HMS OHIPIndustrialCanadaHealthcare Billing

Health Management System Billing (OHIP/Alberta)

Canadian provincial requirements for health management system billing auditing. Requires correlation of billing codes with clinical access records to prevent fraud.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

HMS OHIPPHIPA Section 12A record of access

Audit Trail

Organizations MUST maintain audit logs of access to personal health information.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

HMS OHIPHIA Section 60A record of access

Billing Verification

REQUIRES auditing of billing codes versus clinical access records for fraud prevention.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

HMS OHIPPHIPA Section 10Patching, hardening, and exposureA record of access

Access Controls

Organizations MUST implement technical safeguards to protect health information.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

HMS OHIPBilling Audit RequirementsA record of access

Correlation Analysis

Systems MUST enable correlation of billing submissions with clinical record access patterns.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What HMS OHIP covers

Ontario PHIPA, s. 4 — personal health information

Identifying information about an individual relating to their physical or mental health, or to the provision of health care.

In scope

  • Physical or mental health information, including family health history
  • Health care provided to the individual
  • Payments and eligibility for health care
  • The health number
  • Substitute decision-maker details

What falls outside

Information that has had identifiers removed such that it is not reasonably foreseeable it could identify the individual.

This entry is modelled on Ontario. Every province has its own health privacy statute and its own billing regime — Alberta runs HIA, British Columbia runs FIPPA and PIPA — so the definition and the obligations both change with the province you actually bill.

Information and Privacy Commissioner of Ontario · as at 2026-08

How HMS OHIP is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The provincial health ministry and, for personal health information, the Information and Privacy Commissioner of Ontario.

Billing integrity and health information privacy are two different exposures that arrive together. The ministry can audit, recover payments, and refer billing conduct for prosecution; the personal health information in the same systems is governed by provincial health privacy legislation with its own offence provisions and prosecutions.

The applicable statute is provincial, so Ontario and Alberta differ in both the obligations and the amounts.

Uncapped exposure that sits outside this instrument

These come from company law rather than from HMS OHIP, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Directors’ duty of care

Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.

Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.

Who. Directors and officers personally.

The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.

Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for HMS OHIP,
not configured for it afterwards

Policy Template

Healthcare Billing Audit

Correlate billing codes with clinical database access

Report

HMS Billing Audit Report

10-year audit window for billing fraud detection

Classification

Canadian Healthcare Patterns

Identify OHIP, Alberta Health, and provincial billing codes

Alert

Billing Anomaly Detection

Alert on billing patterns inconsistent with access records

Walk into the HMS OHIP audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment