Canadian privacy compliance

PIPEDA Compliance for AI Healthcare Reception: Canadian Privacy Done Right

Canadian medical practices face a layered privacy regime. Federally, PIPEDA governs commercial collection, use, and disclosure of personal information. Provincially, every province has its own health privacy act with stricter rules for personal health information. MedReception AI is built so that one configuration covers PIPEDA and every provincial act your practice operates under.

PIPEDA Aligned, Province by Province

Provincial Acts Covered

10

Provincial health privacy acts mapped into our control set

Canadian Data Residency

CA

Optional in-Canada storage region for call audio, transcripts, and metadata

Standard Retention

30 days

Call audio default, configurable per provincial requirement

Breach Notification

72 h

QC Law 25 hard window; PIPEDA "as soon as feasible"

PIPEDA fundamentals

PIPEDA Basics for Canadian Healthcare AI

The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies whenever a commercial organization collects, uses, or discloses personal information in the course of commercial activity, including AI reception platforms that handle patient calls on behalf of a clinic.

10 Fair Information Principles

  • 1. Accountability for personal information under our control
  • 2. Identifying purposes at or before collection
  • 3. Consent that is meaningful and informed
  • 4. Limiting collection to what is necessary
  • 5. Limiting use, disclosure, and retention to stated purpose
  • 6. Accuracy of personal information held
  • 7. Safeguards proportional to sensitivity
  • 8. Openness about policies and practices
  • 9. Individual access on request
  • 10. Challenging compliance with a designated officer

How PIPEDA Treats Health Information

  • Personal health information is "sensitive" by default
  • Sensitive data requires express, not implied, consent
  • Safeguards must be proportional to that sensitivity
  • Cross-border transfer requires equivalent protection
  • The Office of the Privacy Commissioner enforces and investigates
  • Mandatory breach reporting since November 2018
  • Penalties up to one hundred thousand dollars per violation

Where AI Reception Touches PIPEDA

  • Inbound caller name, phone, reason for visit
  • Voice biometric data captured in call audio
  • Symptom descriptions classified as health information
  • Insurance, billing, and identifier collection
  • SMS confirmations and reminders
  • Call recordings stored for QA and training

Custodian vs Processor Roles

  • Clinic acts as custodian or trustee under provincial law
  • MedReception AI acts as an information manager or processor
  • Written agreement governs scope, security, and breach reporting
  • Clinic retains ultimate accountability to the patient
  • Processor must follow custodian directions on access and deletion
  • Sub-processors are disclosed and contractually bound

Provincial layering

The 10 Provincial Health Privacy Acts

PIPEDA is the federal baseline. Every province layers its own health privacy law on top, and several have been declared substantially similar so the provincial law replaces PIPEDA for in-province health information. Here is the map MedReception AI uses to configure controls per tenant.

Ontario, PHIPA

Personal Health Information Protection Act, 2004. Custodian-centric, strict lockbox rights, IPC oversight, mandatory breach reporting to the Information and Privacy Commissioner since 2017.

Quebec, Law 25

An Act respecting the protection of personal information in the private sector, modernized by Law 25. Strictest consent regime in Canada, mandatory privacy impact assessments, 72 hour breach notice to the Commission d'acces a l'information, right to data portability.

Alberta, HIA

Health Information Act. Broad definition of health information that includes registration and billing data. Custodian model, strong notice-of-purpose requirements, OIPC Alberta investigates breaches.

British Columbia, PIPA

Personal Information Protection Act for the private sector plus the Personal Information Protection of Privacy Act for public bodies. Both require Canadian data storage for public health entities.

Nova Scotia, PHIA

Personal Health Information Act. Custodian framework similar to Ontario, mandatory breach reporting to the Privacy Review Officer, strict use and disclosure limits.

New Brunswick, PHIPAA

Personal Health Information Privacy and Access Act. Trustee model, written information manager agreements required, Access to Information and Privacy Commissioner oversight.

Manitoba, PHIA

Personal Health Information Act. Trustee responsibilities, written agreements with information managers, Manitoba Ombudsman handles complaints.

Saskatchewan, HIPA

Health Information Protection Act. Trustee model, consent directives recognized, SK Information and Privacy Commissioner investigates.

Newfoundland and Labrador, PHIA

Personal Health Information Act. Custodian framework, mandatory breach notice to the Information and Privacy Commissioner of Newfoundland and Labrador.

Prince Edward Island, HIA

Health Information Act. Custodian and information manager roles defined, IPC PEI oversight, mandatory breach notification for material privacy breaches.

MedReception AI controls

Our PIPEDA-Aligned Control Set

Each PIPEDA principle and provincial requirement maps to a concrete technical or administrative control in the MedReception AI platform. Below is the production control set every Canadian tenant inherits by default.

Data Residency

  • Canadian region option for call audio, transcripts, and metadata
  • Region pinning enforced at tenant configuration time
  • Cross-border transfer notice surfaced in consent script when used
  • Sub-processor list documented and updated
  • Quebec tenants get an enhanced cross-border disclosure

Encryption

  • TLS 1.2 or higher for all data in transit
  • AES 256 at rest for audio, transcripts, and structured data
  • KMS managed keys with documented rotation
  • Customer managed keys available on enterprise tier
  • Encrypted backups with separate key scope

Audit Logs

  • Immutable access logs on patient records and call audio
  • Per-user attribution for every read, export, and delete
  • Retention aligned to longest applicable provincial requirement
  • Custodian access on request for PHIPA and HIA accounting of disclosures
  • Anomalous access alerts feed the security operations queue

Breach Notification Readiness

  • Documented incident response runbook with provincial decision tree
  • Pre-templated notice content for OPC, IPC, and Commission d'acces a l'information
  • Forensic preservation enabled at incident declaration
  • Custodian notification within four hours of detection
  • 72 hour external clock honored for Quebec tenants

Consent Capture

  • Recorded consent statement at start of every call
  • Express consent prompt for symptom and identifier collection
  • Provincial language variants (English, French)
  • Withdrawal of consent honored mid-call and post-call
  • Consent record stored with the call session for audit

OPC Complaint Readiness

  • Named privacy officer reachable by patients and custodians
  • 30 day response standard for access requests
  • Documented complaint intake and triage workflow
  • Cooperation playbook for OPC and provincial commissioner inquiries
  • Annual self-assessment against PIPEDA principles

Data flow specifics

Where Call Data Goes, How Long It Stays, Who Sees It

Privacy regulators want concrete answers, not abstractions. Here is what actually happens to a patient call from the moment it lands on the MedReception AI platform.

Step 1: Inbound call lands

Carrier hands the call to our session orchestrator. The call leg is encrypted in transit. A session record is created in the tenant's region (Canadian region for Canadian tenants).

Step 2: Audio streams to the model

Audio is streamed to a speech model and a conversation model for real-time response. Audio is not used to train base models. Transcripts are persisted to the tenant's region.

Step 3: Structured data is extracted

Caller name, callback, reason for visit, and booking preferences are extracted and written to the EHR or scheduler integration the clinic has configured. The clinic remains the custodian of that downstream record.

Step 4: Retention countdown starts

Call audio is retained for 30 days by default, then purged. Transcripts and structured fields follow the tenant retention policy, configurable to match provincial requirements (for example longer for PHIPA records of care).

Step 5: Access is logged

Every read by clinic staff or MedReception support is logged with user, timestamp, and reason. Support reads require a custodian-approved ticket. The clinic can export the access log at any time.

Step 6: Deletion on request

When a patient asks the custodian to delete their data, the clinic raises a deletion request in the portal. We purge audio, transcripts, and structured records across primary stores and backups within the documented service-level window.

Provincial nuances

Where the Provincial Acts Diverge in Practice

Most provincial acts share the same skeleton (custodian, information manager, lockbox, breach notice), but a few have sharp edges worth calling out before you configure your tenant.

Quebec Law 25

  • Strict, granular, express consent for every purpose
  • 72 hour breach notice to the Commission d'acces a l'information
  • Mandatory Privacy Impact Assessment for AI projects
  • Cross-border transfer requires documented assessment
  • Data portability rights in machine-readable format
  • Penalties up to 4 percent of worldwide turnover

Alberta HIA

  • Health information includes registration and billing
  • Notice-of-purpose statements must be specific and current
  • Custodian must conduct a Privacy Impact Assessment for new systems
  • Information manager agreements are mandatory and reviewable
  • OIPC Alberta investigates and can compel production
  • Mandatory breach reporting to OIPC and the Minister of Health

Ontario PHIPA

  • Custodian has direct accountability for agent conduct
  • Lockbox rights let patients restrict specific disclosures
  • Mandatory IPC breach reporting since October 2017
  • Accounting of disclosures must be available on request
  • Order-making power vests in the IPC of Ontario
  • Information practices must be publicly available

What auditors look at

What Provincial Privacy Commissioners Look At During Audits

When a Privacy Commissioner opens a file (driven by a complaint or a breach report), the same evidence requests come up across PHIPA, HIA, PIPA, Law 25 and the PHIA family. MedReception AI keeps these artifacts ready.

Documentation Evidence

  • Information manager or processor agreement with the clinic
  • Privacy Impact Assessment for the AI reception system
  • Data flow diagram and sub-processor list
  • Notice-of-purpose statements presented to callers
  • Retention schedule and provincial mapping
  • Incident response runbook and most recent tabletop record

Technical Evidence

  • Audit logs proving access tracking is live
  • Encryption configuration evidence at rest and in transit
  • Region pinning evidence for Canadian residency claims
  • Backup and key management documentation
  • Penetration test report from the last 12 months
  • Vulnerability management cadence and patch evidence

Operational Evidence

  • Named privacy officer with contact details
  • Staff privacy training records and renewal cadence
  • Access request handling log with response times
  • Complaint intake log and resolution outcomes
  • Breach log including non-reportable internal events
  • Annual self-assessment report against PIPEDA principles

Patient-Facing Evidence

  • Public privacy policy in plain language
  • Consent script recordings sampled across tenants
  • Withdrawal of consent workflow demonstration
  • Access-to-records request form and process
  • Lockbox or restriction request workflow (PHIPA, PHIA)
  • Language accommodation including French in Quebec

Implementation timeline

From Signature to Canada-Ready in 30 Days

1

Days 1 to 7: Paperwork

Information manager or processor agreement signed. Provincial profile selected. Privacy officer assigned. Data residency region confirmed.

Ready for Privacy Impact Assessment kickoff
2

Days 8 to 21: Configuration

Consent scripts tuned for province and language. Retention windows aligned to custodian schedule. Audit log export wired to clinic IT. Tabletop incident drill completed.

Tenant configuration locked
3

Days 22 to 30: Go-live

Soft launch with monitored call flow. Privacy officer hand-off complete. Audit log baseline captured. First weekly compliance report delivered.

Provincial compliance evidence on file

Operate across the border

Running a HIPAA Clinic Too?

Cross-border practices need both HIPAA and PIPEDA controls. Our HIPAA program and AI-specific HIPAA addendum sit alongside the Canadian profile so dual-country groups have one configuration covering both regimes.

See it on a real call

Hear the Canadian Consent Script Live

Book a demo and we will run a sample patient call from a Canadian number, walk through the consent script, and show you the audit log entry that lands a few seconds later.

Book the Canadian demo

Related compliance reading

Continue Down the Canadian Compliance Path

PIPEDA Compliance for AI Healthcare Reception | Medreception AI