Ontario has a name for a company whose software touches your patients' information. It comes with a contract requirement.

Electronic service provider is a defined role under PHIPA, and a phone system that stores patient calls is squarely inside it.

Ontario's PHIPA governs personal health information held by health information custodians, and it deals directly with the vendors those custodians rely on. An electronic service provider is someone who supplies services that enable a custodian to collect, use, modify, disclose, retain or dispose of personal health information, a definition a recording, transcribing phone system meets on every clause. A custodian must have a written agreement with such a provider covering the services, the safeguards, and the PHIPA requirements the provider has to meet.

What is an electronic service provider under PHIPA?

Someone whose service enables a custodian to handle personal health information electronically. The definition is written around function rather than product category, which is why it captures systems that were never marketed as health software.

An AI receptionist is the clearest example of this gap. Nobody procures an answering service as a clinical system, and clinics rarely run one past the same review a practice management platform would get. But a service that records a patient explaining a symptom, transcribes it, and stores the transcript is enabling the custodian to collect and retain personal health information, which is the test.

The same reasoning applies to whatever sits behind the AI receptionist: the transcription provider, the storage layer, the model provider. Each is a link, and the custodian's obligations do not stop at the vendor it happens to have contracted with directly.

What does the written agreement have to address?

The services being provided, the administrative, technical and physical safeguards protecting the confidentiality and security of the information, and the PHIPA requirements the provider must comply with. In practice that means permitted uses, security obligations, breach notification, what happens to the data at the end of the contract, and the custodian's right to audit.

Agents are a separate category from electronic service providers and carry their own written requirements. A clinic that engages a person to take calls and a system to record them may be dealing with both roles at once, and the analysis differs for each.

  • Permitted use. What the provider may do with the information, stated positively; anything not permitted is not permitted.
  • Safeguards. Administrative, technical and physical, named specifically enough to be checked.
  • Breach notification. What the provider tells the custodian, and how quickly. The custodian's own notification duties depend on this arriving.
  • End of contract. Return or secure destruction of the information, and evidence that it happened.

What should an Ontario clinic settle before switching a line on?

Three questions, all answerable in a short conversation with a vendor: what is retained, for how long, and what happens when a patient asks for their information or asks for it to be deleted. If those answers require escalation to find, the agreement is not ready.

The most useful control is the same one that applies under every health privacy regime: reduce what gets collected. An AI receptionist does not need clinical detail to book an appointment. It needs to know someone wants one, when, and how to reach them, and it can be built to route anything beyond that to a human without storing it.

The second most useful control is retention. A default retention period chosen by a vendor for its own convenience is the most common finding in this area, and it is trivially fixable before launch and awkward to fix afterwards.

A phone system that records a patient describing a symptom and stores the transcript is an electronic service provider under PHIPA, whatever it was sold as, and that role comes with a written agreement requirement the clinic, not the vendor, is answerable for.

Nick Lovett, Founder, AnswerAI

We scope what a clinic line may capture before building it, so the compliance conversation is about a narrow, deliberate dataset instead of everything a caller happened to say.

Start free pilot

What this page does not cover

This is a reading of the legislation as it applies to an AI receptionist answering a business phone, not legal advice. Statutes are amended and regulators publish new guidance; check the source links, which are dated, and take advice on anything that matters.

  1. The agent analysis. PHIPA's rules for agents are distinct from those for electronic service providers. A clinic may be dealing with both, and this page addresses the second.
  2. Whether you are a custodian. That turns on PHIPA's definitions and the facts of your practice, and is a question for your own advisors.
  3. Breach notification thresholds. PHIPA's notification duties, including reporting to the Information and Privacy Commissioner of Ontario, are not detailed here.

Questions this raises

Is an AI receptionist an electronic service provider under PHIPA?
If it supplies services that enable a custodian to collect, use, retain or dispose of personal health information, it meets the definition. A system that records and stores patient calls does.
Do we need a separate agreement, or is the vendor's standard contract enough?
The requirement is for an agreement addressing the services, the safeguards and the applicable PHIPA requirements. A standard commercial contract that does not address those is not sufficient because it was signed.
Does PHIPA apply to a clinic's voicemail?
Voicemail containing personal health information is personal health information held by the custodian. The storage being unglamorous does not change the analysis.
What if the vendor stores data outside Ontario?
PHIPA does not impose a blanket residency requirement, but the custodian remains accountable and the arrangement needs to be addressed in the agreement. Where the data sits should be a stated fact, not an assumption.
Can a clinic's AI receptionist avoid handling health information at all?
Largely, yes, if it is designed for it. A line scoped to appointments and routing can avoid collecting clinical detail, which is the most effective way to reduce what has to be protected.

Sources

  1. Personal Health Information Protection Act, 2004, SO 2004, c 3, Sch AOntario e-Lawsconsulted 2026-08-09
Nick Lovett

Nick Lovett

Founder, AnswerAI

Nick Lovett builds AI receptionists for service businesses across North America, and writes these from the call data they produce. Lovett Ventures Inc., Calgary.

Want an AI receptionist built around these rules rather than despite them?

We build a working receptionist on your calls, your booking rules and your escalation rules, and you call it yourself before committing to anything. About 14 days, no call limit during the pilot.

Start free pilot