You're using an outdated browser. This website will not display correctly and some features will not work.
Learn more about the browsers we support for a faster and safer online experience.

Important: This version of the e-Laws website will be upgraded to a new version in the coming weeks.
You can try the beta version of the new e-Laws at ontario.ca/laws-beta.

Français

ontario regulation 343/23

made under the

Personal Health Information Protection Act, 2004

Made: November 9, 2023
Filed: November 14, 2023
Published on e-Laws: November 14, 2023
Published in The Ontario Gazette: December 2, 2023

Amending O. Reg. 329/04

(GENERAL)

1. Ontario Regulation 329/04 is amended by adding the following section:

Determination of amount of administrative penalty

35. (1) For the purpose of clause 61.1 (2) (b) of the Act, the amount of an administrative penalty determined by the Commissioner for any number of contraventions of the Act or its regulations set out in an order under clause 61 (1) (h.1) of the Act shall not exceed the following:

1.  If the person required to pay the administrative penalty is a natural person, $50,000.

2.  If the person required to pay the administrative penalty is not a natural person, $500,000.

(2) Despite subsection (1), the Commissioner may increase the amount of an administrative penalty that a person is required to pay by an amount equal to the economic benefit acquired by, or that accrued to, the person as a result of the contraventions.

(3) In determining the amount of an administrative penalty, the Commissioner shall consider the following criteria, and may consider any other criteria that the Commissioner considers relevant:

1.  The extent to which the contraventions deviate from the requirements of the Act or its regulations.

2.  The extent to which the person could have taken steps to prevent the contraventions.

3.  The extent of the harm or potential harm to others resulting from the contraventions.

4.  The extent to which the person tried to mitigate any harm or potential harm or took any other remedial action.

5.  The number of individuals, health information custodians and other persons affected by the contraventions.

6.  Whether the person notified the Commissioner and any individuals whose personal health information was affected by the contraventions.

7.  The extent to which the person derived or reasonably might have expected to derive, directly or indirectly, any economic benefit from the contraventions.

8.  Whether the person has previously contravened the Act or its regulations.

Commencement

2. This Regulation comes into force on the later of January 1, 2024 and the day this Regulation is filed.

 

Français