
Do I Need a Privacy Impact Assessment for Our AI Scribe? A Decision Tree for Ontario Health Information Custodians
A seven-question decision tree to determine what level of Privacy Impact Assessment your Ontario clinic needs for its AI scribe under PHIPA and the IPC's January 2026 guidance.
Short answer: If your clinic is using, procuring, or developing an AI scribe in Ontario, the Information and Privacy Commissioner of Ontario expects you to have completed a Privacy Impact Assessment before the tool touches a single patient encounter. PHIPA does not name "PIA" as a statutory submission requirement the way Alberta's Health Information Act does, but as of the IPC's January 2026 guidance, operating an AI scribe without one is operating outside the regulator's stated expectations for custodians.
This article walks you through a seven-question decision tree to determine exactly what level of assessment your clinic needs, what the IPC is looking for, and what happens if you skip it.
Who this article is for
You are a health information custodian in Ontario. That includes family physicians, specialists, Family Health Teams, dental and optometry practices, walk-in clinics, community health centres, independent health facilities, and allied health professionals who collect, use, or disclose personal health information in the course of care. You have either deployed an AI scribe in the last twelve months, are currently evaluating one, or are quietly aware that your staff has started using one without formal governance approval.
If any of those describe your clinic, this decision tree is for you.
The one-sentence version of the law
Under Ontario's Personal Health Information Protection Act, 2004 (PHIPA), the custodian is accountable for all personal health information in its custody or control, and that accountability does not transfer to a vendor just because the vendor is processing the data.
That sentence is the entire reason you need a PIA.
What the IPC actually said in January 2026
On January 28, 2026, the IPC released AI Scribes: Key Considerations for the Health Sector along with a companion checklist. The guidance does not create a new legal obligation. PHIPA already applied to AI scribes the moment they started processing personal health information. What the guidance did was make the IPC's expectations specific and auditable.
Three expectations matter most for the PIA question:
- Custodians should have an AI governance and accountability framework in place before deploying an AI scribe.
- Custodians should establish clear criteria for when a Privacy Impact Assessment is conducted, and conduct one before introducing an AI system that handles personal health information.
- Custodians are expected to update assessments whenever the AI system changes in ways that affect how personal health information is collected, used, or disclosed.
The guidance is not legally binding. PHIPA is. But when the IPC investigates a privacy breach involving an AI scribe, the guidance is the yardstick it will measure your practices against.
The decision tree
Work through these seven questions in order. Stop at the first question where the answer tells you what to do.
Question 1: Does your AI scribe collect, use, or disclose personal health information?
If the tool records patient-clinician conversations, transcribes them, generates notes, summaries, referral letters, or any other output derived from a clinical encounter, the answer is yes.
If yes, continue to Question 2. If no (and this is genuinely rare), document why and move on.
Question 2: Does your clinic have an existing PIA that specifically covers the AI scribe you are using?
Not a PIA for your EMR. Not a PIA for a prior transcription service. A PIA that names this specific AI scribe, its vendor, its data flows, and its integration points.
If yes, skip to Question 6. If no, continue to Question 3.
Question 3: Is the AI scribe on the OntarioMD Vendor of Record list, and does your contract prohibit secondary use and vendor model training?
As of early 2026, OntarioMD, the Ministry of Health, and the Canadian Medical Protective Association have jointly approved a Vendor of Record list of AI scribe products that have been screened against medico-legal and information-handling criteria. Using an approved vendor simplifies your vendor due diligence. It does not replace your PIA.
Why? Because PHIPA accountability sits with the custodian, not the vendor. The vendor's approval status confirms that they are contractually capable of meeting certain standards. Whether you have configured and deployed the tool in a compliant way inside your clinic is a separate question, and it is the one your PIA answers.
If yes, proceed to Question 4. A full PIA is still required, but your vendor-side documentation burden is reduced. If no, proceed to Question 4. A full PIA is required and your vendor due diligence documentation burden is significantly higher.
Question 4: Does the AI scribe retain audio recordings, transcripts, or outputs for any purpose beyond creating the clinical note?
This includes vendor training, model improvement, analytics, quality assurance by the vendor, or any storage that persists after the note is created and verified.
If yes, you need a full PIA and you need to scrutinize the legal basis for the secondary use. The IPC's position is that audio recordings almost never meet PHIPA's de-identification threshold of "very low" re-identification risk, which effectively prohibits vendor training on that data without explicit patient consent.
If no, continue to Question 5.
Question 5: Are patients consistently informed that an AI scribe is being used, and given a real choice to decline?
The IPC has stated that consent is generally required for AI scribe use. Patients must understand that the encounter is being recorded using AI, what information is collected, which vendors are involved, and the key risks and benefits. They must have a genuine ability to decline without receiving a lower standard of care.
If no, your PIA is not just needed, it is urgent. A gap here is the single most likely source of a future complaint to the IPC. If yes, continue to Question 6.
Question 6: Has the AI scribe, its vendor, its configuration, or its use case changed since your last PIA?
Changes that trigger a PIA update include a new software version with expanded features, a change in data residency, a new integration with your EMR, a new clinical use case (for example, moving from primary care notes to specialist referral letters), or a change in vendor ownership or subcontractors.
If yes, your existing PIA needs to be updated. If no, continue to Question 7.
Question 7: Has your AI governance committee reviewed the AI scribe in the last twelve months?
The IPC expects ongoing monitoring, not a one-time sign-off. Even a well-documented PIA from 2024 is stale if no one has revisited it since.
If no, schedule a formal review. Ongoing assessment is part of the governance framework the IPC expects. If yes, you are likely in good standing. Document the review date and carry on.
What your PIA actually needs to contain
The IPC has not published a mandatory PIA template for AI scribes under PHIPA the way Alberta's OIPC has for HIA custodians. That said, a defensible AI scribe PIA in Ontario covers the following sections:
- Project description. What the AI scribe is, what it does, who uses it, and why your clinic procured or developed it.
- Data inventory. Categories of personal health information collected, used, and disclosed by the tool. Audio, transcripts, generated notes, metadata, and any derived outputs.
- Data flow diagram. Every point where personal health information moves between the patient, the clinician, the AI scribe application, the vendor's cloud infrastructure, any subprocessors, your EMR, and any backup or logging systems.
- Legal authority analysis. The PHIPA provisions that authorize each collection, use, and disclosure, and the consent basis where applicable.
- Vendor assessment. Security certifications, data residency, subprocessor list, breach notification obligations, audit rights, and contractual limits on secondary use and training data.
- Risk register. Identified privacy and security risks, likelihood and impact ratings, and mitigation measures.
- Governance and accountability. Who owns the tool internally, how staff are trained, how patients are informed, how consent is obtained and documented, and how incidents are handled.
- Monitoring plan. What gets reviewed, how often, and who is accountable.
- Sign-off. Named decision-makers and the date the PIA was approved.
What happens if you skip the PIA
You are not going to get fined by the IPC tomorrow for not having a PIA. Ontario's enforcement model is complaint-driven and the IPC does not impose statutory fines under PHIPA the way federal regulators do under some other frameworks.
The real risk is different, and more concrete:
A patient complaint triggers an IPC investigation. The IPC asks for your PIA. You do not have one. The IPC's published guidance becomes the reasonable-custodian standard your clinic is measured against. Any breach or adverse finding is now compounded by a documented failure to meet the IPC's stated expectations for governance.
For regulated health professionals, the downstream risk is your college. Medico-legal defensibility in a College complaint increasingly depends on being able to show that the AI tools in your practice were governed with the same care as any other part of the clinical record. A missing PIA is a gift to opposing counsel.
The quieter cost: referral partners, hospital affiliations, and larger clinic networks are starting to require PIA documentation as a condition of collaboration or onboarding. Not having one closes doors you may not know were open.
Common mistakes to avoid
- Treating the vendor's SOC 2 report as a substitute for a PIA. A SOC 2 report tells you the vendor has certain controls. It does not tell you whether your clinic's specific use of the tool complies with PHIPA.
- Assuming OntarioMD Vendor of Record approval covers your obligations. It does not. VOR approval is about the vendor. The PIA is about you.
- Using a generic PIA template that was written for an EMR migration. AI scribes introduce risks that static systems do not, including model drift, hallucination, bias, and secondary use questions. Your PIA needs to address them explicitly.
- Relying on implied consent. The IPC has been clear that patients need to be actively informed about AI scribe use. A notice taped to the waiting room wall is not sufficient documentation of consent.
- Completing the PIA once and filing it. A PIA is a living document. Tie it to your annual governance review, your vendor contract renewal dates, and any change in the tool or its use.
Frequently asked questions
Is a PIA legally required under PHIPA?
PHIPA does not explicitly require custodians to complete and submit a PIA to the IPC the way Alberta's Health Information Act requires under section 64. However, the IPC's January 2026 guidance sets a clear expectation that custodians conduct PIAs before introducing AI systems that handle personal health information, and ongoing regulatory scrutiny is best met with a documented assessment.
How long does a PIA take?
For a single-clinic deployment using an approved vendor, a competent PIA typically takes two to four weeks of focused work, including vendor documentation review, data flow mapping, stakeholder interviews, and drafting. Larger or custom deployments take longer.
Who should conduct the PIA?
The PIA can be conducted internally by a clinic staff member with privacy expertise, or by an external consultant. Either way, the custodian remains accountable for the content and sign-off. A PIA written by the vendor is not a substitute for a custodian PIA.
What if we already deployed the AI scribe without a PIA?
Complete one now. Document the date the tool was deployed, the date the PIA was completed, and the gap. Then implement any remediation the PIA identifies. Retroactive PIAs are common and the IPC treats them more favourably than missing PIAs.
Does this apply to pilot projects and trials?
Yes. If the pilot involves real patient encounters and real personal health information, PHIPA applies and the IPC's expectations apply. A scaled-down PIA is appropriate for a pilot, with a commitment to expand it before full deployment.
Next step
If you are reading this and realizing your clinic does not have a PIA for its AI scribe, the next step is not a panic. It is a structured assessment of where you are, what you have, and what you need to build.
Ciniji Group helps Ontario health information custodians close exactly this gap. Our Governance-First AI Readiness Assessment maps your current AI scribe deployment against PHIPA and the IPC's 2026 guidance, identifies the governance work required, and gives you a prioritized remediation plan.
Book a 20-minute custodian readiness call
We'll map your AI scribe deployment against PHIPA and the IPC's 2026 guidance, and give you a prioritized remediation plan.
Book your call