Government Notices — Other

Notice of Minister of Health

Notice of Proposed Regulation

Personal Health Information Protection Act, 2004

The Minister of Health on behalf of the Government of Ontario invites public comments on an amending regulation proposed to be made under the Personal Health Information Protection Act, 2004 (“PHIPA”).

PHIPA came into force on November 1, 2004. Ontario Regulation 329/04 (General) made under PHIPA (“the PHIPA General Regulation”) also came into force on November 1, 2004. PHIPA requires that the Minister publish a notice of the proposed amending regulation and allow 60 days for public comment, after which the Minister reports to the Lieutenant Governor in Council, who may then finalize the regulation with or without changes.

Content of Proposed Amending Regulation

If approved, the proposed regulation would amend the PHIPA General Regulation to expand the range of digital health services that patients are able to securely access via the Digital Health Identifier (DHI), further to Part V.2 of PHIPA.

Currently, the PHIPA General Regulation contains provisions that authorize Ontario Health (OH), in its role as the ‘prescribed organization’ under Part V.2 of PHIPA, to provide DHI activities, including validation and verification services, authentication services and account management services to enable the collection, use and disclosure of personal health information (PHI), including health card numbers, from an individual, with their express consent, to conduct such DHI activities and to support individuals’ access to records of PHI. The existing regulation only contains provisions that would permit OH to enable patients to use the DHI to access PHI from the provincial Electronic Health Record.

If approved, the proposed amendment to the PHIPA General Regulation would establish a framework that could be leveraged to enable Ontarians to use the DHI to access additional patient-facing Digital Health Resources (as defined in the proposed regulation), where available. It would also establish a framework under which OH, in consultation with the Minister of Health, would be able to approve Digital Health Resources provided by health information custodians (where available) to leverage the DHI authentication services, so that individuals could use the DHI to log in to these tools and authenticate themselves. In consultation with the Minister of Health, OH would be required to create eligibility criteria and a process for the approval of Digital Health Resources seeking to use these authentication services. The eligibility criteria and approval process will be published on OH’s website.

The proposed amending regulation would augment existing privacy protections by establishing additional requirements designed to support the secure delivery of DHI authentication services and Approved Digital Health Resources (as defined in the proposed regulation), including:

  • Requirements that both OH, in its role in delivering DHI authentication services under Part V.2 of PHIPA, as well as Digital Health Resource Providers (as defined in the proposed amending regulation) leveraging these authentication services:
    • Handle patient data securely and with appropriate privacy and security safeguards, and
    • Only handle patient data for specific and limited purposes related to authentication services in the context of Approved Digital Health Resources.
  • Provisions ensuring that OH, in its role in delivering DHI authentication services under Part V.2 of PHIPA, would be able to exchange patient information with Digital Health Resource Providers as necessary to support incident and breach management.

The public is invited to provide written comments on the proposed regulation over a 60-day period, commencing on August 22, 2026 and ending on October 21, 2026.

In providing comments, please consider whether the proposed amending regulation should be made, with or without changes. Furthermore, please consider whether any other regulatory amendments should be made to the PHIPA General Regulation, or if any legislative amendments should be contemplated. Please be as specific as possible, and provide a full rationale for any suggested changes or additions.

Written comments may be addressed to:

Information Management Strategy and Policy Branch
Ministry of Health
Digital and Analytics Strategy Division
Office of the Chief Digital Health Officer
222 Jarvis Street, 7th Floor
Toronto ON M7A 0B6
Email: healthprivacy.moh@ontario.ca

The text of the proposed amending regulation is set out following this notice in English and French. We welcome your input in either English or French. All comments and submissions received during the comment period will be considered during final preparation of the amending regulation. The content, structure and form of the proposed regulation is subject to change as a result of the consultation process and is in the discretion of the Lieutenant Governor in Council, who has the final decision on the contents of any regulation.

Information respecting PHIPA and the PHIPA General Regulation, and electronic copies of this notice, including the text of the proposed regulation, may be accessed through Ontario’s Regulatory Registry website at the following address: https://www.regulatoryregistry.gov.on.ca/home.

Copies of PHIPA and the PHIPA General Regulation are available at https://www.ontario.ca/laws

Please note that all materials or comments received from organizations in response to this Notice will be considered public information and may be used and disclosed by the Ministry to assist the Ministry in evaluating and revising the proposed regulation. This may involve disclosing materials or comments, or summaries of them, to other interested parties during and after the request for public comment process. An individual who provides materials or comments and who indicates an affiliation with an organization will be considered to have submitted those comments or materials on behalf of the organization so identified. Materials or comments received from individuals who do not indicate an affiliation with an organization will not be considered public information unless expressly stated otherwise by the individual. However, materials or comments provided by individuals may be used and disclosed by the Ministry to assist in evaluating and revising the proposed regulation. Personal information of those who do not specify an organizational affiliation, such as an individual’s name and contact details, is collected by the Ministry under the authority of subsection 38(2) of the Freedom of Information and Protection of Privacy Act and subsection 74(1) of the Personal Health Information Protection Act, 2004, and will not be disclosed by the Ministry without the individual’s consent unless required by law. If you have any questions about the collection of this information, you can contact the Freedom of Information and Privacy Coordinator of the Ministry of Health at 416-327-7040.

The Honourable Sylvia Jones
Minister of Health

Caution:

This consultation draft is intended to facilitate dialogue concerning its contents. Should the decision be made to proceed with the proposal, the comments received during consultation will be considered during the final preparation of the regulation. The content, structure, form and wording of the consultation draft are subject to change as a result of the consultation process and as a result of review, editing and correction by the Office of Legislative Counsel.

Consultation Draft

ontario regulation

to be made under the

personal health information protection act, 2004

Amending O. Reg. 329/04

(general)

1. Section 1.1 of Ontario Regulation 329/04 is amended by adding the following definitions:

“agent”, in relation to the Agency, means a person that, with the authorization of the Agency, acts for or on behalf of the Agency in respect of personal health information for the purposes of the Agency, and not the agent’s own purposes, whether or not the agent has the authority to bind the Agency, whether or not the agent is employed by the Agency and whether or not the agent is being remunerated; (“mandataire”)

“approved digital health resource” means a digital health resource that is,

  1. provided by the Agency or any of its agents, or
  2. approved in accordance with section 18.17; (“ressource numérique approuvée en matière de santé”)

“digital health resource” means a provincially funded health resource that enables a digital health resource provider to,

  1. use electronic means to collect, use, modify, disclose, transmit, maintain or dispose of personal health information for the purpose of providing health care or assisting in the provision of health care, or
  2. allow individuals to access, use, disclose, maintain or otherwise manage their records of personal health information; (“ressource numérique en matière de santé”)

“digital health resource provider” means the Agency and any of its agents or a health information custodian that provides one or more digital health resources; (“fournisseur de ressources numériques en matière de santé”)

“provincially funded health resource” has the same meaning as in subsection 34 (1) of the Act. (“ressource en matière de santé subventionnée par la province”)

2. Subsection 11.2 (2) of the Regulation is revoked.

3. (1) Subsection 12 (2) of the Regulation is revoked and the following substituted:

(2) Despite subsection 34 (3) of the Act, the Agency and any of its agents may disclose a health number of an individual that the Agency has custody or control of if the individual gives their express consent to the disclosure and,

  1. the disclosure is made to the Minister for the purpose of assisting the Agency in,
    1. providing validation and verification services,
    2. validating the identity of an individual who contacted the Agency because they require support accessing the digital means of access referred to in subsection 18.1.1 (3), or
    3. validating the identity of an individual who is seeking access to electronic records kept by the Agency under paragraph 4, 5 or 6 of section 55.3 of the Act or digital health identifier records in accordance with subsection 51 (7) of the Act; or
  2. the disclosure is made to a digital health resource provider for the purpose of providing authentication services in respect of the provider’s approved digital health resource.

(2) Clause 12 (2) (a) of the Regulation, as made by subsection (1), is amended by striking out “or” at the end of subclause (ii) and by adding the following subclause:

(ii.1) validating the identity of an individual who is seeking to use an alternative process described in clause 18.1.1 (3) (b), or

(3) Subsection 12 (3) of the Regulation is revoked.

4. The French version of paragraph 3 of subsection 18 (1) of the Regulation is revoked and the following substituted:

3. L’Institute for Clinical Evaluative Sciences.

5. Subsection 18.1.2.2 (1) of the Regulation is amended by adding the following paragraph:

5. Records of the date on which a digital health identifier was used to access an approved digital health resource.

6. Section 18.12 of the Regulation is revoked and the following substituted:

Other purposes

18.12 (1) This section applies if an individual with a digital health identifier has provided their consent for the Agency to do any of the following, even if the individual subsequently withdraws their consent:

  1. Collect, use or disclose the individual’s personal health information under section 55.17 of the Act for the purpose of carrying out digital health identifier activities.
  2. Collect or use the individual’s health number under section 11.2 for the purpose of carrying out the Agency’s powers or duties under Part V.2 of the Act.

(2) The Agency may collect, use and disclose the personal health information of an individual described in subsection (1) for the following purposes even, where applicable, if the individual has withdrawn their consent:

  1. Retention, maintenance and disposal of the personal health information.
  2. Incident and breach management activities, including maintenance, auditing and responding to such incidents or breaches.

7. The Regulation is amended by adding the following sections:

Digital health resource approval

18.17 (1) The Agency may, in consultation with the Minister and in accordance with the eligibility criteria and approval process described in subsection (2), approve a digital health resource.

(2) The Agency shall, in consultation with the Minister, create eligibility criteria and a process for the approval of digital health resources and publish them on the Agency’s website.

(3) The eligibility criteria and approval process described in subsection (2) must require the following:

  1. The digital health resource provider seeking approval of the digital health resource must submit the following assessments to the Agency for review:
    1. An assessment with respect to threats, vulnerabilities and risks to the security and integrity of the personal health information collected, used or disclosed by the digital health resource provider in respect of the digital health resource.
    2. An assessment with respect to how the digital health resource may affect the privacy of the individuals to whom the information relates.
  2. The digital health resource provider seeking approval of the digital health resource must enter into an agreement with the Agency that includes the following:
    1. A description of the authentication services that the Agency will provide to the digital health resource provider in respect of the digital health resource.
    2. A description of the administrative, technical and physical safeguards that the Agency will implement to preserve the confidentiality and security of any personal health information that will be disclosed by the Agency in providing authentication services.
    3. A description of the digital health resource and the personal health information that will be collected by the digital health resource provider in respect of the digital health resource.
    4. A description of the administrative, technical and physical safeguards of the digital health resource.

(4) An agreement described in paragraph 2 of subsection (3) with a digital health resource provider may be,

  1. made in respect of one or more digital health resources that are provided by the health information custodian;
  2. included as part of an agreement that addresses other matters not listed in that paragraph; and
  3. amended after the agreement has been made to reflect any newly approved digital health resources.

Digital health resource providers

18.18 (1) Every digital health resource provider that collects personal health information from the Agency in respect of an approved digital health resource shall only use or disclose that personal health information,

  1. in respect of the approved digital health resource as permitted by law; or
  2. as otherwise required by law.

(2) The Agency and any of its agents, when acting as a digital health resource provider in respect of an approved digital health resource, shall only use or disclose personal health information collected through authentication services,

  1. in respect of the approved digital health resource as permitted by law; or
  2. as otherwise required by law.

(3) A digital health resource provider shall not permit any person acting on its behalf to access the personal health information that it collected in the course of receiving authentication services in respect of its approved digital health resource unless the person agrees to comply with the restrictions and conditions that apply to the digital health resource provider when it receives authentication services.

Collection, use and disclosure for authentication services

18.19 (1) The Agency and any of its agents may, with the express consent of the individual to whom the personal health information relates, disclose personal health information for the purpose of providing authentication services to a digital health resource provider in respect of the provider’s approved digital health resource.

(2) A digital health resource provider may collect personal health information from the Agency and use it for the purpose of receiving authentication services from the Agency or any of its agents in respect of their approved digital health resource.

Other purposes

18.20 (1) This section applies if an individual has provided their consent for the Agency or any of its agents to collect, use or disclose the individual’s personal health information for the purpose of providing authentication services, even if the individual subsequently withdraws their consent.

(2) The Agency and any of its agents may collect, use and disclose the personal health information of an individual described in subsection (1) for the purpose of incident and breach management activities, including maintenance, auditing and responding to such incidents or breaches, even, where applicable, if the individual has withdrawn their consent.

(3) A digital health resource provider may collect, use and disclose personal health information that it received from the Agency through authentication services in respect of their approved digital health resource for the purpose of incident and breach management activities, including maintenance, auditing and responding to such incidents or breaches, even, where applicable, if the individual has withdrawn their consent.

Revocation

8. Subsection 3 (2) of Ontario Regulation 314/25 is revoked.

Commencement

9. [Commencement]

(159-G118E)

Marriage Act

certificate of permanent registration as a person authorized to solemnize marriage in Ontario have been issued to the following:

July 27, 2026 to August 02, 2026

NameLocationEffective Date
Clarke, Krystiana RoseAjax, ON, CA27-Jul-2026
Eyong, Wilson EgbarengChatham , ON, CA27-Jul-2026
Joyson, Satheeshkumar JoyWindsor, ON, CA27-Jul-2026
Khurana, ManasOttawa, ON, CA27-Jul-2026
Muller, Jacqueline EmmaOttawa, ON, CA27-Jul-2026
Thomas, Sooraj PauloseEtobicoke, ON, CA27-Jul-2026
King Gilliard-Samuel, GezeelWoodbridge, ON, CA28-Jul-2026
Lukavenko, YaroslavSarnia, ON, CA28-Jul-2026
Mowafy, Neamat Sadeek MohammadNorth York, ON, CA28-Jul-2026
Muhia, Ann NjambiTrenton, ON, CA28-Jul-2026
Ofori, FosterWelland, ON, CA28-Jul-2026
Tadros, Magdy Guirguis FamMississauga, ON, CA28-Jul-2026
Vargas, Almer James YuzonHamilton, ON, CA28-Jul-2026
Wiredu, Felix StephenMilton, ON, CA28-Jul-2026

Re-Registrations

NameLocationEffective Date
Kariuki, Alex KahuguNorth Bay, ON, CA28-Jul-2026
Stieva, Leonard KevinKingston, ON, CA28-Jul-2026
Wojakiewicz, Piotr JanBurlington, PE, CA28-Jul-2026

certificates of temporary registration as person authorized to solemnize marriage in Ontario have been issued to the following:

July 27, 2026 to August 02, 2026

DateNameLocationEffective Date
19-Aug-2026 to 23-Aug-2026Amarasingha, ErandhithaHalifax, NS, CA27-Jul-2026
27-Aug-2026 to 31-Aug-2026Alkema, Hendrik ThomasSmithers, BC, CA28-Jul-2026

certificate of cancellation of registration as a person authorized to solemnize marriage in Ontario have been issued to the following:

July 27, 2026 to August 02, 2026

NameLocationEffective Date
Caldwell-Reeves, Elaine EthelOrangeville, ON, CA29-Jul-2026
Cohen, Roderick Darnell JacobNorth York, ON, CA29-Jul-2026
Finnie, MichaelMilton, ON, CA29-Jul-2026
Greville, Kenneth RobertCambridge, ON, CA29-Jul-2026
Hamelin, JoyceCarleton Place, ON, CA29-Jul-2026
Hutzel, David LCobourg, ON, CA29-Jul-2026
Kim, Sung HoSooke, BC, CA29-Jul-2026
Markle, Edward JohnColdwater, ON, CA29-Jul-2026
Marryshow, Angus ChristopherToronto, ON, CA29-Jul-2026
Meeks, Charles EdwardVancouver, BC, CA29-Jul-2026
Reed, Jessie LaurenAjax, ON, CA29-Jul-2026
Thompson, Marsha SuzetteKitchener, ON, CA29-Jul-2026

Sirad Mohamoud
Deputy Registrar General

(159-G119)

certificate of permanent registration as a person authorized to solemnize marriage in Ontario have been issued to the following:

August 03, 2026 to August 09, 2026

NameLocationEffective Date
Fenelon, SylfrardHamilton, ON, CA05-Aug-2026
Fisher, Fiona DathlynMississauga, ON, CA05-Aug-2026
Gonsalves, IsraelCambridge, ON, CA05-Aug-2026
Gordon, JohnathanDundas, ON, CA05-Aug-2026
Grant, Michael FitzgeraldOshawa, ON, CA05-Aug-2026
Miranda, Rohan CedricOakville, ON, CA05-Aug-2026
Morataya, Kevin ReneKitchener, ON, CA05-Aug-2026
Neufeld, Douglas RobertNiagara Falls, ON, CA05-Aug-2026
Pegg, Danny LeeSt Catharines, ON, CA05-Aug-2026
Ponce-Maese, GustavoOakville, ON, CA05-Aug-2026
Romanets, MykolaLondon, ON, CA05-Aug-2026
Rose, LeeGatineau, QC, CA05-Aug-2026
Sargent, BarbaraChatham, ON, CA05-Aug-2026
Sayers, Scott AllanCornwall, ON, CA05-Aug-2026
Seiling, Tanya JacquelineElora, ON, CA05-Aug-2026
Shih, Adam DavidMarkham, ON, CA05-Aug-2026
Vernon-Grant, Marie DenieceOshawa, ON, CA05-Aug-2026
Young, Eleanor VenduneciaOshawa, ON, CA05-Aug-2026
Zeljeznjak, IvanHamilton, ON, CA05-Aug-2026

Re-Registrations

NameLocationEffective Date
Hembree, Charles RodneyOrangeville, ON, CA05-Aug-2026
Sim, Michelle FrancesOakville, ON, CA05-Aug-2026

certificates of temporary registration as person authorized to solemnize marriage in Ontario have been issued to the following:

August 03, 2026 to August 09, 2026

DateNameLocationEffective Date
06-Aug-2026 to 10-Aug-2026Langeh, Jude ThaddeusRome, Rome-Lazio, Italy06-Aug-2026
17-Sep-2026 to 21-Sep-2026Shephard, William RyanMiddleton, NS, CA06-Aug-2026

Sirad Mohamoud
Deputy Registrar General

(159-G120)