Health Management System Billing (OHIP/Alberta)
Canadian provincial requirements for health management system billing auditing. Requires correlation of billing codes with clinical access records to prevent fraud.
What HMS OHIP draws on
This framework pulls on 2 pillars of the platform.
Compliance
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Audit Trail
Organizations MUST maintain audit logs of access to personal health information.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Billing Verification
REQUIRES auditing of billing codes versus clinical access records for fraud prevention.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Access Controls
Organizations MUST implement technical safeguards to protect health information.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Correlation Analysis
Systems MUST enable correlation of billing submissions with clinical record access patterns.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
What HMS OHIP covers
Ontario PHIPA, s. 4 — personal health information
Identifying information about an individual relating to their physical or mental health, or to the provision of health care.
In scope
- Physical or mental health information, including family health history
- Health care provided to the individual
- Payments and eligibility for health care
- The health number
- Substitute decision-maker details
What falls outside
Information that has had identifiers removed such that it is not reasonably foreseeable it could identify the individual.
This entry is modelled on Ontario. Every province has its own health privacy statute and its own billing regime — Alberta runs HIA, British Columbia runs FIPPA and PIPA — so the definition and the obligations both change with the province you actually bill.
Information and Privacy Commissioner of Ontario · as at 2026-08
How HMS OHIP is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The provincial health ministry and, for personal health information, the Information and Privacy Commissioner of Ontario.
Billing integrity and health information privacy are two different exposures that arrive together. The ministry can audit, recover payments, and refer billing conduct for prosecution; the personal health information in the same systems is governed by provincial health privacy legislation with its own offence provisions and prosecutions.
The applicable statute is provincial, so Ontario and Alberta differ in both the obligations and the amounts.
Uncapped exposure that sits outside this instrument
These come from company law rather than from HMS OHIP, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Directors’ duty of care
Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.
Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.
Who. Directors and officers personally.
The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.
Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for HMS OHIP,
not configured for it afterwards
Healthcare Billing Audit
Correlate billing codes with clinical database access
HMS Billing Audit Report
10-year audit window for billing fraud detection
Canadian Healthcare Patterns
Identify OHIP, Alberta Health, and provincial billing codes
Billing Anomaly Detection
Alert on billing patterns inconsistent with access records
Other Industrial frameworks
Walk into the HMS OHIP audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.