Why the Phone System Is Part of Your Compliance Perimeter
For clinics, dental offices, allied-health practices and any business handling personal health information (PHI), the phone system is a place PHI lives. Call recordings capture it. Voicemails contain it. Call logs reveal it. Under PIPEDA (federal) and PHIPA (Ontario), the safeguards protecting that information aren't optional — they're law.
This checklist translates the PIPEDA fair-information principles and PHIPA safeguard requirements into concrete, auditable actions for a clinic phone system. It's written for a real Canadian practice, not a generic healthcare-privacy summary.
The Legal Framework in One Page
PIPEDA (federal)
PIPEDA applies to private-sector organizations in Canada collecting, using or disclosing personal information in the course of commercial activities. Its 10 fair-information principles (Schedule 1) — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance — govern every touchpoint where personal information flows.
A phone call that captures a patient's name, DOB, diagnosis, appointment details, or billing information is a collection of personal information under PIPEDA.
PHIPA (Ontario)
For Ontario health information custodians (most clinics, physicians, dentists, pharmacies, optometrists, naturopaths and long-term-care homes are custodians), PHIPA is the primary health-privacy law. PHIPA's key operative requirements that touch phone systems:
- Section 10–12: Custodians must take reasonable steps to ensure PHI is protected against theft, loss and unauthorized use or disclosure.
- Section 12(1): Administrative, technical, and physical safeguards must be in place.
- Section 12(3): Custodians must notify individuals at the first reasonable opportunity of any unauthorized disclosure.
- Section 16: Custodians must provide notice to the public about their information practices (privacy policy).
Call recording and the Criminal Code
Section 184(2)(a) of the Criminal Code of Canada allows the interception of private communications with the consent of one party. This is the "one-party consent" rule that means an employee can lawfully record a call they are on. But for a business recording calls systematically, PIPEDA imposes additional consent and notification requirements.
OPC guidance on call recording (federal)
The Office of the Privacy Commissioner of Canada has published clear expectations for businesses recording customer calls: recording is a collection of personal information requiring knowledge and consent; a general privacy-policy statement alone is not sufficient; the caller must be notified at the outset of the call; and alternatives must be offered to callers who object (e.g., visit the clinic in person, use a web form, speak to a staff member on an unrecorded line).
The Clinic VoIP Compliance Checklist
Work through each section. Any "no" or "N/A" without documented justification is an open compliance item to close.
- Our clinic has a documented business purpose for recording calls (e.g., quality review, training, dispute resolution) YESNON/A
- Callers are notified at the outset of each call that the call may be recorded, with the purpose stated YESNON/A
- Callers who object to recording are offered a practical alternative (unrecorded line, in-person, web form) YESNON/A
- Recording notification is also in our written privacy policy and on our website, not as a replacement for the at-call notice but in addition to it YESNON/A
- Staff making outbound calls to patients know that they must verbally confirm the recording purpose before continuing YESNON/A
- We have a written retention period for call recordings tied to our business purpose (e.g., 90 days for training, longer only with documented reason) YESNO
- Recordings are automatically deleted at the end of the retention period — not manually, not "when we remember" YESNO
- Patients can request deletion of a specific recording and we have a documented process to honour the request YESNO
- Only staff with a legitimate business reason can access call recordings or voicemails containing PHI YESNO
- Access is role-based — not a shared login; each access is logged YESNO
- When a staff member leaves, their access is revoked within 24 hours YESNO
- Voicemail boxes for roles that handle PHI (reception, scheduling) have a strong PIN or password and are not shared casually YESNO
- Voicemail-to-email routing (if used) sends to a clinic-controlled mailbox, not a personal email YESNO
- We know which country our VoIP provider stores call recordings, voicemails, and call detail records (CDRs) in YESNO
- If any data is stored in the United States, we have documented the additional risk (U.S. CLOUD Act jurisdiction) and our patients are informed in the privacy policy YESNON/A
- Our VoIP provider has signed a data processing addendum (DPA) or equivalent written agreement confirming PIPEDA/PHIPA-compliant handling YESNO
- The provider has a documented breach-notification process with a response-time commitment we find acceptable YESNO
- For Ontario custodians: the provider understands their role as an agent of the custodian under PHIPA (section 17) and accepts that framing YESNON/A
- No staff member forwards clinic calls to a personal cell phone in a way that would disclose PHI to an unsecured carrier or personal voicemail YESNO
- Remote staff using the 3CX (or equivalent) mobile softphone have been trained not to use it on unsecured public Wi-Fi without a VPN YESNO
- The mobile softphone app has a device lock (PIN / biometric) required on the phone it's installed on YESNO
- If a personal device with the softphone is lost, we can remotely revoke its access without touching the device YESNO
- We have a written incident-response procedure that includes phone-system breaches (misdirected voicemail, unauthorized recording access, lost mobile device) YESNO
- Staff know who to call and in what timeframe if they suspect a phone-system privacy breach YESNO
- Our Ontario custodian reporting obligations (notifying the patient, and for significant breaches the IPC) are referenced in the incident response procedure YESNON/A
- We review this checklist annually, document any open items, and close them with a timeline YESNO
- We review at any of these triggers: change of VoIP provider, change of physical location, change in clinic practice areas, staff turnover above 20% YESNO
Recording Notification — Suggested Wording
Adapt this to your clinic. It satisfies the OPC's guidance on meaningful consent and the PHIPA openness-of-practice expectation for Ontario custodians.
Red-Flag Questions for Your Current Provider
If your clinic is already running VoIP, ask your provider these questions in writing. The answers should be unambiguous; if they're not, you have a compliance gap.
| Question | What a compliant answer looks like |
|---|---|
| Where are call recordings and voicemails stored? | A specific country (ideally Canada). A specific data centre or region. Not "the cloud." |
| Is any recording data ever transferred outside Canada? | A clear yes or no. If yes, disclosed in your patient-facing privacy policy. |
| Can a U.S. subpoena compel disclosure of our recordings? | For providers with U.S. operations: yes, under the CLOUD Act. You must weigh this against alternatives. |
| Do you sign a written DPA covering your handling of our PHI? | Yes, and they can produce a copy. If not, you're running on a handshake, which a regulator won't accept. |
| How long are recordings retained by default? | A specific number of days, and it matches your documented retention policy. |
| Who on your team can access our recordings? | Named roles (support, billing). Not "anyone." |
| What's your breach-notification commitment to us? | A time (e.g., within 24 hours of confirmation). A named channel. |
| Can we export our recordings and CDRs if we leave? | Yes, in a readable format. Not locked inside their portal. |
Sources
- Personal Information Protection and Electronic Documents Act (PIPEDA) — full text and fair-information principles at Schedule 1.
- Office of the Privacy Commissioner of Canada — Recording of Customer Telephone Calls, priv.gc.ca/en/privacy-topics/surveillance/02_05_d_14/.
- Office of the Privacy Commissioner of Canada — Guidelines for obtaining meaningful consent (2018), priv.gc.ca/en/privacy-topics/collecting-personal-information/consent/gl_omc_201805/.
- OPC Case Summary PIPEDA 2007-384 — telecommunications company on call-recording consent.
- Personal Health Information Protection Act, 2004 (Ontario PHIPA) — S.O. 2004, c. 3, Schedule A. Sections 10–17 on custodian safeguards and notice of practices.
- Information and Privacy Commissioner of Ontario — ipc.on.ca, guidance on health information custodian obligations and breach reporting.
- Criminal Code of Canada — s. 184(2)(a) on one-party consent to interception.