Law 25 Compliance Checklist for Private Clinics in Quebec
Answer 15 questions about how your clinic protects client information. You get a Law 25 compliance score and a prioritized action plan based on the requirements of Quebec's Law 25 and the guidance of the Commission d'accès à l'information.
For private clinics in Quebec
Law 25 amended the Quebec Act respecting the protection of personal information in the private sector. It applies to every clinic and self-employed professional in Quebec, whatever their size. Since July 1, 2024, health and social services information held by private professional practices is also governed by the Act respecting health and social services information (Bill 5), which sets similar obligations.
Is your clinic outside Quebec? Take the PIPEDA compliance checklist.
Solid foundations
Based on your answers, your clinic already has most of the measures covered by this checklist in place. Close the remaining gaps below and review your practices once a year.
Partially compliant: gaps to close
Several important obligations are only partly covered. Start with the high-priority actions: they carry the most risk for your clients and your practice.
Significant compliance risk
Key obligations appear to be missing. Many of the actions below can be started quickly: tackle the high-priority ones first.
At least one high-priority point is answered No or I don't know: your result stays in the significant risk category until it is addressed.
Your prioritized action plan
-
High priority Accountability Partially in place
Confirm who is in charge of the protection of personal information (by default, the person with the highest authority in the clinic; any delegation must be in writing) and publish their title and contact information on your website.
-
Medium priority Transparency Partially in place
Adopt governance policies approved by the person in charge (roles, retention and destruction, complaint handling), publish a clear summary on your website, and publish a privacy policy in clear and simple terms wherever you collect information online. Inform people of any change to it.
-
Medium priority Inventory and necessity Partially in place
Build a simple inventory: each type of information, why you need it, where it is stored (EHR, email, paper, spreadsheets), who can access it and how long you keep it. Remove from your forms any field you do not need, such as a social insurance number.
-
High priority Consent Partially in place
Use a written consent form that explains each purpose in clear terms, including the right to withdraw consent, ask for consent separately for each purpose and keep the signed form in the client file. Health information is sensitive: any consent required for it must be express, and the request must be presented separately from other information.
Colib lets you send consent forms that clients sign online, and files them in the client's chart.
-
Medium priority Minors Partially in place
Add a parent or tutor consent step to your intake for clients under 14, and write down how you handle requests from parents of clients aged 14 and over, who can generally consent alone to the care they receive.
-
Medium priority Website tracking Partially in place
Install a cookie consent banner that blocks analytics and advertising tags until the visitor opts in (tools that can identify, locate or profile visitors must stay off until the visitor activates them), and remove pixels from booking and form pages.
-
High priority Privacy incidents Partially in place
Open a confidentiality incident register today and keep each entry for at least 5 years. Write a one-page procedure: contain the incident, take reasonable steps to reduce the risk of harm, assess the risk of serious injury, and notify the Commission d'accès à l'information and the people concerned promptly.
-
Medium priority Privacy impact assessment Partially in place
Before any new system, major overhaul or online service that handles client information, and before any disclosure outside Quebec or for research without consent, do a privacy impact assessment with the person in charge involved from the start, and keep it on file. For systems already in place, a documented review is a good practice. Ask your software vendors for their security documentation.
-
Medium priority Data location Partially in place
List every tool that stores or processes client information and where its data is located. For anything outside Quebec, other provinces included, complete a privacy impact assessment, sign a written agreement and mention it in your privacy policy.
Colib stores client information in Canada.
-
Medium priority Service providers Partially in place
Sign a written agreement with each service provider that accesses client information, covering confidentiality, security measures, use limited to the mandate, incident notification without delay and destruction at the end of the contract.
-
High priority Access control and logs Partially in place
Give every person an individual account, restrict access to client files by role, turn on two-factor authentication, remove access the day someone leaves, and use a system that logs access to client files so you can review it after any suspected incident.
Colib gives each user their own account with two-factor authentication, and logs access to client files.
-
High priority Encryption and communications Partially in place
Encrypt every device that holds client information (BitLocker, FileVault, phone passcode), keep files in an encrypted EHR rather than on the desktop, and move client exchanges to a secure portal.
Colib encrypts client information and includes a secure client portal with messaging.
-
Medium priority Retention and destruction Partially in place
Write down the retention period required by your professional order, schedule a yearly review of closed files and destroy them securely once the period has ended, keeping a record of what was destroyed. Anonymization must meet the criteria set by regulation: for most clinics, secure destruction is simpler.
-
Medium priority Access and portability requests Partially in place
Write a short procedure for access, correction and portability requests (identity check, 30-day deadline, response format) and test it: can you export the information a client gave you in a readable format today?
-
Medium priority Training and confidentiality Partially in place
Have everyone sign a confidentiality agreement, and hold a short yearly training on privacy, phishing and incident reporting. Keep a record of attendance.
Based on your answers, every point of this checklist is covered. Keep your register, policies and training up to date, and repeat this self-assessment each year.
Close These Gaps Faster With Colib
Colib is a clinic management software and EHR built in Canada. It can help with several technical points of your action plan: encrypted records stored in Canada, individual accounts with two-factor authentication, access logs, online consent forms and a secure client portal. Your policies, consent practices and training remain your responsibility.
- 30-day free trial
- No credit card required
- French and English
This self-assessment is for general information only, is based on the laws in force at the time of writing and does not cover every obligation that may apply to your clinic. It does not constitute legal advice or a certification of compliance. For advice on your situation, consult a lawyer or your professional order or regulatory college.
Law 25 Requirements for Private Clinics in Quebec
Most of Law 25's provisions came into force in three phases between 2022 and 2024. Every obligation is now in effect, for large clinics as well as for self-employed practitioners. Read more on our Law 25 EHR page and our page on electronic medical records in Quebec.
September 2022
- A person in charge of the protection of personal information, by default the highest authority of the clinic
- A register of confidentiality incidents
- Notification of the Commission d'accès à l'information and of the people concerned when there is a risk of serious injury
September 2023
- Governance policies and a privacy policy published on your website
- Privacy impact assessments, including before communicating information outside Quebec
- Stricter consent rules, including for minors under 14, and the highest level of confidentiality by default
- Destruction or anonymization at the end of the retention period
September 2024
- Right to data portability: on request, computerized personal information collected from the client must be provided in a structured, commonly used technological format
Law 25 Guidance From the Commission d'accès à l'information
The Commission d'accès à l'information (CAI) publishes guidance for businesses, including a compliance checklist of their responsibilities, guidelines on the criteria for valid consent and a guide to writing a privacy policy. For health information, private practices must also follow the Act respecting health and social services information (Bill 5), in force since July 1, 2024.
PIPEDA vs Law 25: Key Compliance Differences
Both laws share the same foundations, but Law 25 is more prescriptive. This summary is simplified: provincial health information laws may add their own rules.
| Topic | PIPEDA | Law 25 (Quebec) |
|---|---|---|
| Accountable person | An individual designated as accountable, whose identity is made available on request | By default the person with the highest authority; title and contact information published on the website |
| Policies | Privacy policies and practices readily available | Governance policies and a privacy policy published in clear and simple terms |
| Consent | Meaningful consent; express consent generally expected for sensitive information | Manifest, free and enlightened consent, given for specific purposes; express consent for sensitive information |
| Breaches and incidents | Report breaches creating a real risk of significant harm; keep a record of all breaches for 24 months | Notify the CAI and the people concerned when there is a risk of serious injury; keep an incident register |
| Privacy impact assessment | Recommended good practice | Required for new or overhauled information systems and before communicating information outside Quebec |
| Information leaving the jurisdiction | Transparency and contractual protections | Privacy impact assessment and written agreement |
| Access requests | Answer within 30 days, with a possible extension | Answer within 30 days |
| Data portability | No specific right | Right in force since September 2024 for information collected from the person |
Practising elsewhere in Canada too? Check your clinic with the PIPEDA compliance checklist.
What Is at Stake
Under Law 25, the Commission d'accès à l'information can impose administrative monetary penalties of up to $50,000 for an individual and, for other enterprises, up to $10 million or 2% of worldwide turnover, whichever is greater. Penal fines can reach $100,000 for an individual and $25 million or 4% of worldwide turnover for other enterprises, and are doubled for a subsequent offence. Under PIPEDA, knowingly failing to report a breach, notify affected individuals or keep breach records can lead to fines of up to $100,000.
Beyond Penalties: Client Trust
For a clinic, an incident can also damage client trust and lead to a complaint to your professional order. A yearly self-assessment helps you keep your privacy practices up to date as your clinic, your staff and your software change.
How Colib Helps You Close the Gaps
Several points of this checklist depend on your clinic software. Colib was built in Canada with privacy in mind. Software alone does not make a clinic compliant, but the right tools make the work much easier.
See how Colib supports your obligations on our Law 25-compliant EHR page, and discover our electronic medical records for Quebec.
Hosted in Canada, Encrypted
Client information is encrypted and stored in Canada, which simplifies your assessment of communications outside Canada. See our security page.
Individual Accounts and Two-Factor Authentication
Each user has their own account with two-factor authentication, and access to client files is logged.
Consent Forms, Secure Portal and Telehealth
Send consent forms that clients sign online, replace email with a secure client portal and hold sessions with our telehealth software for therapists.
Law 25 compliance -- frequently asked questions
What are the main Law 25 requirements?
Law 25 requires a person in charge of the protection of personal information, governance policies and a privacy policy, a confidentiality incident register and notification process, privacy impact assessments in specific cases, stricter consent rules, safeguards for communications outside Quebec, and respect for access and portability rights.
Does Law 25 apply to a solo practitioner?
Yes. Law 25 applies to every enterprise that collects, holds, uses or discloses personal information in Quebec, including self-employed professionals and small clinics. There is no size exemption, although policies can be proportionate to the size of the practice. Health information held by private practices is also covered by Quebec's Act respecting health and social services information.
Who is the person in charge of the protection of personal information?
By default, it is the person with the highest authority in the enterprise: for a solo practitioner, it is you. The function can be delegated in writing, in whole or in part, and the title and contact information must be published on the website.
What counts as a confidentiality incident?
Any unauthorized access, use or communication of personal information, its loss, or any other breach of its protection. A stolen laptop, an email sent to the wrong client or a ransomware attack are all incidents that must be recorded in the register.
Does client data have to be hosted in Canada?
Law 25 does not prohibit hosting outside Quebec, but before communicating information outside the province (including to another Canadian province), you must complete a privacy impact assessment showing the information will be adequately protected, sign a written agreement and inform clients. Choosing software hosted in Canada makes that assessment much simpler.
What is the difference between PIPEDA and Law 25?
Both laws rest on similar principles, but Law 25 is more prescriptive: it requires published governance policies, privacy impact assessments in specific cases and a right to data portability, and it provides for administrative monetary penalties. Private clinics in Quebec are generally governed by Quebec's private sector law for their activities within the province.
Is this checklist legal advice?
No. It is a self-assessment tool that helps you identify gaps and prioritize your work. For your specific situation, consult a lawyer or your professional order or regulatory college.
Explore More Colib Resources
Make Compliance the Default in Your Clinic
Encrypted records stored in Canada, two-factor authentication, online consent forms and a secure client portal. Start your 30-day free trial -- no credit card required.