DVGVoIP — Thunder Bay, Ontario

The Canadian Clinic VoIP Compliance Checklist

Phone-system obligations under PIPEDA and Ontario PHIPA — with the consent language, data-residency questions, and access controls your regulator actually expects.

Why the Phone System Is Part of Your Compliance Perimeter

For clinics, dental offices, allied-health practices and any business handling personal health information (PHI), the phone system is a place PHI lives. Call recordings capture it. Voicemails contain it. Call logs reveal it. Under PIPEDA (federal) and PHIPA (Ontario), the safeguards protecting that information aren't optional — they're law.

This checklist translates the PIPEDA fair-information principles and PHIPA safeguard requirements into concrete, auditable actions for a clinic phone system. It's written for a real Canadian practice, not a generic healthcare-privacy summary.

Important: This document is a compliance-planning tool. It is not legal advice. If you are an Ontario health information custodian under PHIPA, your obligations may extend beyond what appears here. Consult your regulatory college and, where warranted, a privacy lawyer.

The Legal Framework in One Page

PIPEDA (federal)

PIPEDA applies to private-sector organizations in Canada collecting, using or disclosing personal information in the course of commercial activities. Its 10 fair-information principles (Schedule 1) — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance — govern every touchpoint where personal information flows.

A phone call that captures a patient's name, DOB, diagnosis, appointment details, or billing information is a collection of personal information under PIPEDA.

PHIPA (Ontario)

For Ontario health information custodians (most clinics, physicians, dentists, pharmacies, optometrists, naturopaths and long-term-care homes are custodians), PHIPA is the primary health-privacy law. PHIPA's key operative requirements that touch phone systems:

Call recording and the Criminal Code

Section 184(2)(a) of the Criminal Code of Canada allows the interception of private communications with the consent of one party. This is the "one-party consent" rule that means an employee can lawfully record a call they are on. But for a business recording calls systematically, PIPEDA imposes additional consent and notification requirements.

OPC guidance on call recording (federal)

The Office of the Privacy Commissioner of Canada has published clear expectations for businesses recording customer calls: recording is a collection of personal information requiring knowledge and consent; a general privacy-policy statement alone is not sufficient; the caller must be notified at the outset of the call; and alternatives must be offered to callers who object (e.g., visit the clinic in person, use a web form, speak to a staff member on an unrecorded line).

The Clinic VoIP Compliance Checklist

Work through each section. Any "no" or "N/A" without documented justification is an open compliance item to close.

A. Call Recording & Notification
  1. Our clinic has a documented business purpose for recording calls (e.g., quality review, training, dispute resolution) YESNON/A
  2. Callers are notified at the outset of each call that the call may be recorded, with the purpose stated YESNON/A
  3. Callers who object to recording are offered a practical alternative (unrecorded line, in-person, web form) YESNON/A
  4. Recording notification is also in our written privacy policy and on our website, not as a replacement for the at-call notice but in addition to it YESNON/A
  5. Staff making outbound calls to patients know that they must verbally confirm the recording purpose before continuing YESNON/A
B. Retention & Deletion
  1. We have a written retention period for call recordings tied to our business purpose (e.g., 90 days for training, longer only with documented reason) YESNO
  2. Recordings are automatically deleted at the end of the retention period — not manually, not "when we remember" YESNO
  3. Patients can request deletion of a specific recording and we have a documented process to honour the request YESNO
C. Access Controls
  1. Only staff with a legitimate business reason can access call recordings or voicemails containing PHI YESNO
  2. Access is role-based — not a shared login; each access is logged YESNO
  3. When a staff member leaves, their access is revoked within 24 hours YESNO
  4. Voicemail boxes for roles that handle PHI (reception, scheduling) have a strong PIN or password and are not shared casually YESNO
  5. Voicemail-to-email routing (if used) sends to a clinic-controlled mailbox, not a personal email YESNO
D. Data Residency & Vendor Selection
  1. We know which country our VoIP provider stores call recordings, voicemails, and call detail records (CDRs) in YESNO
  2. If any data is stored in the United States, we have documented the additional risk (U.S. CLOUD Act jurisdiction) and our patients are informed in the privacy policy YESNON/A
  3. Our VoIP provider has signed a data processing addendum (DPA) or equivalent written agreement confirming PIPEDA/PHIPA-compliant handling YESNO
  4. The provider has a documented breach-notification process with a response-time commitment we find acceptable YESNO
  5. For Ontario custodians: the provider understands their role as an agent of the custodian under PHIPA (section 17) and accepts that framing YESNON/A
E. Call Forwarding & Mobile Softphone Use
  1. No staff member forwards clinic calls to a personal cell phone in a way that would disclose PHI to an unsecured carrier or personal voicemail YESNO
  2. Remote staff using the 3CX (or equivalent) mobile softphone have been trained not to use it on unsecured public Wi-Fi without a VPN YESNO
  3. The mobile softphone app has a device lock (PIN / biometric) required on the phone it's installed on YESNO
  4. If a personal device with the softphone is lost, we can remotely revoke its access without touching the device YESNO
F. Incident & Breach Response
  1. We have a written incident-response procedure that includes phone-system breaches (misdirected voicemail, unauthorized recording access, lost mobile device) YESNO
  2. Staff know who to call and in what timeframe if they suspect a phone-system privacy breach YESNO
  3. Our Ontario custodian reporting obligations (notifying the patient, and for significant breaches the IPC) are referenced in the incident response procedure YESNON/A
G. Annual Review
  1. We review this checklist annually, document any open items, and close them with a timeline YESNO
  2. We review at any of these triggers: change of VoIP provider, change of physical location, change in clinic practice areas, staff turnover above 20% YESNO

Recording Notification — Suggested Wording

Adapt this to your clinic. It satisfies the OPC's guidance on meaningful consent and the PHIPA openness-of-practice expectation for Ontario custodians.

OPTION 1 — At-Call Notification (automated auto-attendant): "Thank you for calling [Clinic Name]. Please note that for quality and training purposes, calls may be recorded. If you prefer not to be recorded, please let the staff member know at the start of the call, press 2 to leave a secure voicemail, or visit our website at [url] to request an appointment online." OPTION 2 — Staff Member Greeting Script: "[Clinic Name], this is [Staff Name]. Please note that this call may be recorded for quality and training purposes — let me know if you'd prefer not to be recorded. How can I help you today?" OPTION 3 — Privacy Policy Paragraph: "[Clinic Name] may record incoming and outgoing telephone calls for the purposes of quality assurance, staff training, and resolving any dispute about the content of a call. Recordings that contain personal health information are stored within Canada, protected with access controls, and retained for [X] days, after which they are automatically deleted. If you do not wish a call to be recorded, please advise the staff member at the beginning of the call. You may at any time request a copy of a recording of a call you participated in, or request that it be deleted, by writing to our Privacy Officer at [email]."

Red-Flag Questions for Your Current Provider

If your clinic is already running VoIP, ask your provider these questions in writing. The answers should be unambiguous; if they're not, you have a compliance gap.

QuestionWhat a compliant answer looks like
Where are call recordings and voicemails stored?A specific country (ideally Canada). A specific data centre or region. Not "the cloud."
Is any recording data ever transferred outside Canada?A clear yes or no. If yes, disclosed in your patient-facing privacy policy.
Can a U.S. subpoena compel disclosure of our recordings?For providers with U.S. operations: yes, under the CLOUD Act. You must weigh this against alternatives.
Do you sign a written DPA covering your handling of our PHI?Yes, and they can produce a copy. If not, you're running on a handshake, which a regulator won't accept.
How long are recordings retained by default?A specific number of days, and it matches your documented retention policy.
Who on your team can access our recordings?Named roles (support, billing). Not "anyone."
What's your breach-notification commitment to us?A time (e.g., within 24 hours of confirmation). A named channel.
Can we export our recordings and CDRs if we leave?Yes, in a readable format. Not locked inside their portal.

Sources