
PHIPA and CRPO therapist consent form template
Updated
PHIPA says you need consent. CRPO says you need informed consent specific to electronic communication. They are not the same thing.
A consent form that satisfies PHIPA s.18 can still fall short of what CRPO Standard 3.4 expects. The reverse is also true. If you copy a generic intake consent off a US template site and assume it covers Ontario, you have a form that satisfies neither.
This guide walks through what each set of rules requires, where they overlap, where CRPO adds to PHIPA, and how to build a consent form that satisfies both. It follows the structure of Curio’s PHIPA and CRPO consent form template field by field, so you can map every section back to the obligation it covers.
You are a registered psychotherapist. You already know the basics of PHIPA email requirements and you have read about CRPO electronic practice standards. This piece is the bridge: how the two combine on the page a client actually signs.
PHIPA consent requirements for email (s.18)
PHIPA s.18 governs consent for the collection, use, and disclosure of personal health information by a health information custodian. Under s.18(1), four things have to be true for the consent to count: it must be the individual’s consent, it must be knowledgeable, it must relate to the information, and it must not be obtained through deception or coercion. Capacity to consent is a separate question, governed by ss.21 to 23 rather than s.18.
“Knowledgeable” is the word that does most of the work. Under PHIPA s.18(5), a consent is knowledgeable if the individual knows the purpose of the collection, use, or disclosure, and knows that they can give or withhold consent. The custodian is presumed to be entitled to assume consent for the purpose of providing health care unless the circumstances suggest otherwise.
For email, this means a client cannot meaningfully consent without understanding what kind of information will be sent, why it will be sent, and that they have a real choice. A signed sentence that says “I consent to receive emails” does not meet the standard. The form needs to put enough information in front of the client that consent reflects an actual decision.
PHIPA does not require a written form. Consent can be express or implied, and express consent can be verbal or written. In practice, you want a written record. If a complaint goes to the Information and Privacy Commissioner of Ontario (IPC), the file you can hand over is the file that protects you.
A few things PHIPA s.18 does not require, which therapists often add anyway because CRPO does require them:
- Channel by channel consent (email versus text versus video, each handled separately)
- Disclosure of specific risks tied to each channel
- A documented alternative to electronic communication
- A documented withdrawal process
PHIPA leaves these to professional judgment. CRPO does not. For a deeper read on PHIPA’s consent framework on its own, see PHIPA consent requirements for email.
CRPO Standard 3.4 consent requirements
CRPO Standard 3.4 is the College of Registered Psychotherapists of Ontario’s electronic practice standard. It applies to telephone, text, email, and video calling when used to provide assessment or treatment. It is not a privacy law. It is a college practice standard, which means non compliance is a registration matter, not a regulatory enforcement one.
Standard 3.4 layers on top of PHIPA. It requires registrants to obtain informed consent for the use of electronic communication media. The CRPO Electronic Practice Guideline elaborates on what this means in practice. The informed part is the same idea as PHIPA’s knowledgeable consent, but the scope is different. PHIPA focuses on the PHI itself. CRPO focuses on the channel that carries it.
Standard 3.4.2 requires informed consent for the use of electronic media, and the CRPO Electronic Practice Guideline sets out what that consent should cover: the platform or channel proposed, its risks, benefits and limitations, what to do if the technology fails or a crisis arises, the confidentiality measures in place and their limits, steps the client can take to protect their own information, the practice’s policies, hours and response times, and a note on CRPO oversight. In a consent form, the elements that do most of the work are:
- Which electronic channels you propose to use
- The specific risks of each channel (interception, forwarding, misdirected messages, device access)
- The limitations of confidentiality through each channel
Two more elements round out a complete form. Both come from general consent law and CRPO Standard 3.2 Consent rather than from Standard 3.4 itself:
- The alternatives available if the client does not want to use electronic communication
- The client’s right to withdraw consent at any time (Standard 3.2)
Notice how channel specific the electronic practice standard is. A client who consents to email is not assumed to have consented to text or to video. Each channel is its own decision.
CRPO also expects competency. Standard 3.4 requires registrants to maintain competency in the technologies they use. A consent form that promises encryption you cannot actually deliver is a competency problem, not just a paperwork one. For the full breakdown of the standard, see the CRPO electronic practice standards guide.
Where PHIPA and CRPO overlap and diverge
Both PHIPA s.18 and CRPO Standard 3.4 require informed consent. Both expect the client to understand what they are agreeing to. Both require the consent to be voluntary. Where they part ways is in the scope and the specificity.
| Element | PHIPA s.18 | CRPO Standard 3.4 |
|---|---|---|
| What consent covers | Collection, use, and disclosure of PHI | The use of electronic communication channels for therapy |
| Capacity requirement | Yes (client must be capable) | Implicit, follows from PHIPA |
| Knowledgeable / informed | Yes (client must know purpose and that consent can be withheld) | Yes (client must understand the channel and its risks) |
| Voluntary | Yes | Yes |
| Channel by channel consent | Not required | Required |
| Specific channel risks disclosed | Not required | Required |
| Alternatives presented | Not required | Required |
| Withdrawal process documented | Not required | Required |
| Competency to use the technology | Not addressed | Required |
| Form of consent | Express or implied; written or verbal | Express; written record expected in practice |
A form that satisfies only PHIPA may miss the channel by channel structure, the explicit risk disclosure, the alternatives, and the withdrawal process. A form that satisfies only CRPO may have all of that but never identify you as the health information custodian or describe what PHI is being collected. You need both. The template that follows is built to cover both in a single document.
Building your consent form, field by field
This section walks through each field of the PHIPA and CRPO consent form template. Each field is annotated with the rule it satisfies, so you can defend any element if a complaint, an audit, or a registrant inquiry asks why it is there.
Field 1: Therapist identification and registration
Open the form with your name, CRPO registration number, practice name, address, phone, and email. PHIPA s.18(1) requires consent to be knowledgeable, which means the client must understand who is collecting their PHI and why. If the client cannot tell from the form who is collecting it, the consent is not knowledgeable.
The CRPO registration number is the part most generic templates miss. Including it identifies you as a regulated practitioner, which signals to the client that an oversight body exists if something goes wrong. CRPO does not formally require the number on a consent form, but registrants are expected to be identifiable.
Field 2: Description of electronic communication methods used
List every channel you propose to use, with the specific address or tool name for each. Email at this address. Text to this number. Video calling through this service. Secure portal at this address. This is the field that earns the CRPO Standard 3.4 box.
A blanket “electronic communication” checkbox is not enough. CRPO’s informed consent requirement applies to each channel. If you use both email and text, the client needs to consent to each separately. The template uses a small table where the client initials beside each channel they accept.
Field 3: What personal health information will be transmitted
State what kinds of content may appear through email versus what stays in session or in the clinical record. Appointment scheduling is one thing. Session notes are another. Crisis communication is a third (and should generally be excluded).
PHIPA s.18(5) says consent must be knowledgeable, which means the client must understand the purpose of the collection, use, or disclosure. Listing the kinds of content email may carry makes that purpose specific. A reasonable client signing the form should be able to predict what will land in their inbox.
Field 4: How PHI will be protected
Describe your encryption setup, what it covers, and what it does not. Specificity matters here. “Encrypted email” is too vague to be useful. “Outbound email is encrypted for PHIPA and logged in a Canadian audit trail” is specific and verifiable.
This is also where you should be honest about limitations. Most encryption layers do not protect email content once it lands on the client’s device. Most do not encrypt metadata. Most do not control what happens if the client forwards the message. The client needs to know the boundaries of the safeguard before they can consent knowledgeably.
If you use a service that provides Canadian hosted compliance infrastructure (audit trail in Montreal, for example), name it. Verifiable claims build trust in a way that generic reassurance does not.
Field 5: Specific risks of electronic communication
CRPO Standard 3.4 requires risk disclosure that goes beyond “email may not be secure.” The template covers five risk categories:
- Interception during transmission
- Forwarding to unintended recipients
- Device access (anyone who can unlock the client’s phone can read the messages)
- Metadata visibility (who you emailed, when, and the subject line)
- Server location and offshore data storage
The fifth risk is the one therapists most often skip. Gmail and Outlook route message content through US servers as part of normal email delivery. That is true even when the compliance infrastructure (audit trail, encryption gateway) is Canadian hosted. Clients should know.
Field 6: Limitations of electronic communication
Email is not for crisis. Email is not a substitute for clinical sessions. Email responses may be delayed by hours or days. These are limitations that the client needs to understand before they form expectations the channel cannot meet.
If a client is in acute crisis, electronic communication is the wrong tool. The consent form should state this explicitly and direct the client to crisis resources. (The 9-8-8 Suicide Crisis Helpline is reachable by call or text 988. It replaced Talk Suicide Canada’s 1-833-456-4566 and text 45645 line in November 2023.)
Field 7: Alternatives to electronic communication
List the alternatives clients can choose instead: in person sessions, telephone, secure portal, postal mail. State that declining electronic communication will not affect the quality of care or the therapeutic relationship.
This field exists because CRPO Standard 3.4 requires the informed consent to be voluntary. Voluntary consent presumes a real alternative. If the only way to communicate between sessions is email, the consent is not really voluntary.
Field 8: Client acknowledgment and signature
Use a checkbox structure for the acknowledgment. The client confirms they have read the form, understood the risks in Field 5, understood the safeguards in Field 4, reviewed the alternatives in Field 7, and are consenting voluntarily.
Then signature, date, therapist counter signature, therapist date. Keep a signed copy in the clinical record. Give the client a copy. This is the document you hand to the IPC or to CRPO if a complaint arrives.
Field 9: Revocation process
Explain how the client can withdraw consent. The template suggests “in writing (email, letter, or secure message)” with a stated business day window for the channel to be discontinued. Withdrawal is not retroactive: emails already sent remain in the clinical record.
CRPO Standard 3.2 Consent requires the client to be informed of their right to withdraw consent at any time. Documenting the mechanism removes ambiguity later. If a client withdraws and you keep emailing, the consent on file does not protect you.
The template
The full PHIPA and CRPO consent form template is available as a standalone resource. It is annotated section by section with the PHIPA or CRPO reference that justifies each field, so you can adapt the form for your practice without losing the regulatory anchors.
A few things to change when you customize it:
- Practice details (name, address, phone, email, registration number)
- Encryption description in Field 4 (use the actual service and details for your setup)
- Business day window for withdrawal in Field 9 (most practices use 1 to 5 business days)
- Channel list in Field 2 (remove channels you do not use)
A few things to keep:
- The annotated bracketed references (
[PHIPA s.18],[CRPO 3.4]). These help future you, an auditor, or a successor practitioner trace the reasoning. - The risk language in Field 5. The wording maps to CRPO Standard 3.4’s specific expectations.
- The acknowledgment checkbox structure in Field 8. A signed paragraph is weaker evidence of knowledgeable consent than discrete confirmations.
This template is a starting point. It is not legal advice. Before adopting it, have it reviewed by a privacy lawyer, your professional liability insurer, or your regulatory body if you have any uncertainty about the wording.
For broader documentation that supports the consent form (email policies, disclaimers, intake addenda), see the client communication templates collection. For the client record access process that often follows from email communication, see the client record access request guide.
Pan-Canadian note: HIA, BC PIPA, and the cross provincial picture
The template is built for Ontario. If you practise outside Ontario, the principles carry over but the specific requirements differ.
Alberta (HIA + CAP). Alberta’s Health Information Act has its own consent framework. The College of Alberta Psychologists publishes practice standards that address electronic communication. The core principles (knowledgeable, voluntary, informed) are similar, but the section numbers and the regulatory body expectations differ. For the Alberta breakdown, see HIA email requirements for Alberta therapists and CAP practice standards for Alberta.
British Columbia (BC PIPA + CHCPBC). BC’s Personal Information Protection Act covers private sector data handling, including private therapy practice. Consent under BC PIPA is generally implied for the purposes of providing the service, but explicit consent is the safer choice for electronic communication. The College of Health and Care Professionals of BC begins regulating psychotherapy on November 29, 2027. Until then, the framework is BC PIPA plus your existing professional college’s standards. See BC PIPA email privacy for therapists and CHCPBC regulation 2027.
Multi province practice. If you see clients in more than one province, the consent form needs to handle multiple regulatory bodies. The simplest approach is a base consent that meets Ontario’s higher specificity bar (PHIPA + CRPO), with a cross provincial consent addendum that captures province specific elements. This is how the template adapts when your client base spans Ontario, Alberta, and BC.
For a side by side of how the three regimes compare on this and other questions, see comparing college requirements across Canada.
What this guide does not cover
Consent is one piece of the email setup. Encryption is another. Documentation is a third. This guide covered the consent form. It did not cover:
- How to implement the encryption that the consent form describes
- How to set up an audit trail that meets CRPO Standard 3.4’s documentation requirements
- What to do when a client revokes consent mid treatment
- How consent interacts with substitute decision makers under PHIPA Part III
For the encryption and audit trail piece: every outbound email is encrypted automatically and logged in a Canadian audit trail, with compliance infrastructure hosted in Montreal. The documentation a regulator would ask for already exists in the audit trail. Join the Curio waitlist.
Curio encrypts every outbound email and logs every send in a Canadian audit trail. The safeguards your consent form names are the safeguards on the wire. Join the waitlist.
This template and guide are for informational purposes only and do not constitute legal advice. Privacy regulations and college practice standards vary by province and are subject to change. Verify current requirements with your provincial regulatory body and consult a qualified privacy professional for your specific situation.
Coming soon
Gmail encryption, built for Canadian therapists.



