Trust & Privacy

PIPEDA for Clinicians: A Plain Guide to What It Actually Says

· By Ian Vardy, CEO, Soma Health

PIPEDA is the federal privacy law covering private-sector organizations that handle personal information commercially. For most Canadian clinicians it sets the floor, with provincial health-privacy law often sitting on top. Here is what the law and the regulator actually say, quoted and linked, and the questions it should make you ask a software vendor.

PIPEDA is the federal privacy law that applies to private-sector organizations handling personal information in the course of commercial activity. For clinicians in private practice it usually sets the floor, with provincial health-privacy legislation sitting on top of it. Which law governs your files is a question the regulator answers — not your software vendor.

I'm not a clinician, and I'm not your privacy lawyer, so I won't hand you a ruling on your own practice. What I can do is quote the actual sources and link them, because I spend most of my week talking with Canadian psychologists who are weighing software, and "am I even allowed to use this?" is almost always the first question. This is the honest version of what those sources say.

A laptop showing a padlock and a secured connection

Every vendor has a page like this. The useful question is which law the page is actually answering to.

Who does PIPEDA actually apply to?

The Office of the Privacy Commissioner of Canada puts the scope in one sentence. In its summary of PIPEDA's requirements, the OPC states:

"PIPEDA applies to private-sector organizations across Canada that collect, use, or disclose personal information in the course of a commercial activity."

Two words in that sentence do a lot of work. Private-sector is why a solo practice and a group clinic are in scope in a way a public school board may not be. Commercial activity is why the law reaches your practice at all, rather than only reaching technology companies.

What clinicians tend to find counterintuitive is that PIPEDA is not a health law. It's a general commercial-privacy law that happens to cover you. The health-specific rules — the ones that use the language of custodianship and circles of care — usually come from your province.

How do I know whether PIPEDA or my provincial law governs my files?

This is the part where I'd rather point you somewhere than answer. Several provinces have health-privacy legislation that has been recognised as substantially similar to PIPEDA for health information, which means the provincial act governs instead of the federal one in those situations. The mapping is genuinely fiddly, it varies by province and by the kind of organisation you are, and getting it wrong is your professional exposure, not mine.

The OPC publishes an interactive "Which privacy law applies?" tool on its PIPEDA overview page for exactly this question. That tool is a better authority than any vendor blog, including this one.

Your college is the other place to look. Ontario's regulator for registered psychotherapists, for instance, summarises the provincial duty as the obligation to "maintain security over personal health information by taking reasonable steps to protect against theft, loss and unauthorized use or disclosure." That's the standard the software has to help you meet — and notice that it lands on you.

What happens to my obligation when I hand data to a vendor?

This is the question that matters most when you're choosing software, and the regulator's answer is not ambiguous. The OPC states plainly that:

"an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing."

Read that twice if you're mid-way through a vendor evaluation. Handing client information to a piece of software does not transfer the obligation to the software company. It stays with you, and you take on the job of having chosen well.

This is why I'm wary of the phrase "we're compliant, so you're covered." No vendor can be compliant on your behalf, because the duty the law describes isn't theirs to hold. If the obligation is yours, you're entitled to a specific answer about where a vendor's safeguards stop and your own assessment begins. What a vendor can legitimately offer is a set of factual safeguards you can point to when you do your own assessment — where data sits, what's encrypted, what's retained and for how long, who can see it, and what happens when you leave.

A professional reviewing a thick stack of documents at a glass desk

The obligation stays on your side of the desk. The vendor's job is to give you something solid to point at.

What does PIPEDA expect around consent?

Consent is one of the ten fair information principles the OPC lists as the backbone of the act. I'm deliberately not going to draft consent language for you — a software company writing consent wording for regulated professionals is a bad idea, and I've watched enough of our category do it to be confident about that.

What I will say is what the clinicians I talk to actually do. They fold the tool into the informed-consent conversation they were already having: they name it, they say what it does with what's said in the room, they say how long anything is kept, and they record the answer. One assessor put the real cost of it to me plainly — the wording is the easy part, and getting every assessor in the practice trained on the new conversation is the actual work.

Their clients, they said, ask remarkably consistent questions: what are you using, is something listening, and where does it go afterwards. If you can answer those three in a sentence each, you're most of the way there.

What should I ask a vendor because of this?

Because the duty stays with you, the useful questions are specific and factual rather than reassuring. There's a longer version of this in how to choose documentation AI for a clinical practice; the privacy-specific subset is:

  • Where is client information processed, and where is it stored? Not "is it secure" — which jurisdictions, at which step.
  • What is retained, and for how long? A number, and where that number is written down.
  • Is anything used to improve the product? If yes, is it off by default, and who has to opt in.
  • Who inside the company can see it? And can they show you the access log rather than describe it.
  • What happens when I leave? How you get your data out, and what's deleted.
  • What haven't you certified? The absence of a claim is information too.

For what it's worth, here's our side of those. Soma processes documentation at edge infrastructure in Montreal; there is a single step in report drafting where content transits a large-model provider outside Canada, and I'd rather write that down than let a map on a marketing page imply otherwise. Clients are aliased so we aren't holding identifiers. Data used to improve the product is off by default and takes both a clinician opt-in and each client's separate approval. And we'd rather point you at facts you can check than at a badge — vague reassurance is the thing I'd want you to be skeptical of from anybody, including me.

If it's useful, you can see how the drafting workflow keeps the clinician as the author who reviews and signs — that design choice exists partly because of the paragraph above about where the obligation lives.

None of this is legal advice, and your college has the final word on your practice. But the sources above are short, they're public, and they'll tell you more in twenty minutes than any vendor's security page will.

— Ian

Ian Vardy
Ian Vardy
Founder & CEO, Soma Health

Ian is building Soma — AI tools that give clinicians their time back by drafting documentation, so therapists and psychologists can focus on their clients. He writes about clinical reporting, AI, and running a clinician-first software company.

See how Soma drafts reports →