PIPEDA Compliance Checklist for Private Clinics
Answer 15 questions about how your clinic protects client information. You get a PIPEDA compliance score and a prioritized action plan based on the 10 PIPEDA principles, the Privacy Commissioner's guidelines and the privacy laws of your province.
For private clinics outside Quebec
Depending on your province, a provincial law may apply instead of or in addition to PIPEDA, for example PHIPA in Ontario, the Health Information Act or PIPA in Alberta, and PIPA in British Columbia. This checklist covers the obligations these laws have in common.
Is your clinic in Quebec? Take the Law 25 compliance checklist.
Solid foundations
Based on your answers, your clinic already has most of the measures covered by this checklist in place. Close the remaining gaps below and review your practices once a year.
Partially compliant: gaps to close
Several important obligations are only partly covered. Start with the high-priority actions: they carry the most risk for your clients and your practice.
Significant compliance risk
Key obligations appear to be missing. Many of the actions below can be started quickly: tackle the high-priority ones first.
At least one high-priority point is answered No or I don't know: your result stays in the significant risk category until it is addressed.
Your prioritized action plan
-
High priority Accountability Partially in place
Designate a privacy officer, preferably in writing, and make their title and contact information available on your website and in your intake documents.
-
Medium priority Transparency Partially in place
Write down your privacy policies (roles, retention and destruction, complaint handling) and publish a plain-language privacy notice on your website and booking page: what you collect, why, where it is stored and who can access it.
-
Medium priority Inventory and necessity Partially in place
Build a simple inventory: each type of information, why you need it, where it is stored (EHR, email, paper, spreadsheets), who can access it and how long you keep it. Limit collection to what your purposes require and remove unnecessary fields from your forms.
-
High priority Consent Partially in place
Use a written consent form that explains each purpose in plain language, including the right to withdraw consent, ask for consent separately for secondary purposes and keep the signed form in the client file. Check whether your provincial health privacy law allows implied consent within the circle of care.
Colib lets you send consent forms that clients sign online, and files them in the client's chart.
-
Medium priority Minors Partially in place
Write down, for your province, who can consent for a minor or an incapable client, and apply that rule to intake forms and to requests for access to the file.
-
Medium priority Website tracking Partially in place
Install a cookie consent banner that blocks analytics and advertising tags until the visitor opts in, and remove pixels from booking and form pages.
-
High priority Privacy incidents Partially in place
Open a breach record and keep entries for at least 24 months, and write a one-page procedure: contain the breach, assess the real risk of significant harm, report it to the privacy commissioner and notify the people concerned as soon as feasible. Check your provincial health privacy law: PHIPA in Ontario, for example, requires notifying the individual of any theft, loss or unauthorized use.
-
Medium priority Privacy impact assessment Partially in place
Document a privacy and security review for each new system that holds client information, and ask your software vendors for their security documentation. In Alberta, custodians under the Health Information Act must submit a privacy impact assessment to the Information and Privacy Commissioner before implementing a new system.
-
Medium priority Data location Partially in place
List every tool that stores or processes client information and where its data is located. For anything outside Canada, tell clients in your privacy notice and secure contractual protections, or switch to a provider hosted in Canada.
Colib stores client information in Canada.
-
Medium priority Service providers Partially in place
Make sure each service provider that accesses client information is bound by a contract covering confidentiality, security safeguards, limited use, breach notification and destruction at the end of the contract.
-
High priority Access control and logs Partially in place
Give every person an individual account, restrict access to client files by role, turn on two-factor authentication, remove access the day someone leaves, and use a system that logs access to client files so you can review it after any suspected incident.
Colib gives each user their own account with two-factor authentication, and logs access to client files.
-
High priority Encryption and communications Partially in place
Encrypt every device that holds client information (BitLocker, FileVault, phone passcode), keep files in an encrypted EHR rather than on the desktop, and move client exchanges to a secure portal.
Colib encrypts client information and includes a secure client portal with messaging.
-
Medium priority Retention and destruction Partially in place
Write down the retention period required by your regulatory college, schedule a yearly review of closed files and securely destroy or anonymize them once the period has ended, keeping a record of what was destroyed.
-
Medium priority Access and portability requests Partially in place
Write a short procedure for access and correction requests (identity check, legal deadline for your province, reasons for any refusal) and test it on a real file.
-
Medium priority Training and confidentiality Partially in place
Have everyone sign a confidentiality agreement, and hold a short yearly training on privacy, phishing and incident reporting. Keep a record of attendance.
Based on your answers, every point of this checklist is covered. Keep your register, policies and training up to date, and repeat this self-assessment each year.
Close These Gaps Faster With Colib
Colib is a clinic management software and EHR built in Canada. It can help with several technical points of your action plan: encrypted records stored in Canada, individual accounts with two-factor authentication, access logs, online consent forms and a secure client portal. Your policies, consent practices and training remain your responsibility.
- 30-day free trial
- No credit card required
- French and English
This self-assessment is for general information only, is based on the laws in force at the time of writing and does not cover every obligation that may apply to your clinic. It does not constitute legal advice or a certification of compliance. For advice on your situation, consult a lawyer or your professional order or regulatory college.
The 10 PIPEDA Principles, Explained for Clinics
PIPEDA compliance rests on the 10 fair information principles set out in Schedule 1 of the Act. Here is what each principle means in day-to-day practice for a private clinic.
-
Accountability
Designate a person accountable for privacy and make sure your service providers protect the information they handle for you.
-
Identifying purposes
Explain why you collect information, at or before the time of collection.
-
Consent
Obtain meaningful consent. For sensitive information such as health information, express consent is generally expected.
-
Limiting collection
Collect only the information you need for the purposes you identified.
-
Limiting use, disclosure and retention
Use and disclose information only for those purposes, keep it only as long as needed, then destroy or anonymize it securely.
-
Accuracy
Keep client information accurate, complete and up to date for the purposes it is used for.
-
Safeguards
Protect information with physical, organizational and technological measures that match its sensitivity.
-
Openness
Make your privacy policies and practices readily available and easy to understand.
-
Individual access
On request, tell people what information you hold about them, give them access and let them challenge its accuracy.
-
Challenging compliance
Let people raise a concern with your privacy officer, and have a simple process to investigate and answer complaints.
PIPEDA Guidelines and Provincial Privacy Laws
The Office of the Privacy Commissioner of Canada (OPC) publishes guidance that explains how it interprets PIPEDA. For a clinic, these documents are the most useful starting points.
Meaningful Consent
The OPC's guidelines for obtaining meaningful consent ask you to explain, in plain language, what you collect, why, with whom you share it and what the risks are, and to give people clear choices for anything that is not essential.
Breach Reporting and Record-Keeping
Breaches of security safeguards that create a real risk of significant harm must be reported to the OPC and to the individuals concerned as soon as feasible, and a record of every breach must be kept for 24 months.
Processing Across Borders
The OPC's guidelines on processing personal data across borders expect transparency with clients and contractual protections when a service provider stores or processes information outside Canada.
Does PIPEDA Apply to Your Clinic?
PIPEDA applies to private clinics that collect personal information in the course of commercial activities, unless a substantially similar provincial law applies. Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador have health information laws for custodians that replace PIPEDA for health information, other provinces such as Alberta, Manitoba and Saskatchewan also have health information laws, and Alberta and British Columbia have their own private-sector laws.
These laws rely on the same principles. Looking for software that supports them? See our page on PIPEDA compliant software.
Provincial details: electronic medical records in Ontario, EMR in British Columbia, EMR in Alberta and electronic health records in Canada.
PIPEDA vs Law 25: Key Compliance Differences
Both laws share the same foundations, but Law 25 is more prescriptive. This summary is simplified: provincial health information laws may add their own rules.
| Topic | PIPEDA | Law 25 (Quebec) |
|---|---|---|
| Accountable person | An individual designated as accountable, whose identity is made available on request | By default the person with the highest authority; title and contact information published on the website |
| Policies | Privacy policies and practices readily available | Governance policies and a privacy policy published in clear and simple terms |
| Consent | Meaningful consent; express consent generally expected for sensitive information | Manifest, free and enlightened consent, given for specific purposes; express consent for sensitive information |
| Breaches and incidents | Report breaches creating a real risk of significant harm; keep a record of all breaches for 24 months | Notify the CAI and the people concerned when there is a risk of serious injury; keep an incident register |
| Privacy impact assessment | Recommended good practice | Required for new or overhauled information systems and before communicating information outside Quebec |
| Information leaving the jurisdiction | Transparency and contractual protections | Privacy impact assessment and written agreement |
| Access requests | Answer within 30 days, with a possible extension | Answer within 30 days |
| Data portability | No specific right | Right in force since September 2024 for information collected from the person |
Practising in Quebec too? Check your clinic with the Law 25 compliance checklist.
What Is at Stake
Under Law 25, the Commission d'accès à l'information can impose administrative monetary penalties of up to $50,000 for an individual and, for other enterprises, up to $10 million or 2% of worldwide turnover, whichever is greater. Penal fines can reach $100,000 for an individual and $25 million or 4% of worldwide turnover for other enterprises, and are doubled for a subsequent offence. Under PIPEDA, knowingly failing to report a breach, notify affected individuals or keep breach records can lead to fines of up to $100,000.
Beyond Penalties: Client Trust
For a clinic, an incident can also damage client trust and lead to a complaint to your professional order. A yearly self-assessment helps you keep your privacy practices up to date as your clinic, your staff and your software change.
How Colib Helps You Close the Gaps
Several points of this checklist depend on your clinic software. Colib was built in Canada with privacy in mind. Software alone does not make a clinic compliant, but the right tools make the work much easier.
See how Colib supports your obligations on our PIPEDA-compliant software page, and discover our electronic health records software in Canada.
Hosted in Canada, Encrypted
Client information is encrypted and stored in Canada, which simplifies your assessment of communications outside Canada. See our security page.
Individual Accounts and Two-Factor Authentication
Each user has their own account with two-factor authentication, and access to client files is logged.
Consent Forms, Secure Portal and Telehealth
Send consent forms that clients sign online, replace email with a secure client portal and hold sessions with our telehealth software for therapists.
PIPEDA compliance -- frequently asked questions
What are the 10 PIPEDA principles?
Schedule 1 of PIPEDA sets out 10 fair information principles: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance.
Where can I find official PIPEDA guidelines?
The Office of the Privacy Commissioner of Canada publishes guidance for businesses, including guidelines for obtaining meaningful consent, guidance on reporting breaches of security safeguards and guidelines for processing personal data across borders. Provincial commissioners publish their own guidance for provincial laws.
Does PIPEDA apply to my clinic outside Quebec?
PIPEDA applies to private clinics engaged in commercial activities, except where a substantially similar provincial law applies, such as PHIPA for health information custodians in Ontario or PIPA in Alberta and British Columbia.
When must a privacy breach be reported under PIPEDA?
When a breach of security safeguards creates a real risk of significant harm, you must report it to the Office of the Privacy Commissioner of Canada and notify the individuals concerned as soon as feasible. Every breach must be recorded, and the records kept for 24 months.
Does PIPEDA require client data to be stored in Canada?
No. PIPEDA does not prohibit storing information outside Canada, but you remain accountable for it: clients must be informed and contracts must protect the information. Provincial laws may add their own rules. Choosing software that stores data in Canada simplifies your obligations.
What is the difference between PIPEDA and Law 25?
Both laws rest on similar principles, but Law 25 is more prescriptive: it requires published governance policies, privacy impact assessments in specific cases and a right to data portability, and it provides for administrative monetary penalties. Private clinics in Quebec are generally governed by Quebec's private sector law for their activities within the province.
Is this checklist legal advice?
No. It is a self-assessment tool that helps you identify gaps and prioritize your work. For your specific situation, consult a lawyer or your professional order or regulatory college.
Make Compliance the Default in Your Clinic
Encrypted records stored in Canada, two-factor authentication, online consent forms and a secure client portal. Start your 30-day free trial -- no credit card required.