The day AMPs stopped being hypothetical
On August 27, 2025, the Information and Privacy Commissioner of Ontario issued PHIPA Decision 298 — the first use of administrative monetary penalties under the Personal Health Information Protection Act since AMP powers came into force in January 2024. The IPC’s public summary is blunt: unauthorized access and use of patient records for private commercial gain is no longer only a professional discipline and breach-notification story. It is a money story.
The penalties themselves were modest relative to the statutory ceiling:
- $5,000 against the physician.
- $7,500 against the co-owned private clinic.
- Maximums under PHIPA: $50,000 per individual and $500,000 per custodian (per the framework the IPC applies).
If you only remember the dollar figures, you will miss the point. First cases set doctrine. Later cases use it.
What happened, in plain terms
A physician with hospital privileges used access to a shared electronic health record environment across hospitals to run targeted searches for newborn males, then contacted parents to offer circumcision services through his private pediatric clinic. Hospitals investigated after parent complaints, suspended privileges, and reported. Neither the physician nor the clinic had notified the IPC of the breach.
The IPC found unauthorized access and use of personal health information for economic purposes on the physician’s side, and fundamental privacy program failures on the clinic’s side. The hospital side of the fact pattern is equally important for custodians: reasonable safeguards, training, and response mattered when the IPC assessed who should pay.
How the IPC thinks about AMPs
The Commissioner’s guidance for the health care sector on administrative monetary penalties frames AMPs as part of progressive enforcement. They are not the first tool for every technical breach. They are meant to encourage compliance and to prevent economic benefit from contraventions.
Decision 298 applies that logic. The conduct was a serious departure from PHIPA duties, done for financial opportunity, and it affected families in a vulnerable postpartum moment. Mitigating factors still counted — including that the physician stopped when confronted and had no prior privacy offences. That is why the numbers landed in the thousands, not at the cap.
I find that calibration reassuring and cautionary at once. Reassuring because the IPC is not swinging wildly on case one. Cautionary because the analytical framework is now road-tested: seriousness, economic motivation, harm, mitigation, deterrence.
Why health custodians should care beyond “we’re not that clinic”
Three structural lessons travel well:
- Individuals and organizations can both pay. The physician’s conduct did not shield the clinic’s program failures, and the clinic’s existence did not absorb the physician’s personal liability.
- Caps create board-visible risk. Even if first penalties are low, $500,000 custodian exposure changes residual risk conversations for multi-site operators.
- Breach response quality is an AMP variable. How quickly you detect, contain, report, and document will influence whether the regulator sees a rogue actor or a system that invites abuse.
Hospitals should also note the shared-EHR dimension. Privileges that span sites create technical reach far beyond a single circle of care. If your access model still assumes “credentialed equals clinically appropriate,” Decision 298 is your wake-up call.
What I would put on a 90-day plan
- Map agents and physicians who can reach shared EHRs beyond a single site.
- Verify that private clinics affiliated with credentialed staff have actual privacy management programs — not borrowed hospital policies they never operationalize.
- Rehearse breach reporting decision trees when the actor is a privileged physician, not only an employee.
- Brief the board on AMP caps and Decision 298 as the start of a series, not a one-off curiosity.
- Align HR, professional practice, and privacy so economic misuse of PHI is explicitly forbidden and auditable.
- Stress-test your “demonstrable accountability” evidence: training logs, policy acknowledgments, access audit samples, and incident timelines you can produce in days, not weeks.
- Review professional staff bylaws so privacy duties sit inside credentialing, not only employee handbooks.
Counsel and privacy officers should also stop treating AMP quantum as the only risk metric. Parallel exposure still includes college complaints, privilege loss, civil claims, and reputational harm to both the hospital and any affiliated clinic. The AMP is the new line item, not the whole bill.
How I brief non-health executives
If you sit in a parent health system or digital health vendor, translate Decision 298 into product language: commercial secondary use of clinical access is an enforcement magnet; weak clinic-side programs are not free-riders on hospital maturity; and monetary penalties now join notification and discipline in the residual risk table. Point people to primary sources on ipc.on.ca before they invent folk versions of the facts.
Actionable takeaway
Decision 298 is Ontario’s first clear AMP signal in the health privacy space. The numbers were measured. The message was not soft: PHIPA now has a monetary enforcement path, and the IPC will use it when access for private gain meets weak organizational controls. Read the decision. Read the AMP guidance. Then ask whether your evidence would survive the same progressive enforcement analysis. If the IPC asked tomorrow why an AMP is not needed in your last serious access incident, what proof would you hand over?