Free tool for private clinics

Law 25 and PIPEDA Compliance Checklist for Private Clinics

Answer 15 questions about how your clinic protects client information. You get a compliance score and a prioritized action plan, adapted to Quebec's Law 25 or to PIPEDA and the privacy laws of the other provinces.

15 questions About 5 minutes No email required Answers stay in your browser
Where is your clinic located?

Depending on your province, a provincial law may apply instead of or in addition to PIPEDA, for example PHIPA in Ontario or PIPA in Alberta and British Columbia. This checklist covers the obligations these laws have in common.

Law 25 amended the Quebec Act respecting the protection of personal information in the private sector. It applies to every clinic and self-employed professional in Quebec, whatever their size.

  1. 1 Accountability Have you designated, in writing, the person in charge of the protection of personal information, and are their title and contact information published on your website? Have you designated, in writing, a privacy officer accountable for your clinic's compliance, and can clients easily find their title and contact information?
  2. 2 Governance policies Have you adopted governance policies and practices (roles and responsibilities, retention and destruction, complaint handling) and published detailed information about them on your website? Do you have written privacy policies and procedures (roles, retention and destruction, complaint handling) and are they available to clients on request?
  3. 3 Privacy policy When you collect information through technological means (website, online booking, online forms), do you publish a privacy policy written in clear and simple terms? Does your website or online booking page link to a clear privacy notice explaining what you collect, why, and with whom you share it?
  4. 4 Consent Do you obtain your clients' express consent, documented in their file, before collecting and using their health information, with a separate request for each specific purpose (e.g. research, newsletter, disclosure to a third party)? Do you obtain your clients' express consent, documented in their file, before collecting, using or disclosing their health information, with a separate request for any secondary purpose (e.g. research, newsletter, disclosure to a third party)?
  5. 5 Website tracking Are the tracking tools on your website (analytics, advertising pixels) turned off by default until the visitor consents, and do you avoid sending any health-related data to advertising platforms? Do you obtain visitors' consent before activating tracking tools on your website (analytics, advertising pixels), and do you avoid sending any health-related data to advertising platforms?
  6. 6 Privacy incidents Do you keep a register of confidentiality incidents and have a written procedure to notify the Commission d'accès à l'information and the people concerned when an incident presents a risk of serious injury? Do you keep a record of every privacy breach (for at least 24 months) and have a written procedure to report breaches that pose a real risk of significant harm to the privacy commissioner and to the people concerned?
  7. 7 Privacy impact assessment Do you carry out a privacy impact assessment (PIA) before acquiring, developing or overhauling software that handles personal information (EHR, online booking, telehealth, AI tools)? Before adopting new software that handles client information (EHR, online booking, telehealth, AI tools), do you assess its privacy and security risks and keep a written record of that review?
  8. 8 Data location If client information is stored or processed outside Quebec (US cloud, email service, transcription or AI tool), have you completed a privacy impact assessment and signed a written agreement that ensures adequate protection? Do you know where your client information is hosted, and if it is stored or processed outside Canada, are clients informed and are contractual protections in place?
  9. 9 Service providers Do your written contracts with service providers (software, IT support, billing, transcription) require them to protect the information, use it only for the mandate and notify you of any incident? Do your contracts with service providers (software, IT support, billing, transcription) require them to protect the information, use it only for the services provided and notify you of any breach?
  10. 10 Access control Does each person in your clinic have an individual account (no shared passwords), with access limited to what they need and two-factor authentication turned on? Does each person in your clinic have an individual account (no shared passwords), with access limited to what they need and two-factor authentication turned on?
  11. 11 Encryption and communications Are client records encrypted, including on laptops and phones, and do you avoid exchanging health information by regular email or text message? Are client records encrypted, including on laptops and phones, and do you avoid exchanging health information by regular email or text message?
  12. 12 Access logs Can you find out who viewed or modified a client's file, and when? Can you find out who viewed or modified a client's file, and when?
  13. 13 Retention and destruction Do you follow a retention schedule based on your professional order's record-keeping rules, and securely destroy or anonymize files once the retention period has ended? Do you follow a retention schedule based on your regulatory college's record-keeping rules, and securely destroy files once the retention period has ended?
  14. 14 Access and portability requests Can you answer a client's request to access or correct their file within 30 days, and give them their computerized information in a structured, commonly used technological format if they ask? Can you answer a client's request to access or correct their personal information within 30 days?
  15. 15 Training and confidentiality Have all employees, contractors and practitioners signed a confidentiality agreement and received privacy and security training in the past 12 months? Have all employees, contractors and practitioners signed a confidentiality agreement and received privacy and security training in the past 12 months?

What Law 25 Requires From Private Clinics in Quebec

Law 25 came into force in three phases between 2022 and 2024. Every obligation is now in effect, for large clinics as well as for self-employed practitioners. Read more on our Law 25 EHR page.

looks_one

September 2022

  • A person in charge of the protection of personal information, by default the highest authority of the clinic
  • A register of confidentiality incidents
  • Notification of the Commission d'accès à l'information and of the people concerned when there is a risk of serious injury
looks_two

September 2023

  • Governance policies and a privacy policy published on your website
  • Privacy impact assessments, including before communicating information outside Quebec
  • Stricter consent rules and the highest level of confidentiality by default
  • Destruction or anonymization at the end of the retention period
looks_3

September 2024

  • Right to data portability: on request, computerized personal information must be provided in a structured, commonly used technological format
public

Outside Quebec: PIPEDA and Provincial Laws

PIPEDA applies to private clinics that collect personal information in the course of commercial activities, unless a substantially similar provincial law applies. Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador have health information laws for custodians, and Alberta and British Columbia have their own private-sector laws.

They all rely on the same principles: accountability, consent, limited collection and retention, safeguards, openness, individual access and breach reporting. PIPEDA compliant software.

gavel

What Is at Stake

Under Law 25, the Commission d'accès à l'information can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, and penal fines can reach $25 million or 4%. Under PIPEDA, knowingly failing to report a breach or to keep breach records can lead to fines of up to $100,000.

For a clinic, the first risk remains the loss of client trust after an incident, and a complaint to your professional order.

How Colib Helps You Close the Gaps

Several points of this checklist depend directly on your clinic software. Colib was built in Canada with privacy in mind.

cloud_done

Hosted in Canada, Encrypted

Client information is encrypted and hosted in Canada, which simplifies your assessment of communications outside Quebec or outside Canada. See our security page.

verified_user

Individual Accounts and Two-Factor Authentication

Each user has their own account protected by two-factor authentication, and access to client files is logged.

forum

Consent Forms and Secure Portal

Send consent forms that clients sign online and replace email with a secure client portal.

Law 25 and PIPEDA for clinics -- frequently asked questions

Does Law 25 apply to a solo practitioner?

Yes. Law 25 applies to every enterprise that collects personal information in Quebec, including self-employed professionals and small clinics. There is no size exemption.

Who is the person in charge of the protection of personal information?

By default, it is the person with the highest authority in the enterprise: for a solo practitioner, it is you. The function can be delegated in writing, in whole or in part, and the title and contact information must be published on the website.

What counts as a confidentiality incident?

Any unauthorized access, use or communication of personal information, or its loss. A stolen laptop, an email sent to the wrong client or a ransomware attack are all incidents that must be recorded in the register.

Does client data have to be hosted in Canada?

Law 25 does not prohibit hosting outside Quebec, but it requires a privacy impact assessment and a written agreement before communicating information outside the province. Choosing software hosted in Canada makes that assessment much simpler.

Does PIPEDA apply to my clinic outside Quebec?

PIPEDA applies to private clinics engaged in commercial activities, except where a substantially similar provincial law applies, such as PHIPA for health information custodians in Ontario or PIPA in Alberta and British Columbia.

Is this checklist legal advice?

No. It is a self-assessment tool that helps you identify gaps and prioritize your work. For your specific situation, consult a lawyer or your professional order or regulatory college.

Make Compliance the Default in Your Clinic

Encrypted records hosted in Canada, two-factor authentication, online consent forms and a secure client portal. Start your 30-day free trial -- no credit card required.