
- Governance. Named accountability, reporting line, schedule of policy review, minutes that show real decisions.
- Inventory. Systems holding PHI, including shared EHRs, messaging, billing, and vendor tools.
- Access control proof. Role design, joiner-mover-leaver logs, privileged access reviews, audit sampling results.
- Training proof. Curricula, completion rates, role-specific modules for registration and clinicians, remediation for non-completion.
- Vendor proof. Contracts, security reviews, breach notification clauses, and residual risk acceptance.
- Incident proof. Detection to closure timelines, notification decisions, and management sign-off.
- Monitoring proof. Metrics that leadership sees quarterly — not only after a crisis.
Each rung needs an owner and a retrieval time objective. If evidence takes three weeks to assemble, it will not help you mid-investigation.
AMPs make weak programs expensive
Ontario’s AMP guidance and the first AMP decisions together show a direction of travel: serious departures, economic benefit, weak mitigation, and thin accountability invite monetary outcomes. Demonstrable accountability is how you argue for organizational mitigation when an agent goes offside. It is also how you avoid being the clinic that becomes the example.
Paper policies without operation are worse than a frank gap analysis. They create false confidence and give a regulator a credibility problem to prosecute.
A 30-day evidence drill
Pick one claim you make to your board — for example, “all agents complete annual privacy training” or “we audit high-risk access monthly.” Then:
- Retrieve the last twelve months of raw evidence in one working session.
- Note every manual workaround required.
- Fix the retrieval path (export, dashboard, owner).
- Document one improvement you can finish in thirty days.
Repeat quarterly. That is demonstrable accountability as a habit, not a slogan.
Small clinics sometimes tell me this standard is unfair because they lack a hospital privacy office. I am sympathetic to resource constraints and unsympathetic to zero program. A proportionate privacy management program for a small clinic still needs a named lead, access rules, training, a breach process, and records that those things happened. Decision 298’s clinic penalty is a warning shot at “we’re too small for governance.”
Portability of the idea beyond PHIPA
Private-sector teams under PIPEDA and Quebec organizations under Law 25 face the same cultural test: can you show the control worked, or only that you wrote about it? Demonstrable accountability is not Ontario jargon. It is how modern privacy enforcement thinks. Health just got a vivid case citation.
Actionable takeaway
Decision 298’s most portable legacy may not be the dollar amounts. It is the insistence that PHIPA compliance is shown, not declared. Hospitals with living programs and clinics without them will not be judged the same when something goes wrong. Build evidence as you build controls — or plan to explain the gap under oath, interview, or AMP submissions. Keep the decision, the first AMP announcement, and the AMP guidance in your leadership pack. Which of your “green” privacy controls would turn yellow if you had to prove operation this week?