Canadian privacy compliance
PIPEDA Compliance for AI Healthcare Reception: Canadian Privacy Done Right
Canadian medical practices face a layered privacy regime. Federally, PIPEDA governs commercial collection, use, and disclosure of personal information. Provincially, every province has its own health privacy act with stricter rules for personal health information. MedReception AI is built so that one configuration covers PIPEDA and every provincial act your practice operates under.
Provincial Acts Covered
10
Provincial health privacy acts mapped into our control set
Canadian Data Residency
CA
Optional in-Canada storage region for call audio, transcripts, and metadata
Standard Retention
30 days
Call audio default, configurable per provincial requirement
Breach Notification
72 h
QC Law 25 hard window; PIPEDA "as soon as feasible"
PIPEDA fundamentals
PIPEDA Basics for Canadian Healthcare AI
The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies whenever a commercial organization collects, uses, or discloses personal information in the course of commercial activity, including AI reception platforms that handle patient calls on behalf of a clinic.
10 Fair Information Principles
- 1. Accountability for personal information under our control
- 2. Identifying purposes at or before collection
- 3. Consent that is meaningful and informed
- 4. Limiting collection to what is necessary
- 5. Limiting use, disclosure, and retention to stated purpose
- 6. Accuracy of personal information held
- 7. Safeguards proportional to sensitivity
- 8. Openness about policies and practices
- 9. Individual access on request
- 10. Challenging compliance with a designated officer
How PIPEDA Treats Health Information
- Personal health information is "sensitive" by default
- Sensitive data requires express, not implied, consent
- Safeguards must be proportional to that sensitivity
- Cross-border transfer requires equivalent protection
- The Office of the Privacy Commissioner enforces and investigates
- Mandatory breach reporting since November 2018
- Penalties up to one hundred thousand dollars per violation
Where AI Reception Touches PIPEDA
- Inbound caller name, phone, reason for visit
- Voice biometric data captured in call audio
- Symptom descriptions classified as health information
- Insurance, billing, and identifier collection
- SMS confirmations and reminders
- Call recordings stored for QA and training
Custodian vs Processor Roles
- Clinic acts as custodian or trustee under provincial law
- MedReception AI acts as an information manager or processor
- Written agreement governs scope, security, and breach reporting
- Clinic retains ultimate accountability to the patient
- Processor must follow custodian directions on access and deletion
- Sub-processors are disclosed and contractually bound
Provincial layering
The 10 Provincial Health Privacy Acts
PIPEDA is the federal baseline. Every province layers its own health privacy law on top, and several have been declared substantially similar so the provincial law replaces PIPEDA for in-province health information. Here is the map MedReception AI uses to configure controls per tenant.
Ontario, PHIPA
Personal Health Information Protection Act, 2004. Custodian-centric, strict lockbox rights, IPC oversight, mandatory breach reporting to the Information and Privacy Commissioner since 2017.
Quebec, Law 25
An Act respecting the protection of personal information in the private sector, modernized by Law 25. Strictest consent regime in Canada, mandatory privacy impact assessments, 72 hour breach notice to the Commission d'acces a l'information, right to data portability.
Alberta, HIA
Health Information Act. Broad definition of health information that includes registration and billing data. Custodian model, strong notice-of-purpose requirements, OIPC Alberta investigates breaches.
British Columbia, PIPA
Personal Information Protection Act for the private sector plus the Personal Information Protection of Privacy Act for public bodies. Both require Canadian data storage for public health entities.
Nova Scotia, PHIA
Personal Health Information Act. Custodian framework similar to Ontario, mandatory breach reporting to the Privacy Review Officer, strict use and disclosure limits.
New Brunswick, PHIPAA
Personal Health Information Privacy and Access Act. Trustee model, written information manager agreements required, Access to Information and Privacy Commissioner oversight.
Manitoba, PHIA
Personal Health Information Act. Trustee responsibilities, written agreements with information managers, Manitoba Ombudsman handles complaints.
Saskatchewan, HIPA
Health Information Protection Act. Trustee model, consent directives recognized, SK Information and Privacy Commissioner investigates.
Newfoundland and Labrador, PHIA
Personal Health Information Act. Custodian framework, mandatory breach notice to the Information and Privacy Commissioner of Newfoundland and Labrador.
Prince Edward Island, HIA
Health Information Act. Custodian and information manager roles defined, IPC PEI oversight, mandatory breach notification for material privacy breaches.
MedReception AI controls
Our PIPEDA-Aligned Control Set
Each PIPEDA principle and provincial requirement maps to a concrete technical or administrative control in the MedReception AI platform. Below is the production control set every Canadian tenant inherits by default.
Data Residency
- Canadian region option for call audio, transcripts, and metadata
- Region pinning enforced at tenant configuration time
- Cross-border transfer notice surfaced in consent script when used
- Sub-processor list documented and updated
- Quebec tenants get an enhanced cross-border disclosure
Encryption
- TLS 1.2 or higher for all data in transit
- AES 256 at rest for audio, transcripts, and structured data
- KMS managed keys with documented rotation
- Customer managed keys available on enterprise tier
- Encrypted backups with separate key scope
Audit Logs
- Immutable access logs on patient records and call audio
- Per-user attribution for every read, export, and delete
- Retention aligned to longest applicable provincial requirement
- Custodian access on request for PHIPA and HIA accounting of disclosures
- Anomalous access alerts feed the security operations queue
Breach Notification Readiness
- Documented incident response runbook with provincial decision tree
- Pre-templated notice content for OPC, IPC, and Commission d'acces a l'information
- Forensic preservation enabled at incident declaration
- Custodian notification within four hours of detection
- 72 hour external clock honored for Quebec tenants
Consent Capture
- Recorded consent statement at start of every call
- Express consent prompt for symptom and identifier collection
- Provincial language variants (English, French)
- Withdrawal of consent honored mid-call and post-call
- Consent record stored with the call session for audit
OPC Complaint Readiness
- Named privacy officer reachable by patients and custodians
- 30 day response standard for access requests
- Documented complaint intake and triage workflow
- Cooperation playbook for OPC and provincial commissioner inquiries
- Annual self-assessment against PIPEDA principles
Data flow specifics
Where Call Data Goes, How Long It Stays, Who Sees It
Privacy regulators want concrete answers, not abstractions. Here is what actually happens to a patient call from the moment it lands on the MedReception AI platform.
Step 1: Inbound call lands
Carrier hands the call to our session orchestrator. The call leg is encrypted in transit. A session record is created in the tenant's region (Canadian region for Canadian tenants).
Step 2: Audio streams to the model
Audio is streamed to a speech model and a conversation model for real-time response. Audio is not used to train base models. Transcripts are persisted to the tenant's region.
Step 3: Structured data is extracted
Caller name, callback, reason for visit, and booking preferences are extracted and written to the EHR or scheduler integration the clinic has configured. The clinic remains the custodian of that downstream record.
Step 4: Retention countdown starts
Call audio is retained for 30 days by default, then purged. Transcripts and structured fields follow the tenant retention policy, configurable to match provincial requirements (for example longer for PHIPA records of care).
Step 5: Access is logged
Every read by clinic staff or MedReception support is logged with user, timestamp, and reason. Support reads require a custodian-approved ticket. The clinic can export the access log at any time.
Step 6: Deletion on request
When a patient asks the custodian to delete their data, the clinic raises a deletion request in the portal. We purge audio, transcripts, and structured records across primary stores and backups within the documented service-level window.
Provincial nuances
Where the Provincial Acts Diverge in Practice
Most provincial acts share the same skeleton (custodian, information manager, lockbox, breach notice), but a few have sharp edges worth calling out before you configure your tenant.
Quebec Law 25
- Strict, granular, express consent for every purpose
- 72 hour breach notice to the Commission d'acces a l'information
- Mandatory Privacy Impact Assessment for AI projects
- Cross-border transfer requires documented assessment
- Data portability rights in machine-readable format
- Penalties up to 4 percent of worldwide turnover
Alberta HIA
- Health information includes registration and billing
- Notice-of-purpose statements must be specific and current
- Custodian must conduct a Privacy Impact Assessment for new systems
- Information manager agreements are mandatory and reviewable
- OIPC Alberta investigates and can compel production
- Mandatory breach reporting to OIPC and the Minister of Health
Ontario PHIPA
- Custodian has direct accountability for agent conduct
- Lockbox rights let patients restrict specific disclosures
- Mandatory IPC breach reporting since October 2017
- Accounting of disclosures must be available on request
- Order-making power vests in the IPC of Ontario
- Information practices must be publicly available
What auditors look at
What Provincial Privacy Commissioners Look At During Audits
When a Privacy Commissioner opens a file (driven by a complaint or a breach report), the same evidence requests come up across PHIPA, HIA, PIPA, Law 25 and the PHIA family. MedReception AI keeps these artifacts ready.
Documentation Evidence
- Information manager or processor agreement with the clinic
- Privacy Impact Assessment for the AI reception system
- Data flow diagram and sub-processor list
- Notice-of-purpose statements presented to callers
- Retention schedule and provincial mapping
- Incident response runbook and most recent tabletop record
Technical Evidence
- Audit logs proving access tracking is live
- Encryption configuration evidence at rest and in transit
- Region pinning evidence for Canadian residency claims
- Backup and key management documentation
- Penetration test report from the last 12 months
- Vulnerability management cadence and patch evidence
Operational Evidence
- Named privacy officer with contact details
- Staff privacy training records and renewal cadence
- Access request handling log with response times
- Complaint intake log and resolution outcomes
- Breach log including non-reportable internal events
- Annual self-assessment report against PIPEDA principles
Patient-Facing Evidence
- Public privacy policy in plain language
- Consent script recordings sampled across tenants
- Withdrawal of consent workflow demonstration
- Access-to-records request form and process
- Lockbox or restriction request workflow (PHIPA, PHIA)
- Language accommodation including French in Quebec
Implementation timeline
From Signature to Canada-Ready in 30 Days
Days 1 to 7: Paperwork
Information manager or processor agreement signed. Provincial profile selected. Privacy officer assigned. Data residency region confirmed.
Days 8 to 21: Configuration
Consent scripts tuned for province and language. Retention windows aligned to custodian schedule. Audit log export wired to clinic IT. Tabletop incident drill completed.
Days 22 to 30: Go-live
Soft launch with monitored call flow. Privacy officer hand-off complete. Audit log baseline captured. First weekly compliance report delivered.
Operate across the border
Running a HIPAA Clinic Too?
Cross-border practices need both HIPAA and PIPEDA controls. Our HIPAA program and AI-specific HIPAA addendum sit alongside the Canadian profile so dual-country groups have one configuration covering both regimes.
See it on a real call
Hear the Canadian Consent Script Live
Book a demo and we will run a sample patient call from a Canadian number, walk through the consent script, and show you the audit log entry that lands a few seconds later.
Book the Canadian demoRelated compliance reading
Continue Down the Canadian Compliance Path
Compliance Overview
Our full multi-jurisdiction compliance program at a glance
Compliance FAQ
Custodian, processor, audit, and breach questions answered
AI Receptionist for Canada
Product page tuned to Canadian clinics and provincial rules
Security Program
Technical safeguards, monitoring, and incident response
Privacy Policy
How we handle personal information across the platform
All Compliance Topics
Browse the full compliance topic library