A multi-site Toronto dental and medical group discovered that front desk staff were using consumer AI tools to summarize patient intake forms and draft referral letters - processing personal health information outside Canada without a data processing agreement. This composite case study covers the PHIPA exposure, AI inventory audit, and how governance controls were implemented across all three clinic locations.
AI Governance for a Toronto Healthcare Clinic: Closing a PHIPA Gap Before It Became a Breach
This is a composite case study. The scenario, challenge, and outcome are based on patterns Group 4 Networks observes across Toronto healthcare clients. No individual organization is identified.
The Problem
A three-site dental and family medicine group in the Greater Toronto Area had invested significantly in modernizing its clinical operations over the previous two years - new practice management software, updated imaging systems, and a shift to digital patient intake. The clinic director was satisfied with the technology infrastructure and confident in the organization's PHIPA compliance posture.
What the clinic director did not know was that front desk staff at two of the three locations had started using consumer AI tools on their own initiative. One team member was using a free AI writing assistant to draft referral letters, pasting in patient notes from the practice management system. Another was using a chatbot to summarize patient intake forms before physician consultations. A third was experimenting with an AI scheduling tool that had requested access to the clinic's shared calendar, which included patient appointment details.
None of these tools had been assessed for PHIPA compliance. None had Canadian data processing agreements. The personal health information being processed by these tools - patient names, health histories, referral content - was being transmitted to and processed on servers outside Canada.
The situation came to light during a routine technology review by Group 4 Networks, which had been providing managed IT services to the clinic for several years. The review flagged outbound traffic to AI service endpoints that had not been authorized by the clinic's IT policy.
What the Audit Found
Group 4 Networks conducted a full AI inventory audit across all three clinic sites within five business days. The audit combined network traffic analysis, review of Microsoft 365 activity, and staff interviews.
Findings:
- 6 distinct consumer AI tools were in active use across the three sites
- All 6 processed data on servers outside Canada with no data processing agreements
- Personal health information - including patient names, date of birth references, health conditions, and referral content - had been input into at least 3 of the 6 tools
- None of the tools had been reviewed against PHIPA requirements before staff began using them
- The clinic's existing PHIPA privacy policy did not address AI tool use
Under PHIPA, a health information custodian is responsible for the personal health information in its custody, including when that information is shared with agents or third parties. The use of unapproved AI tools to process patient information without an appropriate data processing agreement was a material gap in the clinic's PHIPA compliance posture. The gap had not yet resulted in a reportable incident, but the potential exposure was significant.
The Approach
Group 4 Networks designed a governance response that could be implemented consistently across all three clinic sites, at a pace that did not disrupt clinical operations.
PHIPA-aligned data classification
Patient health information was classified at the highest data tier - no external AI processing permitted without explicit PHIPA compliance review and a signed data processing agreement. Internal administrative information (staff schedules, non-patient correspondence) was classified at a lower tier with appropriate controls.
Access controls via Entra ID and network policy
Entra ID conditional access policies were configured to restrict access to known consumer AI web services from clinic-managed devices. Network-level controls were applied at each of the three sites to flag traffic to AI endpoints outside the approved list. These controls were deployed at all three sites within two weeks of the audit findings.
PHIPA-aligned acceptable-use policy
A plain-language AI acceptable-use policy was drafted for clinic staff - written specifically for a healthcare context, not a generic technology policy. The policy explained which tools were approved (none involving external AI for patient data), which staff roles could use which approved tools, and how to report a potential AI policy question or incident.
Clinic-wide staff training
A one-hour training session was delivered at each of the three sites, timed to shift changes to minimize disruption. The training covered what PHIPA requires, why consumer AI tools created an exposure, how to recognize a tool that processes patient data, and where to direct questions. Training was completed within four weeks of the audit findings.
Microsoft 365 Copilot assessment
The clinic director asked whether Microsoft 365 Copilot could be used for administrative drafting - referral letter templates, non-clinical correspondence. Group 4 Networks completed a PHIPA-focused configuration review of the clinic's Microsoft 365 environment and confirmed that, with appropriate sensitivity labels and access controls configured, Copilot could be used for Tier 2 administrative drafting work that does not involve patient health information.
Outcome
At the 60-day mark following the audit:
- Zero unapproved AI tools detected at any of the three sites in the follow-up network audit
- PHIPA gap closed: personal health information was no longer being processed by unapproved external AI tools
- Governance policy ratified by the clinic director and distributed to all clinical and administrative staff across all three sites
- All 3 sites operating on consistent AI access controls, verified by network monitoring
- Staff training completed at 100 percent across administrative staff at all three locations
- Microsoft 365 Copilot approved and configured for Tier 2 administrative drafting with appropriate sensitivity label controls
- Incident-free 90-day check: no PHI-related AI policy violations detected in the 90-day follow-up audit
The clinic director's assessment at the 90-day review: the governance program gave the organization visibility it had not had before, and the controls were in place before a reportable incident occurred.
What This Means for Toronto Healthcare Organizations
PHIPA creates strict obligations for health information custodians in Ontario. The use of consumer AI tools by clinical or administrative staff - even without IT authorization - creates PHIPA exposure for the organization if those tools process personal health information outside an appropriate data governance framework.
The challenge for most healthcare organizations is that staff adopt AI tools the same way they adopt any productivity tool: because it makes their work easier, not because they have considered the regulatory implications. A governance program that addresses AI tools specifically - with clear policies, technical controls, and training - closes this gap before it becomes a reportable incident.
Group 4 Networks' AI Governance service is designed for healthcare organizations at this stage. Our healthcare IT services include AI governance as part of the managed IT engagement for Ontario clinics, medical groups, and dental practices.
Contact us at (416) 623-9677 or book a free AI Governance assessment.
Frequently Asked Questions
Does PHIPA apply to AI tools that process patient data?
Yes. PHIPA applies to personal health information in the custody or control of a health information custodian, regardless of where or how it is processed. Using a consumer AI tool to process patient information - even for an administrative task like drafting a referral letter - without a written data sharing agreement and appropriate safeguards is a PHIPA compliance issue. Ontario's Information and Privacy Commissioner has indicated that AI tools processing personal health information are subject to the same requirements as any other third-party processor.
What AI tools are safe for healthcare staff to use in Toronto clinics?
The answer depends on what data the tool accesses and processes. Tools that process only anonymized or non-patient administrative content (such as drafting internal memos or non-clinical correspondence) may be appropriate with standard controls. Tools that process any patient-identifying information require PHIPA compliance review, a data processing agreement with the vendor confirming Canadian data residency and processing controls, and sensitivity label controls to prevent accidental use with protected data. Group 4 Networks assesses AI tools against these criteria as part of the AI Governance engagement.
How quickly can a shadow AI audit identify unapproved tools in a healthcare clinic?
Group 4 Networks completes the initial Shadow AI Audit for a healthcare organization within five business days. The audit uses network traffic analysis, Microsoft 365 activity review, and staff interviews to identify every AI tool in active use. Most multi-site healthcare organizations discover between four and eight unapproved tools - the majority introduced by administrative staff without IT involvement.
Can Microsoft 365 Copilot be used in a PHIPA-compliant healthcare environment?
Microsoft 365 Copilot operates within the Microsoft 365 trust boundary, with data processed in Canadian data centres for Canadian tenants. Copilot does not use customer data to train the underlying models. For healthcare organizations, the key question is what data Copilot can access within the Microsoft 365 tenant. With appropriate sensitivity labels, data classification controls, and access restrictions, Copilot can be used for administrative work that does not involve personal health information. Any use of Copilot with clinical data requires additional PHIPA review specific to the organization's configuration.
What does an AI governance program cost for a small healthcare clinic?
Group 4 Networks prices AI Governance as a managed service with an initial implementation phase and ongoing monthly monitoring. Pricing is based on organization size and scope of the environment. For healthcare organizations already on a Group 4 Networks managed IT engagement, AI Governance is available as an add-on to the existing service. Contact us at (416) 623-9677 for a quote specific to your clinic's size and locations.