Guidelines›Security›Canada

Canada · PIPEDA · PHIPA · HIA · PHIA · Québec Law 25 and Law 5 · provincial colleges

Canada has no HIPAA. It has one federal law, a provincial health statute where you practise, and a college on top of both.

Nobody in Canadian health care is regulated by a single Act. A psychotherapy practice in Toronto answers to PHIPA and the Information and Privacy Commissioner of Ontario. The same practice in Calgary answers to Alberta's HIA. In Vancouver it is PIPA and the OIPC. In Montréal it is Law 25 and Law 5, in French. And in every one of those places, the professional college adds record-keeping rules that the privacy statute never mentions.

This page goes through what applies, in ordinary words, and says for each obligation which part the software already does, which part is a number you set, and which part is missing and why. The section about what we cannot do is not in small type at the bottom — it is section 09, and in Canada it decides most deals before privacy is ever discussed.

Clinic owners and practice leads Practice managers Privacy officers and contact persons Group, virtual-care and EAP operators
10+3provinces and territories 4health statutes deemed substantially similar 30 daysto answer an access request 24 monthsof breach records under PIPEDA 0provincial claims we can lodge
01 — Orientation

Four rulebooks, and the one that binds you depends on your postal code

The single most common mistake in a Canadian software conversation is to ask "are you HIPAA-compliant?" HIPAA is American law and does not apply to a Canadian clinic at all. What applies is a stack, and the top of the stack changes when you cross a provincial boundary.

Federal · PIPEDA

The default, and the floor

The Personal Information Protection and Electronic Documents Act governs personal information collected in the course of commercial activity, and it carries ten fair information principles in its Schedule 1 — accountability, purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

The part people get wrong: PIPEDA applies unless a provincial law has been declared substantially similar for that activity. It is a fallback, not an exemption — in a province without its own health statute, PIPEDA is the whole rulebook. Section 03.

Provincial health statutes

The rulebook that usually actually governs you

Ontario's PHIPA, Alberta's HIA, Saskatchewan's HIPA, Manitoba's PHIA, New Brunswick's PHIPAA, Nova Scotia's and Newfoundland & Labrador's PHIA, Prince Edward Island's HIA. These are not privacy laws with a health chapter — they are health-information laws, written around a defined custodian.

Why it matters: they carry duties PIPEDA does not have at all — the circle of care, the lockbox, the duty to log every access to an electronic record, and a report to the provincial commissioner. Section 04.

Professional colleges

Record keeping, and it is not in the statute

How long you keep a chart, what has to be in it, and what happens when you close a practice are set by your college — the CPSO, the CPSA, the CPSBC, the CRPO, the provincial college of psychologists, of social workers, of nurses. They differ by province and by profession.

Why it matters: the retention period in your contract is almost never a number from the privacy Act. BC sits at 16 years from the last entry; Alberta at 10. Both are computed dates, not typed ones. Section 06.

The provincial billing rail

OHIP, MSP, AHCIP, and the rest

Insured services are billed to a provincial plan — OHIP in Ontario, MSP through Teleplan in British Columbia, AHCIP in Alberta — each with its own submission format, its own vendor conformance process and its own reconciliation cycle.

Why it matters: we are not on any of it. That is a boundary, not a backlog, and section 09 says exactly where it hurts and where it does not.

The short version, for somebody deciding whether to read on

If you run a private-pay, extended-health, EAP, employer-funded or virtual-care practice — psychotherapy, counselling, psychology, most allied health — every obligation on this page is one we can meet or exceed, and the privacy argument is unusually strong here because the software runs on your own infrastructure, so the cross-border question never arises. If billing an insured service to a provincial plan is your revenue model, read section 09 first: we cannot lodge that claim, and no amount of privacy architecture changes it.

02 — The map

Which statute, and which commissioner, by where you practise

Read your own row and ignore the rest. The right-hand column is the office that would receive a complaint about you, and — in most of these provinces — a breach report.

Two things this table deliberately does not do. It does not tell you whether your particular practice is a "custodian" or a "trustee" under your statute; that turns on your profession and how you are organised, and it is a question for counsel. And it does not list your college, because the college depends on your profession rather than your province.

Where you practiseThe health-information statuteWho oversees it
OntarioPersonal Health Information Protection Act, 2004 (PHIPA), with O. Reg. 329/04Information and Privacy Commissioner of Ontario
AlbertaHealth Information Act (HIA); Alberta PIPA for the private-sector remainderOffice of the Information and Privacy Commissioner of Alberta
British ColumbiaNo separate health statute for the private sector — Personal Information Protection Act (PIPA)Office of the Information and Privacy Commissioner for BC
SaskatchewanHealth Information Protection Act (HIPA)Saskatchewan Information and Privacy Commissioner
ManitobaPersonal Health Information Act (PHIA)Manitoba Ombudsman
QuébecLaw 25 (private sector), and Law 5 — the Act respecting health and social services informationCommission d'accès à l'information
New BrunswickPersonal Health Information Privacy and Access Act (PHIPAA)NB Ombud / Access to Information and Privacy Commissioner
Nova ScotiaPersonal Health Information Act (PHIA)Office of the Information and Privacy Commissioner for Nova Scotia
Newfoundland and LabradorPersonal Health Information Act (PHIA)Office of the Information and Privacy Commissioner
Prince Edward IslandHealth Information Act (HIA)PEI Information and Privacy Commissioner
Yukon, NWT, NunavutTerritorial health information legislation where enacted; PIPEDA for commercial activity otherwiseTerritorial commissioner and/or the OPC
Anywhere, for data crossing a borderPIPEDA governs personal information moving between provinces or out of Canada in the course of commercial activityOffice of the Privacy Commissioner of Canada
"Substantially similar" is a narrower word than it sounds

The federal government has declared a handful of provincial health statutes substantially similar to PIPEDA for health information held by custodians — Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador — and Québec, British Columbia and Alberta's general private-sector laws for commercial activity generally. Alberta's HIA is not on that list, which does not make it weaker; it makes the interaction between HIA and PIPEDA a question worth putting to counsel rather than assuming.

What it means practically: PIPEDA never stops mattering. Even in Ontario, the moment information moves across a provincial boundary or out of the country in the course of commercial activity, the federal law is in play alongside the provincial one.

03 — PIPEDA

The ten principles, and what the software does about each one

Schedule 1 of PIPEDA is the Canadian Standards Association model code, written as ten principles. They are obligations on your organisation, not on your software — but eight of the ten are obligations a system either supports or quietly makes impossible.

Read the status column, not just the mark. One of these is an honest partial and four are "the mechanism is ours, the wording is yours". They are marked as such.

✓BuiltIn the platform now, and demonstrable on a live system. ⚙Built — you set the valueThe mechanism exists; the number, the wording or the policy is yours. Not a shortfall. ◐Partly builtSomething is genuinely missing. The right-hand column says exactly what. §The principle asks for lessNothing is missing. The obligation is organisational, or the law reaches the same place another way. ✗Not builtAbsent, and not a configuration away. Section 09 is where these are.
PrincipleStatusWhat it asks, and what happens here
1 · Accountability ⚙ An organisation is responsible for information under its control and must designate someone accountable for compliance. The designation register is built — named roles carry named people and effective dates, and the record does not quietly change hands. Who you designate is yours. The register also holds the agreements with anyone who processes information on your behalf, which is the same evidence a commissioner asks for after an incident.
2 · Identifying purposes ⚙ Purposes must be identified at or before collection. Purpose is a stored field on every disclosure, not a free-text note, so "why did this leave the practice" is answerable per document rather than reconstructed. The words you use at collection are yours, and they belong in the policy register.
3 · Consent ◐ Knowledge and consent are required for collection, use and disclosure, except where the Act allows otherwise. Consent as a basis for disclosure is built — a disclosure records its basis, and where the basis is consent it carries the reference to the authorisation. What is missing is the withdrawal side as a first-class object: a patient instruction that restricts a specific record from a specific use, standing on the record itself and enforced at read time. That is the lockbox, and it is section 05.
4 · Limiting collection § Collect only what is necessary. No software can limit what a clinician chooses to ask, and a system that claimed to would be overselling. What the platform does do is make the forms yours to define, so the shortest version of a form is a configuration rather than a code change.
5 · Limiting use, disclosure and retention ✓ This is the principle the architecture was built around. Access follows the treatment relationship: a clinical document is readable by someone with a current care relationship to that patient, and the relationship carries a start date, an end date and a grace period, so access ends on its own rather than when somebody remembers to remove it. Every disclosure is a record with a recipient, a purpose and a basis. Retention is an engine, not a folder convention — section 06.
6 · Accuracy ✓ Information must be as accurate, complete and up to date as is necessary. Correction is a first-class request with an owner and a clock, and a corrected document keeps its earlier version rather than overwriting it — which is what lets you show what was corrected and when, not merely that it is right now.
7 · Safeguards ✓ Security appropriate to the sensitivity of the information. Clinical documents are encrypted with a per-version data key wrapped under a key that is not in the database; every read is logged into an append-only, hash-chained trail so a deleted or edited log entry breaks the chain and is visible; emergency access is a deliberate break-glass action that files its own record. The risk analysis, workforce training and sanctions registers a commissioner asks about after an incident are part of the same system rather than a binder.
8 · Openness ⚙ Policies and practices must be readily available. The policy register is built: policies are versioned, each version keeps its own effective dates, and superseded versions are not overwritten — so you can answer "what was our practice in March last year", which is the form the question actually takes. The text is yours.
9 · Individual access ✓ On request, an individual must be told of the existence, use and disclosure of their information and be given access, generally within 30 days. Access requests are first-class records with a statutory due date computed from the request, an extension that is recorded separately so the file shows how much time the extension actually bought, and a form-and-format field. The accounting of disclosures is generated from the disclosure register rather than assembled by hand.
10 · Challenging compliance ✓ An individual must be able to challenge compliance with the person accountable. Privacy complaints are a first-class record with an owner, a clock and a recorded outcome — not an inbox — and they are retained long enough to answer a pattern question rather than a single incident.
04 — Ontario, in detail

PHIPA, because it is the largest market and the strictest template

Ontario is worth reading even if you do not practise there. PHIPA is the most demanding of the provincial health statutes on the two points software decides — logging every access to an electronic record, and the lockbox — so a system built to satisfy Ontario generally satisfies the others. The vocabulary below is Ontario's; Alberta says affiliate where Ontario says agent, Saskatchewan says trustee where Ontario says custodian, and the shape is the same.

One definition decides your whole obligation set. A health information custodian is the practice. An agent acts for the custodian. An electronic service provider supplies the system without looking at the information — and where that provider lets two or more custodians share information electronically, it becomes a health information network provider, with a specific list of duties in section 6(3) of O. Reg. 329/04.

What PHIPA asksStatusWhat happens here
Custodians, agents and authority ⚙ An agent may only handle information as permitted by the custodian. Access authorisation is an explicit, dated record naming who may do what — so "who was allowed to see this in February" has an answer that does not depend on the current state of the system. Who you appoint is yours.
The circle of care — implied consent for providing health care ✓ PHIPA lets custodians assume implied consent to share for the purpose of providing health care to that patient. This is the exact shape of the care-relationship model: treating, supervising and administrative relationships are separate kinds, each with a start date, an end date and a grace period, and read access is derived from them rather than granted as a role. Membership of the circle is therefore a fact with dates on it, which is what a commissioner asks to see.
The lockbox — express instruction, s. 20(2) and s. 37(1)(a) ◐ Genuinely missing, and the largest gap on this page. A patient can instruct a custodian not to share part of their record within the circle of care. Today that instruction can be recorded as a note and honoured by people; it is not an object on the record that the read path enforces. Section 05 sets out what building it means.
Telling the recipient that something was withheld ◐ Where a lockbox stops a disclosure, the custodian must tell the receiving custodian that it has been prevented from disclosing everything reasonably necessary — so the recipient knows the picture is incomplete. That notice is part of the same missing piece, and it is the half people forget.
s. 10(1) — information practices in place ⚙ A custodian must have information practices that comply with the Act, and a written public statement describing them. The versioned policy register holds them; the words are yours.
s. 12(1) — reasonable steps to protect ✓ Encryption at rest with keys held outside the database, closed-by-default access derived from care relationships, an append-only access log, break-glass as a recorded action rather than a shared password, and a documented risk analysis. Section 03, principle 7.
s. 12(2) — notify the individual at the first reasonable opportunity ✓ The breach record carries the affected individuals, what was involved, whether the data was encrypted, whether keys were compromised, and the notification itself as a step with a date — so the file answers "when did we tell them" rather than "we think we did".
s. 12(3) — report the breach to the Commissioner ◐ Certain breaches must be reported to the IPC. The breach record exists and holds everything the report needs; what is missing is the Ontario trigger list evaluated on the record, and the report itself as a produced artefact. Today it is a person reading the record and filling in the IPC's form. Section 07.
Annual breach statistics to the Commissioner ◐ Custodians track breach statistics by calendar year and report the previous year's numbers to the IPC each March — including breaches that never met the reporting threshold. The underlying records exist and are categorised; the yearly count is not produced for you. It is a small piece of work, and it is the kind that gets forgotten in February — which is the argument for building it rather than remembering it.
s. 52–55 — access and correction ✓ Access within 30 days, extendable; correction with a right to attach a statement of disagreement where the custodian refuses. Both are first-class requests with computed statutory dates, and a refusal has to record its reason rather than simply closing.
O. Reg. 329/04 s. 6(3) — logging, on an electronic record ✓ Records held electronically must keep an electronic record of who accessed what and when. This is the hash-chained access log, and it is the single most useful artefact in a PHIPA investigation: it answers the snooping question — did a staff member look at a patient they had no relationship with — as a query rather than an inference.
Health information network provider duties ◐ If you deploy the platform so that two or more custodians share information through it, section 6(3) adds duties: written agreements, a threat and risk assessment and privacy impact assessment made available to the custodians, a plain-language description of the service, an annual written report on accesses, and prompt notice of breaches. The underlying evidence — the risk analysis, the logs, the breach records — exists. The HINP statement of practices and the annual report do not, as documents. A single-practice deployment does not raise this at all.
Retention, transfer and disposal ⚙ Records must be retained, transferred and disposed of securely. The retention engine computes disposal dates and disposal destroys the key rather than hoping every copy was found; the periods themselves are yours to set, because in Canada they come from your college. Section 06.
05 — The lockbox

The one Canadian concept the architecture does not yet have

Every other jurisdiction page on this site has a section like this. Here is Canada's, and it is worth being precise about, because it is the thing a well-prepared Ontario buyer will ask.

What the law asks

A patient can fence off part of their own record

Under PHIPA a patient may give an express instruction that some of their information not be used or disclosed for providing health care — even inside the circle of care, even to a clinician who would otherwise be entitled to it. Alberta's HIA reaches a similar place through an expressed wish. It is not an opt-out of the record; it is a fence around part of it.

And there is a second duty: when the fence stops a disclosure, the recipient must be told that something has been withheld — not what, but that the picture is incomplete.

What exists today

Everything the fence would attach to

Documents are individually addressable and individually encrypted. Access is already derived at read time from the care relationship rather than granted as a static role. Every read is already logged. Disclosures already carry a basis and a purpose.

Which is the point: the lockbox is not a rebuild. It is a restriction object on the record plus a check in a read path that already exists and is already the only way in.

What building it means

Four pieces, none of them large

A patient instruction with a scope, a date and a recorded channel; enforcement in the document read path, so it binds regardless of who is asking; the withheld-from-disclosure notice as a generated artefact; and the override — because a lockbox yields to a lawful requirement, and an override must file its own record the way break-glass already does.

It belongs in a Canadian pack, alongside the retention schedule and the two breach flows, in the same way that the GDPR, UK and US packs sit on the shared core.

What we will not claim

That a note in a field is a lockbox

Today a practice can record the instruction and honour it by discipline, and many Canadian practices run exactly that way on their current system. That is a real answer, and it is what we would say in a tender.

It is not what we will call it. A control enforced by people is not a control enforced by software, and a buyer who is told otherwise finds out during an IPC review.

06 — Retention

The engine is built; the Canadian numbers are yours, and here is why

In Germany the retention period comes from statute. In the United Kingdom it comes from a national code of practice. In Canada it comes from your professional college, which means it changes with your profession as well as your province — a psychologist, a physician and a registered psychotherapist in the same building can be on three different clocks.

So the platform ships the mechanism and not the numbers, and that is a deliberate choice rather than an omission.

The rule shapeStatusWhat it means, and where Canada uses it
A fixed number of years after filing ✓ The simple case — financial records, consent forms, administrative documents.
Years after the last contact ✓ The common Canadian clinical shape. British Columbia's college of physicians and surgeons sits at 16 years from the last entry; Alberta's at 10 years from the last date the patient was seen. "Last contact" is computed from the care relationships and the activity on the record, not typed by a person at closing time.
Until the patient reaches majority, plus years ✓ The child rule, and the one hand-run schedules get wrong. Canadian colleges commonly extend a minor's record well past the adult period — BC to age 35, Alberta to two years past 18, others to 21. The age of majority is set per rule, not per system, because it differs between provinces (18 or 19) and a group practice may hold records under more than one.
Years after death ✓ Runs from the recorded date of death, and takes precedence where the college rule says the shorter of the two applies.
A Canadian schedule, shipped as data ◐ Not shipped. The UK pack ships the NHS schedule as rows because there is one national schedule to ship. Canada has no single schedule to ship — so today a Canadian deployment enters its own rules, and we would rather say that than pretend a province-and-profession matrix maintained by us is safer than one your privacy officer signed off.
Legal hold ✓ A record under hold does not reach disposal, whatever its rule says, and the hold is itself a dated record with a reason. This matters more in Canada than elsewhere because a college investigation can outlast a retention period.
Disposal that actually disposes ✓ Disposal destroys the key rather than deleting rows and hoping every backup was reached. The document's audit trail survives the document — which is the right way round, because the evidence that you disposed of a record correctly must outlive the record.
What to do at implementation

Bring your college's record-retention standard to the configuration session — not the privacy Act. Every period on this page came from a college or a professional body, and if you hold records for more than one profession you will end up with more than one rule. That is normal, it is supported, and it is far better than a single conservative number that keeps everything for 30 years and turns your record store into a liability.

07 — When something gets out

Two clocks, and they are not the same clock

A Canadian clinic can be under both a federal and a provincial reporting duty for the same incident, with different thresholds, different recipients and different record-keeping. This is where Canadian breach handling is genuinely harder than the American or British equivalents, and it is worth walking a buyer through it deliberately.

Federal · PIPEDA

Real risk of significant harm

A breach of security safeguards must be reported to the Office of the Privacy Commissioner of Canada, and the affected individuals notified, as soon as feasible after you determine it creates a real risk of significant harm. The test turns on the sensitivity of the information and the probability of misuse — and health information is about as sensitive as the assessment gets.

And separately: you must keep a record of every breach of security safeguards for 24 months, whether or not it was reportable, and produce those records to the OPC on request.

Provincial · PHIPA, Ontario

Notify the patient, report to the IPC, count the year

Three separate duties. Notify the affected individual at the first reasonable opportunity. Report to the Information and Privacy Commissioner of Ontario where the breach falls into one of the prescribed circumstances. And track statistics for the calendar year and report the previous year's numbers each March — including breaches that never crossed the reporting threshold.

Other provinces differ. Alberta's HIA carries its own notification duty to the Commissioner and the Minister; several other provinces have their own. Your row in section 02 is the starting point.

What the platform does

One record, and the awkward questions asked up front

A breach is a record from the moment it is discovered, carrying when it happened, when you became aware, who found it, what documents and which individuals were involved, and — the two fields that decide most Canadian assessments — whether the data was encrypted and whether the keys were compromised. Mitigation steps and notifications hang off the same record with their own dates.

Because the access log is append-only and hash-chained, the scope question — what was actually opened — is answered from evidence rather than estimated.

What is missing

The Canadian forms, and the yearly count

The record holds everything both regulators ask for. What it does not do is evaluate the Canadian thresholds for you — the RROSH assessment federally, the prescribed circumstances in Ontario — or produce either filing as an artefact, or count the calendar year for the March report.

Today those are a person reading a complete record and filling in a form. That is workable, and it is materially better than assembling the facts from email. It is still work we should be doing for you, and it belongs in a Canadian pack alongside the lockbox and the retention schedule.

08 — Where the data lives

The question every Canadian buyer asks, and the reason we answer it easily

Canadian health buyers ask about data residency earlier and harder than buyers anywhere else on this site, usually in the first meeting. The honest legal position is more nuanced than the folklore — and the architecture makes the nuance irrelevant.

The beliefWhat is actually the case
"Canadian health data has to stay in Canada." Generally not true as a blanket rule for a private clinic. PIPEDA does not prohibit transfers; it holds you responsible for information you transfer to a processor and requires comparable protection by contract. Most provincial health statutes take a similar approach for private custodians.
"British Columbia requires it." It did, and it changed. The FIPPA requirement for public bodies to store and access personal information only in Canada was repealed in November 2021, replaced by an assessment obligation. FIPPA governs public bodies rather than private clinics in any event.
"Nova Scotia requires it." For public bodies and their service providers, broadly yes — PIIDPA restricts storage and access outside Canada, with a modernised replacement not in force until 2027. If you contract with a public body in Nova Scotia, this is a live constraint on your suppliers, not only on you.
"Québec requires it." Not as a prohibition — but Law 25 requires an assessment before information leaves Québec, and the transfer may only proceed if that assessment shows adequate protection. In practice that is a document you must be able to produce.
"So a cloud product is fine." Legally, often. Commercially, it is still the objection you will spend the meeting on — and with a public-sector or hospital-affiliated buyer it can be decisive regardless of what the statute says.
Why this section is short for us

The platform is deployed on infrastructure you choose, with a separate database per organisation. Put it on a Canadian host, or in your own building, and the cross-border transfer question does not arise: there is no transfer to assess, no processor to contract with, and no vendor holding your patients' records. That is a stronger answer than any hosted competitor in this market can give, and in Canada it is worth leading with.

The corollary is honest too: the security of that deployment is then genuinely yours. Section 14 says what that means in practice.

09 — The boundary

What we cannot do in Canada, said plainly and early

This is the section that decides most Canadian deals, and it belongs here rather than in a footnote. None of it is a backlog item that arrives next quarter. Each one is a national or provincial rail with its own conformance process, and being outside them is a fact about the product today.

The railStatusWhat it is, and who it hurts
Provincial insurance billing — OHIP, MSP/Teleplan, AHCIP and the rest ✗ We cannot submit an insured-service claim to a provincial plan. Each province has its own submission format, its own vendor process and its own remittance and reconciliation cycle. If your revenue is billed to a provincial plan, this is disqualifying and we would rather you knew in the first meeting. If your work is private-pay, extended-health, employer-funded, EAP or third-party — which describes most psychotherapy, counselling and much allied health in Canada — it costs you nothing, because those are invoices and the platform does invoices well.
Provincial EHR viewers and repositories ✗ connectingOntario and OLIS in Ontario, Netcare in Alberta, CareConnect in British Columbia, the provincial systems elsewhere. These are integrations gated by provincial onboarding, identity federation and conformance testing. We are not connected to any of them, so lab results, dispensed-medication history and hospital reports do not flow in.
EMR certification programmes ✗ Ontario's EMR specification and the provincial certification programmes that go with it exist to qualify a product as a primary-care EMR, sometimes with funding attached. We are not certified, and we are not a primary-care EMR. For a physician practice that is decisive; for a psychotherapy or allied-health practice it is usually not even relevant.
E-prescribing ✗ PrescribeIT and the provincial drug information systems. No prescribing, no transmission to a pharmacy, no drug interaction checking. A prescribing practice needs another system for that part of its work.
Pan-Canadian interoperability — CA Core+ / FHIR ◐ The national direction is FHIR-based, with a Canadian baseline profile set. The platform has an API and structured records; it does not implement the Canadian FHIR profiles, and has not been through any conformance testing. Marked partial rather than absent because the gap is profile work on an interface that exists, not a missing interface — but nobody should read that as "supported".
The Canadian jurisdiction pack itself ◐ The shared core carries what every jurisdiction needs, and the GDPR, UK and US packs sit on top of it. There is no Canadian pack yet — so the lockbox (section 05), the retention schedule (section 06), the two breach filings and the annual count (section 07) and the Québec registers (section 10) are configuration and discipline today rather than software. Everything they would attach to already exists.
How to use this section

Two questions decide whether the rest of this page matters. Do you bill a provincial plan for insured services? And do you need lab results and hospital reports to arrive electronically? If both answers are no — and for a great many Canadian mental health, counselling and allied-health practices both answers are no — nothing on this list costs you anything, and the privacy position in section 08 is the strongest available in the market.

10 — Québec

A separate jurisdiction in every sense that matters here

Québec is not "Canada plus French". It has its own privacy statute, its own health-information statute, its own regulator and its own language law, and a Canadian implementation plan that treats it as one more province will fail at the first audit.

Law 25

The private-sector law, and the closest thing Canada has to GDPR

Phased in from 2022 and complete since September 2024. A designated person responsible for privacy. A register of confidentiality incidents. Privacy impact assessments before an information-system project. Granular, purpose-by-purpose consent, with explicit consent for sensitive information — and health information is sensitive by definition. Rights of access, rectification, portability and de-indexing. Penalties that are orders of magnitude above the rest of Canada.

Law 5

The health-information statute, in force since 2024

The Act respecting health and social services information came into force in phases from July 2024 and applies to clinics — including private medical and dental clinics — with obligations that do not simply mirror Law 25. It is designed to protect health data and to make it flow securely within the health system at the same time, which means duties in both directions.

This is the section to put to Québec counsel before quoting a Québec clinic. It is new, its regulations are still settling, and we are not going to summarise it as though it were settled.

What the platform already gives you

More of it than you would expect

The incident register is the breach record. The designated person is the designation register. Access, rectification and the complaint route are first-class requests. Portability has a real answer — the export machinery built for GDPR is jurisdiction-neutral — and so does erasure, because disposal destroys the key rather than deleting a row.

The pieces that are genuinely Québec-shaped are the privacy impact assessment as a record and the transfer assessment before information leaves the province. Neither exists as an object today.

The language obligation

French is not a nice-to-have in Québec

The Charter of the French Language, as amended, requires French in consumer and workplace dealings and a French version of a business's digital presence. For software this reaches the interface your staff and your patients actually use.

Where we stand: the platform runs in French, and the guides on this site have a French edition. What has not been done is a Québec clinical vocabulary review — the difference between correct French and the French a Québec clinician expects to read. Section 11.

11 — Language and accessibility

Two obligations that are not privacy obligations, and get forgotten

ObligationStatusWhat it means here
French, in Québec ⚙ The interface, the patient-facing portal and the documents you send need a French version. The platform is fully translatable and ships French; the templates and clinical wording are yours, and a Québec deployment should budget a vocabulary review rather than assuming the shipped French reads as Québec French.
Bilingual service, outside Québec ⚙ New Brunswick is officially bilingual, and federally funded or federally contracted work carries its own language obligations. The same translation machinery covers it; which languages you enable is a configuration.
AODA — accessible websites, Ontario ◐ Ontario organisations above the small-employer threshold have had to meet WCAG 2.0 Level AA on public websites and web content since January 2021. This reaches your patient portal and booking pages, which are public web content. The platform's portal is built on standard, semantic web components and is in reasonable shape; it has not been formally audited to WCAG 2.0 AA, and we will not claim conformance we have not tested.
Accessible Canada Act § Applies to federally regulated organisations. A private clinic is provincially regulated and generally outside it — but a clinic delivering services under federal contract should check rather than assume.
12 — CASL

The anti-spam law, because appointment reminders live next door to marketing

Canada's Anti-Spam Legislation governs commercial electronic messages, and it is stricter than most clinics expect: consent must be express or fall within a defined implied category, every message must identify the sender and carry a working unsubscribe, and the penalties are substantial.

What CASL asksStatusWhat happens here
Separate a service message from a marketing message ✓ Communication preferences are held per person and per channel, and the transactional path — appointment confirmations, reminders, secure-document notices — is a different path from the marketing one. A patient who unsubscribes from a newsletter still gets told their appointment moved.
Record how consent was obtained ⚙ Consent is stored against the contact with its channel and date. Proving consent is the whole of a CASL defence, so the discipline of capturing it at the point of collection is worth more than any feature.
Identification and unsubscribe in every message ⚙ Templates carry them; the sender details and the wording are yours, and they belong in the same review as your privacy policy.
13 — Where we are stronger

Four things a Canadian buyer should weigh on the other side

Section 09 is deliberately unflattering. This is the other half of the same honesty.

Residency, answered structurally

Nothing leaves, because there is nowhere for it to go

The deployment is yours. There is no vendor tenancy holding Canadian patient records, no cross-border transfer to assess under Law 25, and no processor agreement to negotiate. In a market where this is the first question asked, it is the strongest available answer — and it is architectural rather than contractual.

The snooping question

An access log that answers it as a query

The characteristic Canadian health privacy incident is not a hacker; it is a staff member looking at a record they had no business in. Because access is derived from dated care relationships and every read is written to an append-only, hash-chained trail, "who looked at this patient without a relationship to them" is a query rather than an investigation. Most systems in this market cannot answer it at all.

Disposal you can evidence

Destroying the key, not deleting the row

Secure disposal is a college obligation as much as a privacy one, and the usual failure is a backup nobody reached. Here the record's key is destroyed and the audit trail of the disposal outlives the record — which is the evidence a college actually asks for.

One system, not five

Booking, notes, documents, invoicing, portal and payouts

A Canadian group practice typically runs a booking tool, a note-taking tool, a file share, an accounting package and a payments processor, and reconciles them by hand. The privacy exposure of that estate is larger than any single one of its parts, and consolidating it is a privacy argument as much as an efficiency one.

14 — What stays with you

The obligations no software carries, in Canada or anywhere

Every page on this site ends here, and the list is deliberately short and deliberately blunt.

YoursWhy it cannot be ours
Being the custodian, trustee or responsible personThe statute names the practice, and in most provinces a named individual within it. A supplier cannot hold that role for you and no contract transfers it.
The words in your privacy policy and your consent formsThey describe what you do. We hold them, version them and keep the superseded ones; we do not write them, and a template that has not been read by your privacy officer is worse than none.
The retention periodsThey come from your college. Section 06.
Deciding whether a breach is reportableThe real-risk-of-significant-harm judgement federally, and the prescribed circumstances provincially, are assessments about your patients and your context. We give you a complete record to make the judgement from; the judgement is yours.
Securing the deploymentThe corollary of running it yourself. Patching, backups, restore testing, network security and physical access to the machine are yours — and where you want that carried, it is an operations contract, stated as one, not a footnote in a licence.
Legal adviceNothing on this page is legal advice, and it is not a substitute for Canadian counsel. It is a map of what applies and an honest account of what the software does about each item. The statutes move — Law 5 is new, Québec's regulations are still settling, and federal privacy reform has been in and out of Parliament for years.
How this page was written

The obligations are summarised from the statutes, regulator guidance and college standards named throughout, and the status column is written against the code in this repository rather than against a roadmap — which is why four rows say ◐ and six say ✗. Read those first. If a Canadian pack is built, this page changes with it and the marks move; until then they say what is true today.

The primary sources were not reachable from the machine this was written on. Several federal and provincial legislation sites are blocked by the network here, so the obligations below were assembled from regulator and professional-body material rather than read off the statute. That is fine for a map and not fine for a filing: have Canadian counsel confirm anything you intend to rely on, particularly Québec, where Law 5 is new and its regulations are still settling.