Canadian provincial law document representing Alberta Health Information Act requirements

Alberta HIA and therapist email: who it covers

Gabriel Borges12 min read

Updated

If you’re a therapist or psychologist practising in Alberta, the law governing your client email is probably not the one you expect. The Health Information Act applies to “custodians” of health information, a designated list that covers physicians, nurses, pharmacists and other named providers. Psychologists and counselling therapists in private practice are not on that list. Their email falls under Alberta’s Personal Information Protection Act (PIPA), with CAP’s standards on top. This guide covers which law applies to your practice, what each one expects for email, where Gmail falls short, and when HIA still reaches you. Ontario runs on a different statute, so if you see clients there too, start with the PHIPA compliance guide for Ontario email.

Who is a “custodian” under HIA?

The Health Information Act defines a custodian under section 1(1)(f) as a list of specific entities (Alberta Health Services, the Minister, hospital operators and others) plus health services providers designated in the Health Information Regulation. The designation list covers professions like physicians, registered nurses, pharmacists, dentists, chiropractors, optometrists, midwives and podiatrists.

Psychologists are not on it. Neither are counselling therapists or social workers.

That changes the picture for a solo practice. If you’re a psychologist regulated by the College of Alberta Psychologists (CAP) running your own practice, HIA’s obligations don’t attach to you personally. Your statute is Alberta PIPA, the province’s private sector privacy law, and CAP’s standards sit on top of it.

HIA still reaches you in two common situations. Work inside a custodian organization (a clinic with physicians, a hospital, AHS) and you’re an affiliate: HIA governs what you do with health information there. Provide a service that handles health information for a custodian and you may be an information manager under HIA s.66, with a written agreement setting the rules.

A note on scope: CAP is set to regulate counselling therapists in Alberta. That expansion changes who answers to CAP’s standards; it does not create custodian status under HIA. A counselling therapist in private practice would still fall under PIPA. For the full picture, read what CAP regulation of counselling therapists in Alberta actually changes.

Ontario’s PHIPA uses a similar concept (“health information custodian”) but draws the line differently: psychotherapists providing health care are custodians there. The contrast matters for therapists who see clients in both provinces, because the statutory definitions aren’t interchangeable.

What HIA requires for email, when it applies

The duties below bind custodians and their affiliates. If your practice runs under Alberta PIPA instead, the parallel obligation is PIPA’s duty to make reasonable security arrangements against unauthorized access, use and disclosure. The practical safeguards land in the same place.

Security safeguards (HIA s.60)

Section 60 of the HIA creates the general duty: custodians must protect health information against theft, loss, unauthorized access, unauthorized copying, tampering, and any other form of unauthorized use or disclosure.

The Health Information Regulation (s.8) specifies how that duty should be met: through administrative, technical, and physical safeguards. For email, this means encryption. The Office of the Information and Privacy Commissioner of Alberta (OIPC) hasn’t published a prescriptive list of encryption standards for email, but the general principle across Canadian health privacy law is that opportunistic TLS alone is unlikely to meet the reasonable safeguard standard when the content is health information.

What reasonable safeguards look like in practice for email:

  • Encryption in transit that doesn’t depend on the recipient’s email provider cooperating. Default TLS is a start, but it isn’t guaranteed.
  • Encryption at rest for stored email containing health information. Standard Gmail storage doesn’t provide per-message encryption that prevents the email provider from accessing the content.
  • Access controls that limit who can read the email to authorized individuals. Strong authentication (two-factor at minimum) on the account that sends and receives health information.

The standard scales with the sensitivity of the information. Health information from therapy sessions is among the most sensitive categories. The OIPC has consistently held that more sensitive information requires stronger safeguards.

Privacy impact assessments (HIA s.64)

Here’s where Alberta diverges from Ontario. Before a custodian starts using any new system that handles health information (including email), section 64 of the HIA requires them to prepare a privacy impact assessment (PIA) and submit it to the OIPC. Not file it for their own records. Submit it.

If you work inside a custodian organization that adopted Google Workspace without submitting a PIA, there may be a gap worth assessing. A private practice under PIPA owes no submission, but a PIA is still the cleanest way to document that you considered the risks.

The OIPC Alberta’s PIA requirements are stricter than Ontario’s in two ways:

  1. Mandatory submission. In Ontario, the IPC recommends PIAs but doesn’t require submission. In Alberta, custodians must submit the completed PIA to the OIPC before implementation.
  2. Review process. The OIPC reviews submitted PIAs; since October 2024 a review ends in a closing letter rather than an acceptance. In Ontario, you complete the PIA for your own records.

We have a privacy impact assessment template that covers the core structure, though it was written for Ontario’s PHIPA framework and will need substantial adaptation for Alberta’s OIPC submission requirements. Alberta’s PIA process requires mandatory submission to the OIPC, analysis of cross border data flows, and addressing Alberta specific risk factors that the Ontario template doesn’t cover. We plan to publish an Alberta specific PIA guide.

Consent under HIA works differently than you might expect if you’re coming from Ontario’s framework. Section 34 sets out the requirements for written or electronic consent to disclosure. Sections 35 and 36 address discretionary disclosure without consent and disclosure of registration information, respectively.

The consent framework is different from PHIPA’s in important ways. HIA doesn’t use a deemed consent model for collection: sections 20 to 22 authorize custodians to collect health information without consent where their conditions are met. Deemed consent through voluntary provision is an Alberta PIPA concept (s.8(2)), and PIPA is the statute most private practices answer to. For disclosure, HIA’s s.34 written or electronic consent applies, as above.

For email specifically, the question is whether sending health information by email falls within the scope of the consent the client provided. HIA doesn’t have an explicit email consent provision. The safe approach is the same as in Ontario: obtain clear authorization before sending health information by email, document that authorization, and make sure the client understands the risks.

The practical point survives the statutory differences: email communication with health information requires explicit attention under either regime. The client must know that email is being used, understand what information will be communicated, and have the opportunity to withdraw consent.

Data handling and retention

CAP’s Standards of Practice require psychologists to retain records for at least 10 years after the last date a professional service was provided. For minors, retention runs to 2 years after the age of majority or 10 years after the last professional service, whichever is longer. The HIA itself doesn’t specify a minimum retention period for clinical records, though s.41 requires custodians to maintain records of disclosures for 10 years following the date of disclosure.

For therapists using Gmail, this means:

  • Don’t delete client emails containing health information before the applicable retention period expires.
  • Have a retention policy that accounts for email records. Gmail’s default behaviour is to keep everything, which satisfies the retention minimum but doesn’t address the disposition requirement.
  • Disposition after retention. When the retention period ends, the general duty under s.60 to protect health information throughout its lifecycle extends to secure destruction. For email, secure destruction means permanently deleting the email and any backups, not just moving it to the trash.

Most therapists don’t have a formal email retention policy. Worth fixing. If you’re using Gmail as part of your practice, building one is part of your obligations under HIA and CAP’s standards.

Is Gmail HIA compliant?

No, not by default. Whether you measure Gmail against HIA s.60 and the Health Information Regulation’s safeguard categories (custodian settings) or against Alberta PIPA’s reasonable safeguards duty (private practice), the default configuration falls short for health information. The analysis parallels what we found for Ontario’s PHIPA.

The specific gaps:

  • Encryption is opportunistic. Gmail’s TLS depends on the recipient’s server. Health information requires reliable encryption, not conditional.
  • No HIA specific agreement from Google. Google offers a HIPAA BAA (US law), but nothing equivalent for Alberta’s HIA. Some practitioners sign the HIPAA BAA for the additional contractual protections it provides, but it’s a US legal instrument and doesn’t address HIA’s requirements. Consult a privacy professional for guidance on appropriate custodian agreements.
  • No PIA submission. Google Workspace doesn’t come with a completed PIA. Custodian organizations are responsible for preparing and submitting their own to the OIPC; a private practice under PIPA owes no submission but still carries the risk assessment.

And Gmail’s admin logs don’t track what health information was sent to whom, which means you have no communication level audit trail.

You can reduce the gaps by configuring admin security settings, disabling AI features, and maintaining manual documentation.

But the core limitations remain.

How HIA compares to Ontario’s PHIPA

If you see clients in both Ontario and Alberta, or if you’re considering expanding your practice across provincial lines, here’s how the two frameworks compare for email:

How HIA compares to Ontario’s PHIPA
RequirementHIA (Alberta custodians)PHIPA (Ontario)
EncryptionReasonable safeguards required under s.60 and Health Information Regulation s.8Reasonable steps under s.12(1), including encryption as a technical safeguard
Consent modelCollection without consent where ss.20 to 22 authorize it; disclosure consent under s.34Express consent is the safe standard for email containing health information
Data residencyNot mandated, but OIPC considers it a factor in PIAsNot mandated, but IPC considers it a risk factor
Privacy Impact AssessmentMandatory PIA with OIPC submission before system implementationRecommended by IPC but not mandatory; no submission required
Breach notifications.60.1: notification to affected individuals as soon as practicables.12(2): notification to individual at first reasonable opportunity
Retention10 years (CAP Standards of Practice; varies by regulatory college)10 years (College of Registered Psychotherapists of Ontario standard; varies by regulatory college)

The practical takeaway: Alberta’s PIA requirement is the biggest difference, and it sits with custodians. If you’re practising in Ontario, you should have a PIA on file but you don’t need to submit it to anyone. In Alberta, the OIPC expects to receive a custodian’s PIA before the system goes live; a private practice under PIPA has no submission duty.

BC’s PIPA adds a third set of requirements for therapists using Gmail, with different rules around cross border data transfers and notification obligations. Our Gmail compliance guide touches on PIPA briefly, but for full BC coverage, see our PIPA guide for therapists.

For a complete comparison of PHIPA, HIA, and PIPA, see our cross provincial overview (coming soon). For a deeper look at how these frameworks will converge as provincial regulation evolves, see our cross provincial comparison hub (coming soon).

CAP’s expansion and what it actually changes

The College of Alberta Psychologists is preparing to regulate counselling therapists in addition to psychologists. That expansion changes professional oversight; it does not change custodian status under HIA. Custodians are designated by regulation, and neither psychologists nor counselling therapists are on the designation list.

For counselling therapists in Alberta who aren’t currently regulated by CAP, this means:

  • CAP’s practice standards would apply to your records, technology use and consent processes.
  • Your privacy statute in private practice stays Alberta PIPA.
  • HIA enters the picture only if you work inside a custodian organization or take on an information manager role for one.

The timeline for this expansion isn’t finalized. For an overview of what CAP’s current practice standards require for email and digital communication, see our guide to CAP practice standards for Alberta therapists.

What to do next

If you’re an Alberta therapist using Google Workspace, start with the admin console security settings guide. The settings are the same regardless of province. Then review the AI features guide to address the consent gap around AI processing.

The one step that’s unique to Alberta: the PIA. If you work in a custodian setting that hasn’t completed and submitted one to the OIPC, that’s the gap with the most regulatory exposure. In private practice, a PIA isn’t owed to anyone, but completing one is the cleanest way to show you took the safeguard duty seriously. Our PIA template covers the structure, though you’ll need to adapt it for Alberta’s framework.

For the encryption and audit trail gaps that remain after configuration, there are a few directions to consider. You could switch to a provider with stronger built in encryption (like ProtonMail), add a third party encryption layer to your current Gmail setup, or explore tools like Curio that aim to add automatic encryption and a Canadian audit trail to your existing workflow. The right approach depends on your practice size, technical comfort, and which gaps carry the most risk for your situation.


This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook