Free tool for private clinics

PIPEDA Compliance Checklist for Private Clinics

Answer 15 questions about how your clinic protects client information. You get a PIPEDA compliance score and a prioritized action plan based on the 10 PIPEDA principles, the Privacy Commissioner's guidelines and the privacy laws of your province.

15 questions About 5 minutes No email required Answers stay in your browser

For private clinics outside Quebec

Depending on your province, a provincial law may apply instead of or in addition to PIPEDA, for example PHIPA in Ontario, the Health Information Act or PIPA in Alberta, and PIPA in British Columbia. This checklist covers the obligations these laws have in common.

Is your clinic in Quebec? Take the Law 25 compliance checklist.

  1. 1 Accountability Have you designated a privacy officer accountable for your clinic's compliance, and can clients easily find their title and contact information?
  2. 2 Transparency Do you have written privacy policies (roles, retention and destruction, complaint handling), and is a clear privacy notice readily available to clients, for example on your website and booking page?
  3. 3 Inventory and necessity Have you listed the personal information your clinic holds (clinical, billing, staff, website), where it is kept and who can access it, and do you collect only what is necessary for your stated purposes?
  4. 4 Consent Do you obtain valid consent for collecting, using and disclosing client information (express consent where required for sensitive health information), documented in their file, with a separate request for any secondary purpose (e.g. research, newsletter, disclosure to a third party)?
  5. 5 Minors For minors and clients who cannot consent, do you check who can give consent under your provincial law and apply the same rule to requests for access to their file?
  6. 6 Website tracking Do you obtain visitors' consent before activating tracking tools on your website (analytics, advertising pixels), and do you avoid sending any health-related data to advertising platforms?
  7. 7 Privacy incidents Do you keep a record of every privacy breach (for at least 24 months) and have a written procedure to report breaches that pose a real risk of significant harm to the privacy commissioner and to the people concerned?
  8. 8 Privacy impact assessment Before adopting new software that handles client information (EHR, online booking, telehealth, AI tools), do you assess its privacy and security risks and keep a written record of that review?
  9. 9 Data location Do you know where your client information is hosted, and if it is stored or processed outside Canada, are clients informed and are contractual protections in place?
  10. 10 Service providers Do your contracts with service providers (software, IT support, billing, transcription) require them to protect the information, use it only for the services provided and notify you of any breach?
  11. 11 Access control and logs Does each person in your clinic have an individual account (no shared passwords), with access limited by role, two-factor authentication, and a log showing who viewed or changed a client file?
  12. 12 Encryption and communications Are client records encrypted, including on laptops and phones, and do you avoid exchanging health information by regular email or text message?
  13. 13 Retention and destruction Do you follow a retention schedule based on your regulatory college's record-keeping rules, and securely destroy or anonymize files once the retention period has ended?
  14. 14 Access and portability requests Can you answer a client's request to access or correct their personal information within the legal deadline (30 days under PIPEDA and PHIPA, 45 days under Alberta's PIPA, 30 business days under British Columbia's PIPA)?
  15. 15 Training and confidentiality Have all employees, contractors and practitioners signed a confidentiality agreement and received privacy and security training in the past 12 months?

The 10 PIPEDA Principles, Explained for Clinics

PIPEDA compliance rests on the 10 fair information principles set out in Schedule 1 of the Act. Here is what each principle means in day-to-day practice for a private clinic.

  1. Accountability

    Designate a person accountable for privacy and make sure your service providers protect the information they handle for you.

  2. Identifying purposes

    Explain why you collect information, at or before the time of collection.

  3. Consent

    Obtain meaningful consent. For sensitive information such as health information, express consent is generally expected.

  4. Limiting collection

    Collect only the information you need for the purposes you identified.

  5. Limiting use, disclosure and retention

    Use and disclose information only for those purposes, keep it only as long as needed, then destroy or anonymize it securely.

  6. Accuracy

    Keep client information accurate, complete and up to date for the purposes it is used for.

  7. Safeguards

    Protect information with physical, organizational and technological measures that match its sensitivity.

  8. Openness

    Make your privacy policies and practices readily available and easy to understand.

  9. Individual access

    On request, tell people what information you hold about them, give them access and let them challenge its accuracy.

  10. Challenging compliance

    Let people raise a concern with your privacy officer, and have a simple process to investigate and answer complaints.

Check My PIPEDA Compliance

PIPEDA Guidelines and Provincial Privacy Laws

The Office of the Privacy Commissioner of Canada (OPC) publishes guidance that explains how it interprets PIPEDA. For a clinic, these documents are the most useful starting points.

how_to_reg

Meaningful Consent

The OPC's guidelines for obtaining meaningful consent ask you to explain, in plain language, what you collect, why, with whom you share it and what the risks are, and to give people clear choices for anything that is not essential.

report

Breach Reporting and Record-Keeping

Breaches of security safeguards that create a real risk of significant harm must be reported to the OPC and to the individuals concerned as soon as feasible, and a record of every breach must be kept for 24 months.

travel_explore

Processing Across Borders

The OPC's guidelines on processing personal data across borders expect transparency with clients and contractual protections when a service provider stores or processes information outside Canada.

Does PIPEDA Apply to Your Clinic?

PIPEDA applies to private clinics that collect personal information in the course of commercial activities, unless a substantially similar provincial law applies. Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador have health information laws for custodians that replace PIPEDA for health information, other provinces such as Alberta, Manitoba and Saskatchewan also have health information laws, and Alberta and British Columbia have their own private-sector laws.

These laws rely on the same principles. Looking for software that supports them? See our page on PIPEDA compliant software.

Provincial details: electronic medical records in Ontario, EMR in British Columbia, EMR in Alberta and electronic health records in Canada.

PIPEDA vs Law 25: Key Compliance Differences

Both laws share the same foundations, but Law 25 is more prescriptive. This summary is simplified: provincial health information laws may add their own rules.

Topic PIPEDA Law 25 (Quebec)
Accountable person An individual designated as accountable, whose identity is made available on request By default the person with the highest authority; title and contact information published on the website
Policies Privacy policies and practices readily available Governance policies and a privacy policy published in clear and simple terms
Consent Meaningful consent; express consent generally expected for sensitive information Manifest, free and enlightened consent, given for specific purposes; express consent for sensitive information
Breaches and incidents Report breaches creating a real risk of significant harm; keep a record of all breaches for 24 months Notify the CAI and the people concerned when there is a risk of serious injury; keep an incident register
Privacy impact assessment Recommended good practice Required for new or overhauled information systems and before communicating information outside Quebec
Information leaving the jurisdiction Transparency and contractual protections Privacy impact assessment and written agreement
Access requests Answer within 30 days, with a possible extension Answer within 30 days
Data portability No specific right Right in force since September 2024 for information collected from the person

Practising in Quebec too? Check your clinic with the Law 25 compliance checklist.

gavel

What Is at Stake

Under Law 25, the Commission d'accès à l'information can impose administrative monetary penalties of up to $50,000 for an individual and, for other enterprises, up to $10 million or 2% of worldwide turnover, whichever is greater. Penal fines can reach $100,000 for an individual and $25 million or 4% of worldwide turnover for other enterprises, and are doubled for a subsequent offence. Under PIPEDA, knowingly failing to report a breach, notify affected individuals or keep breach records can lead to fines of up to $100,000.

handshake

Beyond Penalties: Client Trust

For a clinic, an incident can also damage client trust and lead to a complaint to your professional order. A yearly self-assessment helps you keep your privacy practices up to date as your clinic, your staff and your software change.

How Colib Helps You Close the Gaps

Several points of this checklist depend on your clinic software. Colib was built in Canada with privacy in mind. Software alone does not make a clinic compliant, but the right tools make the work much easier.

See how Colib supports your obligations on our PIPEDA-compliant software page, and discover our electronic health records software in Canada.

cloud_done

Hosted in Canada, Encrypted

Client information is encrypted and stored in Canada, which simplifies your assessment of communications outside Canada. See our security page.

verified_user

Individual Accounts and Two-Factor Authentication

Each user has their own account with two-factor authentication, and access to client files is logged.

forum

Consent Forms, Secure Portal and Telehealth

Send consent forms that clients sign online, replace email with a secure client portal and hold sessions with our telehealth software for therapists.

PIPEDA compliance -- frequently asked questions

What are the 10 PIPEDA principles?

Schedule 1 of PIPEDA sets out 10 fair information principles: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance.

Where can I find official PIPEDA guidelines?

The Office of the Privacy Commissioner of Canada publishes guidance for businesses, including guidelines for obtaining meaningful consent, guidance on reporting breaches of security safeguards and guidelines for processing personal data across borders. Provincial commissioners publish their own guidance for provincial laws.

Does PIPEDA apply to my clinic outside Quebec?

PIPEDA applies to private clinics engaged in commercial activities, except where a substantially similar provincial law applies, such as PHIPA for health information custodians in Ontario or PIPA in Alberta and British Columbia.

When must a privacy breach be reported under PIPEDA?

When a breach of security safeguards creates a real risk of significant harm, you must report it to the Office of the Privacy Commissioner of Canada and notify the individuals concerned as soon as feasible. Every breach must be recorded, and the records kept for 24 months.

Does PIPEDA require client data to be stored in Canada?

No. PIPEDA does not prohibit storing information outside Canada, but you remain accountable for it: clients must be informed and contracts must protect the information. Provincial laws may add their own rules. Choosing software that stores data in Canada simplifies your obligations.

What is the difference between PIPEDA and Law 25?

Both laws rest on similar principles, but Law 25 is more prescriptive: it requires published governance policies, privacy impact assessments in specific cases and a right to data portability, and it provides for administrative monetary penalties. Private clinics in Quebec are generally governed by Quebec's private sector law for their activities within the province.

Is this checklist legal advice?

No. It is a self-assessment tool that helps you identify gaps and prioritize your work. For your specific situation, consult a lawyer or your professional order or regulatory college.

Make Compliance the Default in Your Clinic

Encrypted records stored in Canada, two-factor authentication, online consent forms and a secure client portal. Start your 30-day free trial -- no credit card required.