AI report writing can be used in a PHIPA-compliant way, but the software category itself is never simply "compliant" or "non-compliant." Compliance depends on the vendor's safeguards and on how you, as the custodian, configure and use the tool. PHIPA keeps the responsibility for client information with you, not with the software.
I'm not a clinician, and I'm not your privacy lawyer, so I won't pretend to hand you a legal ruling. But I spend a lot of my time talking with psychologists in Canada about the tools they're weighing, and "is this even allowed?" is one of the first questions I hear. So here is the honest version of what I've learned, with the actual sources.

The lock icon is the easy part. What sits behind it is the part worth asking about.
Is AI report writing PHIPA-compliant?
The honest answer is: it can be, and no vendor can promise you it always is. "PHIPA-compliant" isn't a badge a piece of software earns and keeps. It's a description of how personal health information is actually handled in your practice, day to day. A tool can make compliance easy or hard, but the obligation lands on the custodian using it.
So when a vendor tells you their product "is PHIPA-compliant," treat that as a starting point for questions, not an answer. The real question is whether the way you use it, with the safeguards they provide, meets the standard PHIPA sets.
What does PHIPA actually require of me?
PHIPA requires you, as a health information custodian, to protect the client information in your control. Ontario's regulator for registered psychotherapists summarizes the duty as the obligation to "maintain security over personal health information by taking reasonable steps to protect against theft, loss and unauthorized use or disclosure."
The same source is clear about where responsibility sits: "A health information custodian is ultimately responsible for the personal health information in his or her custody or control, but may permit an agent to collect, use, disclose, retain or dispose of the information if certain requirements are met."
That last part is the whole ballgame for AI tools. You're allowed to use a third party. You remain responsible for what that third party does with the information. So the tool's safeguards become an extension of your own.
Where does PIPEDA fit in?
PIPEDA is the federal law that governs personal information handled in the course of commercial activity, and it reinforces the same principle when you hand data to a vendor. The Office of the Privacy Commissioner of Canada states plainly that "an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing."
It goes further on what you owe the information once it leaves your hands: "The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party."
In plain terms: sending client information into an AI tool doesn't transfer the responsibility along with it. You still have to be satisfied the protection travels with the data. Where that data lives matters too, which is a big enough topic that I gave it its own article on Canadian data residency.
What questions should I ask an AI report tool before I trust it?
Instead of asking "are you compliant?", ask questions that force specifics. The good vendors will have crisp answers; the vague ones tell you something by being vague.
- Where is client data stored and processed, and is it kept in Canada?
- Is data encrypted both in transit and at rest?
- What is retained after a draft is produced, and for how long? Is anything used to train models?
- Is information de-identified before processing, and what identifiers are stripped?
- If you transcribe sessions, is any audio kept, or only the text?
- What do you put in writing about all of this, so I can meet my duty to secure a "comparable level of protection"?
Notice that none of these ask the vendor to grade themselves. They ask for facts you can document and stand behind.

The same review instinct you bring to a report is the one to bring to a vendor's answers.
What is Soma's actual privacy posture?
Since I'm the one writing this, I'll be direct about where Soma stands, and I'll only state facts, not certifications. Soma keeps client data in Canada. Data is encrypted in transit and at rest. We de-identify information before it's processed, we operate on a zero-retention basis for the content we handle, and where sessions are transcribed we keep the text, not audio.
What I won't tell you is that any of that makes your practice compliant. That claim is exactly the one I'd want you to be skeptical of from anyone. The right frame is that Soma gives you factual safeguards to point to when you do your own PHIPA assessment.
So, can I use AI drafting and stay onside?
Yes, many Canadian psychologists do, provided the tool's safeguards are real and you use it within your obligations as a custodian. The law doesn't ban new tools. It asks you to take reasonable steps to protect client information, to stay responsible for third parties, and to make sure a comparable level of protection follows the data.
If a tool gives you honest, specific answers to the questions above, you can make an informed decision. If it gives you a badge and a shrug, keep asking. And if faster reports are the goal, the fairest way to judge a tool is on whether the reports still hold up once you've reviewed them. That's why Soma drafts a report you review and sign, rather than one you're asked to trust unread.
Thanks for reading. Getting privacy right for the people who trust you with their information is worth the extra questions, and I'm grateful to the clinicians who keep pushing me to answer them honestly.
— Ian
