Does Canada Have HIPAA? PIPEDA and Provincial Laws

Canada does not have HIPAA, and it has no single law that plays the same role. Health information in Canada is protected by a layered system: a federal statute called the Personal Information Protection and Electronic Documents Act (PIPEDA) sets baseline rules for private-sector organizations, and several provinces have their own health-specific privacy laws that apply on top of, or in place of, the federal one. In many situations the Canadian rules are stricter than what HIPAA requires.

Why Canada Doesn’t Need a HIPAA Equivalent

HIPAA is a sector law. It reaches only “covered entities” in U.S. healthcare — providers who transmit information electronically, health insurers, and clearinghouses — plus the “business associates” those entities hire to handle patient data.1HHS.gov. Covered Entities and Business Associates A U.S. fitness app or an employer wellness program that isn’t a covered entity often falls outside HIPAA entirely.

PIPEDA works differently. It applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity, regardless of industry.2Office of the Privacy Commissioner of Canada. PIPEDA Requirements in Brief A tech company holding health data, an insurance broker, and a pharmacy chain all sit inside the same framework. There is no threshold test for whether a business is “covered” the way HIPAA requires.

Enforcement is also split up. HIPAA violations are pursued by the U.S. Department of Health and Human Services. In Canada, the federal Privacy Commissioner handles PIPEDA, while provincial commissioners or information officers handle their own health privacy statutes. Canadian penalties were historically modest, but recent provincial reforms have pushed some fines into the hundreds of thousands, and in Quebec into the millions.

PIPEDA: The Federal Baseline

PIPEDA is the federal backbone of private-sector privacy law in Canada, including for health information, and it governs whenever data crosses provincial or national borders.2Office of the Privacy Commissioner of Canada. PIPEDA Requirements in Brief Alberta, British Columbia, and Quebec have their own private-sector privacy laws that the federal government has deemed substantially similar to PIPEDA, so organizations operating entirely inside one of those provinces follow the provincial law instead.3Office of the Privacy Commissioner of Canada. Provincial Laws That May Apply Instead of PIPEDA Everywhere else, and for any data flowing between provinces or internationally, PIPEDA applies.

The law is built on ten fair information principles that boil down to a short list of duties: tell people why you’re collecting their information, get meaningful consent, take only what you need, keep it accurate and secure, and let people see what you hold and challenge it.

A proposed replacement called the Consumer Privacy Protection Act, part of Bill C-27, stalled in committee and did not pass before the parliamentary session ended in January 2025.4Parliament of Canada. C-27 (44-1) – LEGISinfo PIPEDA remains the operative federal law.

Provincial Health Privacy Laws

Healthcare is mainly a provincial responsibility in Canada, so most provinces have layered their own health-specific privacy laws on top of PIPEDA. These provincial statutes generally take precedence for health data collected and used inside the province.2Office of the Privacy Commissioner of Canada. PIPEDA Requirements in Brief Ontario, New Brunswick, Nova Scotia, and Newfoundland and Labrador have all had their health privacy laws recognized as substantially similar to PIPEDA for health information.

Ontario

Ontario’s Personal Health Information Protection Act (PHIPA) is one of the most detailed provincial statutes. It applies to “health information custodians,” which includes physicians, hospitals, pharmacies, labs, and long-term care homes.5Ontario.ca. Personal Health Information Protection Act, 2004 Since January 2024, Ontario’s Information and Privacy Commissioner can impose administrative monetary penalties of up to $50,000 for individuals and $500,000 for organizations, with larger fines available through prosecution.

Alberta

Alberta’s Health Information Act (HIA) governs custodians including physicians, nurses, pharmacists, Alberta Health Services, and the provincial health ministry.6Alberta.ca. Health Information Act It uses a “circle of care” model that lets providers involved in your treatment share information without renewed consent for each exchange. Mandatory breach notification is built in, with fines that can reach $500,000 for organizations.

British Columbia

BC splits its rules across two statutes. The Freedom of Information and Protection of Privacy Act (FIPPA) covers public bodies such as hospitals and health authorities, and the Personal Information Protection Act (PIPA) covers private providers like physicians’ offices and private clinics. Both fall to BC’s Information and Privacy Commissioner.

Quebec

Quebec’s private-sector privacy law was substantially rewritten by what is commonly called “Law 25.”3Office of the Privacy Commissioner of Canada. Provincial Laws That May Apply Instead of PIPEDA Medical information counts as sensitive personal information and generally requires express consent before it is shared with a third party. The reforms phased in from 2022 through 2024. Administrative fines can reach $10 million CAD or 2% of worldwide turnover, whichever is greater. Enforcement runs through the Commission d’accès à l’information.

What Rights You Have Over Your Health Information

The specific statute varies, but your core rights are broadly the same across the country.

You can ask to see the personal health information an organization holds about you. Under PIPEDA, organizations must respond to an access request within 30 days.7Office of the Privacy Commissioner of Canada. PIPEDA Fair Information Principle 9 – Individual Access Provincial health laws set similar timelines. You can also challenge the accuracy of your records and ask that errors be corrected.

If you think an organization has mishandled your health information, you can complain to the relevant oversight body. Federally, that is the Office of the Privacy Commissioner of Canada. Every province has its own commissioner or equivalent office. These regulators can investigate, make recommendations, order compliance, and in some provinces impose financial penalties directly.

Consent is the default in every jurisdiction. Organizations generally need your knowledge and consent to collect, use, or share health information, with narrow exceptions for emergencies and for sharing within the treating team. They can also only use the information for the purpose you agreed to, or a closely related one, and are expected to collect no more than they need.

What Happens If There’s a Breach

Breach notification is one area where Canadian law has tightened noticeably. Under PIPEDA, any organization that experiences a security breach involving personal information must report it to the Privacy Commissioner if there is a “real risk of significant harm” to the affected individuals, and must notify those individuals as soon as feasible.8Justice Laws Website. Personal Information Protection and Electronic Documents Act – Section 10.19Office of the Privacy Commissioner of Canada. What You Need to Know About Mandatory Reporting of Breaches of Security Safeguards

Significant harm is defined broadly and includes identity theft, financial loss, damage to reputation, humiliation, and loss of employment or business opportunities. The assessment turns on how sensitive the information was and how likely it is to be misused.8Justice Laws Website. Personal Information Protection and Electronic Documents Act – Section 10.1 Health data almost always qualifies as highly sensitive, so a breach involving medical records will nearly always trigger notification.

Organizations must also keep a record of every breach for at least two years, even ones that don’t clear the significant-harm threshold.9Office of the Privacy Commissioner of Canada. What You Need to Know About Mandatory Reporting of Breaches of Security Safeguards Knowingly failing to report a breach, notify individuals, or maintain the records is a criminal offence under PIPEDA and can lead to fines of up to $100,000 on indictment.10Justice Laws Website. Personal Information Protection and Electronic Documents Act – Section 28 Provincial health laws impose their own parallel duties.

What About Data Sent to the United States?

This is where the HIPAA question becomes especially practical. Many Canadian healthcare organizations use cloud platforms, electronic medical record systems, or billing services hosted in the United States. PIPEDA does not ban sending personal information across the border, but it puts the full burden of protection on the Canadian organization that initiates the transfer.11Office of the Privacy Commissioner of Canada. Guidelines for Processing Personal Data Across Borders

The Canadian organization must use contracts or other binding arrangements to ensure the foreign processor delivers a comparable level of protection. It is expected to do due diligence on the foreign processor’s security policies, staff training, and safeguards, and to keep the right to audit.11Office of the Privacy Commissioner of Canada. Guidelines for Processing Personal Data Across Borders

There is also a transparency duty. Organizations must tell you, ideally at the time of collection, that your information may be processed in another country and that while it is there, it could be accessible to that country’s law enforcement and national security authorities. A contract with a U.S. vendor cannot override U.S. law. If your health data sits on a U.S. server, U.S. authorities may be able to reach it under U.S. law regardless of what the contract says, and Canadian regulators expect organizations to weigh and disclose that risk.

Penalties Have Real Teeth

Canadian health privacy penalties have grown substantially, especially at the provincial level.

  • Under PIPEDA, knowingly breaking the breach-notification rules or obstructing a Privacy Commissioner investigation can bring fines of up to $10,000 on summary conviction or $100,000 on indictment. The Commissioner can also audit organizations, publish findings, and pursue compliance agreements.10Justice Laws Website. Personal Information Protection and Electronic Documents Act – Section 28
  • Under Ontario’s PHIPA, administrative monetary penalties reach $50,000 for individuals and $500,000 for organizations, and prosecution can push fines to $200,000 for individuals and $1,000,000 for organizations.
  • Under Alberta’s HIA, fines run from $2,000 to $10,000 for individuals and $200,000 to $500,000 for organizations.6Alberta.ca. Health Information Act
  • Under Quebec’s Law 25, administrative penalties can reach $10 million CAD or 2% of worldwide turnover, whichever is greater.

Formal penalties are only part of the picture. Privacy breaches also trigger class-action lawsuits, and Canadian courts have awarded damages in privacy cases involving health data. The Canadian enforcement climate is no longer a lenient one.