Canada's Provincial Health Privacy Laws: PHIPA, HIA & PHIA Compared

PIPEDA rarely governs health information in Canada. A province-by-province look at PHIPA, HIA, PHIA, and BC's FIPPA/PIPA split, and which one applies to you.

Learnsignal Education Team
7 min read
Updated

If your compliance plan for handling patient information in Canada starts and ends with "PIPEDA training," it's probably pointing your staff at the wrong law. PIPEDA is the federal Personal Information Protection and Electronic Documents Act, and it's the law most people have heard of. But for health information specifically, several provinces have their own dedicated statutes, and the federal government has formally recognised a number of them as "substantially similar" to PIPEDA — which means PIPEDA steps aside and the provincial law takes over for activity within that province. Training your team on the wrong statute isn't a small technicality; it means teaching the wrong consent rules, the wrong breach-notification timelines, and the wrong regulator to call when something goes wrong.

This guide walks through the picture province by province, so you can see which law actually governs where your organisation operates. It picks up the same theme covered in our guide to healthcare compliance and CPD training across Canada: health regulation in this country is administered provincially far more often than people assume, and privacy law is one more place that pattern holds.

Why "PIPEDA training" alone misses the point

PIPEDA applies to personal information, including health information, that private-sector organisations collect, use, or disclose in the course of commercial activity — but only where no substantially similar provincial law has been declared to apply instead. Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia have each had health-specific statutes formally declared substantially similar to PIPEDA by federal order. Once that designation is in place, organisations handling health information within that province are generally governed by the provincial law, not PIPEDA, for activity that stays inside the province. Federally regulated organisations, and health information that crosses provincial or national borders, can still bring PIPEDA back into play — which is exactly why "just do the generic PIPEDA course" is a risky shortcut rather than a safe default.

Ontario: PHIPA is the model most other provinces get compared to

Ontario's Personal Health Information Protection Act (PHIPA) governs "health information custodians" — a term that covers physicians, nurses, pharmacists, hospitals, labs, and most other providers who handle personal health information in the course of care. PHIPA was declared substantially similar to PIPEDA for health information by federal order in 2005, so PIPEDA generally does not apply to health information handled by custodians within Ontario. PHIPA sets its own consent rules (including "implied consent" within a patient's circle of care), its own breach-notification duties, and its own regulator, the Office of the Information and Privacy Commissioner of Ontario. If your organisation operates in Ontario, PHIPA — not PIPEDA — is the statute your privacy training needs to be built around.

Alberta: the HIA looks similar, but the substantially-similar label sits elsewhere

Alberta also has a dedicated health statute, the Health Information Act (HIA), which governs "custodians" such as physicians, Alberta Health Services, and other regulated health providers. Here's the distinction worth knowing: the federal substantially-similar designation for Alberta was granted to the province's general private-sector law, the Personal Information Protection Act (PIPA), not to the HIA specifically. That doesn't mean the HIA is unenforceable or optional — it's Alberta's binding law for custodians and carries its own obligations, including mandatory privacy impact assessments for new information systems. But readers should not assume the HIA carries the same federal "substantially similar" exemption that PHIPA carries in Ontario; the two provinces reached a similar practical destination (a dedicated health-privacy statute) by a different regulatory route, and the paperwork trail behind them is genuinely different. Organisations training staff on Alberta compliance should treat the HIA as the operative law for custodians, while recognising this nuance rather than repeating it as settled fact without checking current federal orders.

Manitoba: its own PHIA, without a confirmed substantially-similar order

Manitoba has its own Personal Health Information Act, also abbreviated PHIA, which sets out rules for "trustees" (the Manitoba term for custodians) handling personal health information in the province. Based on the available federal exemption orders, Manitoba's PHIA does not currently appear on the list of statutes formally declared substantially similar to PIPEDA for health information — unlike Ontario, New Brunswick, Newfoundland and Labrador, and Nova Scotia. In practice this means organisations in Manitoba need to think about both PHIA (as the provincial law governing trustees) and the possibility that PIPEDA still has a role for commercial activity that falls outside PHIA's scope. Given how consequential this distinction is, any organisation relying on Manitoba's designation status for a compliance decision should confirm the current position directly with the Office of the Manitoba Ombudsman or federal sources rather than taking a secondary summary — including this one — as the final word.

British Columbia: no single dedicated health-privacy statute

BC is the province most likely to trip people up, because it doesn't have one consolidated health-privacy law the way Ontario or Alberta do. Instead, which law applies depends on who is holding the information. Public bodies — health authorities, hospitals, government-run clinics — are governed by the Freedom of Information and Protection of Privacy Act (FIPPA), along with sector-specific statutes like the E-Health Act. Private-sector health providers — physicians in private practice, private clinics, independent practitioners — fall under the Personal Information Protection Act (PIPA), BC's general private-sector privacy law, which has itself been declared substantially similar to PIPEDA. So in BC, the right question isn't "which health-privacy act applies" but "is this a public body or a private organisation" — the answer determines whether FIPPA or PIPA governs, and PIPEDA generally isn't the answer either way for BC-based activity.

Saskatchewan and other provinces: check before you assume

Saskatchewan has its own Health Information Protection Act (HIPA), but it does not currently appear on the federal list of statutes declared substantially similar to PIPEDA for health information. The same caution applies to any province not named above: a provincial health-privacy law existing is not the same thing as it having received a formal substantially-similar designation, and only the latter displaces PIPEDA's application. Don't assume — verify against current federal orders for the specific province your organisation operates in.

What this means practically for staff training

The practical takeaway is simple even though the legal landscape isn't: generic, one-size-fits-all privacy training built around PIPEDA alone will miss the actual rules your staff need to follow in Ontario, Alberta, Manitoba, BC, or anywhere else with its own regime. Training needs to name the correct statute for the province your people work in, use that statute's own definitions (custodian, trustee, circle of care, and so on), and point staff to the right regulator for reporting a breach. This is the same lesson our post on the provincial patterns behind nursing CPD requirements makes about clinical continuing education — Canadian healthcare compliance is rarely one national rulebook, it's thirteen provincial and territorial ones that happen to rhyme. Privacy law is just the latest example, and it sits alongside things like the vulnerable sector check requirements that healthcare employers manage province by province — another compliance obligation that looks uniform from a distance but is actually administered locally.

Getting this right where you operate

If your organisation operates across more than one province, the safest approach is to map each location to its correct statute before building or buying training — PHIPA for Ontario custodians, the HIA for Alberta custodians, PHIA for Manitoba trustees, and the FIPPA/PIPA split for BC — rather than defaulting to a federal-only course that may not reflect the law your staff are actually bound by. Learnsignal's CPD resources can help you build role-appropriate, province-aware training programs for your team; take a look at our CPD course library to see what's available.

This article is provided for general information only and is not legal advice. Privacy legislation, substantially-similar designations, and regulatory guidance change over time, and this summary reflects our research at time of writing. Before making compliance decisions, verify the current law and any applicable federal exemption orders for your specific province with a qualified privacy lawyer or your provincial regulator.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View Pricing