The tooling a Canadian health information custodian needs to prove who accessed what, when, and under whose authority.
Contact Us
Most health-privacy content online is written for American hospitals. It talks about HIPAA, covered entities, and ePHI. None of that is your legal framework.
In Canada you answer to provincial health privacy legislation. In Ontario that's PHIPA, the Personal Health Information Protection Act. Manitoba, Nova Scotia, and Newfoundland and Labrador each have their own Personal Health Information Acts. Alberta has the Health Information Act. The obligations differ act to act, but they all define a health information custodian and place similar duties on that role around access, retention, revocation, and breach reporting.
Optrics has been Canada's authorized ManageEngine reseller since 2010. We sell and support into Canada only, so the deployments we've built are Canadian deployments under Canadian rules. If you're looking at the broader IT picture for a hospital, clinic, or health authority, see our healthcare industry page.
Talk to Optrics
The term is defined differently in each provincial act, but the pattern is consistent: it's the organization or professional that has legal responsibility for a patient's personal health information. In Ontario, PHIPA's definition covers hospitals, long-term care homes, community care access centres, regulated health professionals, and pharmacies, among others. Similar definitions apply elsewhere.
Hospitals, clinics, physician practices, long-term care homes, community health centres, and mental health services generally sit inside the custodian definition.
Vendors, cloud hosts, and shared-services organizations aren't custodians themselves, but they operate under contract with one, and the custodian's obligations flow to them through those contracts.
Privacy legislation doesn't ask whether you have a policy. It asks whether you can produce evidence. Four IT capabilities determine whether the answer is "yes, here it is" or "we'll have to get back to you."
Who opened this patient's chart, when, and from where. Not just the login trail into the EMR, but the file-level and folder-level access on the underlying record store.
Logs that have already rolled off a server are the same as no logs. Retention windows matter as much as capture, and they matter for longer than most default settings assume.
Who authorized this person's access, when, and when was it revoked. Clinical staff rotate constantly, and standing accounts that outlived a placement are the most common source of quiet privacy risk.
How long does it take you to answer "did this account touch this record last month"? Breach investigations move on days, not weeks.
Each capability below is delivered by a specific ManageEngine product. Follow the links for how each one works in detail.
File and folder auditing across your record stores, with reports formatted for a privacy officer rather than a sysadmin.
Products: ADAudit Plus, DataSecurity Plus
Cross-system log collection with retention that outlasts a breach investigation window, and immutable storage so the trail can't quietly disappear.
Products: EventLog Analyzer, Log360
Account lifecycle tied to your HR process, with an audit trail of every permission grant and revocation.
Product: ADManager Plus
Behavioural analytics on user activity to surface off-hours access, cross-department snooping, and other patterns that a rules-only alerting model tends to miss.
Product: Log360
Self-service password reset from the login screen, so a clinician at shift change doesn't need a help desk ticket or a colleague's credentials.
Product: ADSelfService Plus
Patch clinical endpoints on schedules that respect maintenance windows, enforce configuration standards, and see the unmanaged devices on your network.
Products: Endpoint Central, OpManager
No software product makes an organization PHIPA compliant on its own. Compliance is a combination of legal policy, documented processes, staff training, and technical controls. ManageEngine covers the technical-controls layer well: access logging, retention, provisioning trails, and breach investigation evidence. Optrics can help you map what you already have to what PHIPA asks of a custodian, and identify the gaps.
PHIPA specifically is Ontario legislation. Manitoba, Nova Scotia, and Newfoundland and Labrador each have their own Personal Health Information Acts, and Alberta has the Health Information Act. The obligations are similar but the specifics differ, so the answer to "what am I responsible for" depends on the province your organization operates in. The IT capabilities that support the obligations are the same across provinces.
Yes to both. Every ManageEngine product referenced on this page has an on-premises edition that runs on your own servers in Canada. Cloud editions are also available, and where relevant we can point you at the ManageEngine Canada Cloud region for hosted deployments. Data residency is a routine buying question for Canadian health data, and Optrics can walk through the deployment options against your specific requirements.
Shared clinical workstations are the norm on wards and in clinics, and they break the "the account did it" assumption that ordinary corporate IT relies on. Endpoint Central handles the workstation itself: patching around shift schedules, enforcing configuration standards, and inventorying what's actually running. Identity attribution during a shift happens at the login layer through Active Directory, which is where ADAudit Plus and ADManager Plus become the accountability backbone.
Both. As Canada's authorized ManageEngine reseller since 2010, Optrics handles licensing (quoted in CAD, delivered on a Canadian invoice) and can also handle implementation, configuration, training, and ongoing support. If you have an internal IT team that wants to own the deployment, we can just quote the licences. If you'd rather we drive the implementation, our Edmonton-based technical team does that too.
Real-time auditing of Active Directory and file-server access, with reports built for privacy officers.
File auditing, data discovery, and DLP for personal health information across your record stores.
Centralized log collection and retention for the trail that supports breach investigations.
Unified SIEM with behavioural analytics to surface anomalous access patterns.
Provisioning and deprovisioning workflows with a full audit trail of permission changes.
Self-service password reset so clinicians at shift change don't share credentials.
Our Edmonton-based team quotes in CAD, supports on Canadian time zones, and has spent 15 years deploying ManageEngine into Canadian environments.