Soma · Articles

Trust & Privacy

10 articles in this category.

Trust & PrivacyAugust 24, 2026

Why We Describe De-Identification as a Tool, Not a Promise

Two things get conflated constantly: a model holding context while it works, and a vendor training on your content. They are different, and only one of them persists. Here is the distinction, plus the part that matters most — the strongest de-identification happens on your own machine, before anything is sent anywhere.

Trust & PrivacyAugust 21, 2026

What to Ask About Where Your Data Is Processed

Processing location and storage location are different questions, and most vendor pages only answer the second. Here are the five questions that get a specific answer about where your client information actually goes, and what a vague reply is telling you.

Trust & PrivacyAugust 20, 2026

Does an AI Tool Train on Your Client Notes? Where the Answer Is Actually Written

The answer is almost never under a heading that says 'training'. It sits in the terms of service under service improvement, product development, or aggregated and de-identified data. Here is exactly where to look, which four phrases to search for, and what each one actually permits.

Trust & PrivacyAugust 19, 2026

PIPEDA for Clinicians: A Plain Guide to What It Actually Says

PIPEDA is the federal privacy law covering private-sector organizations that handle personal information commercially. For most Canadian clinicians it sets the floor, with provincial health-privacy law often sitting on top. Here is what the law and the regulator actually say, quoted and linked, and the questions it should make you ask a software vendor.

Trust & PrivacyAugust 18, 2026

Which Canadian Colleges Have AI Documentation Guidance? What I Found When Clinicians Kept Asking

Clinicians kept asking me the same question — are we even allowed to use this? So I read what Canadian psychology colleges actually publish on AI. No college bans these tools; none has a full rulebook. Ontario, Alberta, and Ontario's privacy commissioner all land in the same place: the psychologist stays the author who reviews and signs.

Trust & PrivacyAugust 17, 2026

Is AI Report Writing PHIPA-Compliant? What Canadian Clinicians Need to Know

AI report writing can be used in a PHIPA-compliant way, but no software category is 'compliant' on its own. Compliance depends on the vendor's safeguards and how you, the custodian, configure and use the tool. Here is what PHIPA and PIPEDA actually require, and the questions to ask before you trust any AI report tool with client information.

Trust & PrivacyAugust 14, 2026

What Canadian Data Residency Means for Your Client Files

Canadian data residency means your client files are stored and processed inside Canada, rather than on servers in another country. For clinicians, it matters because information held abroad can fall under foreign laws and be accessed by foreign courts or governments. Here is what data residency actually means, why it matters under PIPEDA, and what to ask a vendor.

Trust & PrivacyAugust 10, 2026

Why the Clinician Stays the Author

Every psychologist I've spoken to draws the same line in almost the same words: the interpretation is what they trained for, and their signature has to mean something. We built to that line deliberately — here is what it means in the product, what it costs us, and why I think the trade is right.

Trust & PrivacyJune 25, 2026

Will an AI-Drafted Report Still Sound Like Me?

Yes — because you keep your voice, your structure, your clinical reasoning, and your final sign-off. The software takes the mechanical assembly off your plate, not the thinking. You read every section and it's yours, or it doesn't go out.

Trust & PrivacyJuly 23, 2025

AI and Client Data Privacy: What Anonymization Actually Protects

Protecting client privacy is essential when clinical text or speech is processed by AI. Anonymization and de-identification strip the obvious identifiers — but on their own they aren't foolproof, since models can sometimes re-identify people. A layered approach — masking identifiers, distorting biometrics, and differential privacy — keeps data useful while the clinician stays in control of every record.