
Alberta therapist email encryption: PIPA, CAP, HIA
If you searched for HIA email requirements and landed here, start with the part most Alberta guidance gets wrong. You’re probably not a custodian under the Health Information Act.
Custodian status under HIA runs through the definition at s.1(1)(f), which depends on a designation list in the Health Information Regulation (AR 70/2001) s.2. Private practice psychologists, social workers and counselling therapists aren’t on that list. They never were.
What governs your client email in Alberta is the Personal Information Protection Act (PIPA), which reaches you as an organization, plus whatever your college’s standards add on top. HIA has a place in this article, but a small one: who it actually covers, and the two narrow routes by which it can still reach someone in private practice.
That correction changes the answer to almost every question that follows.
What actually binds you
| Instrument | Applies to you? | What it asks for |
|---|---|---|
| Alberta PIPA | Yes, as an organization | Reasonable security arrangements (s.34), breach notice to the Commissioner (s.34.1), access within 45 days (s.28(1)(a)) |
| College of Alberta Psychologists (CAP) Standards of Practice | Only if you’re a registered or provisional psychologist | Named safeguards for electronic client records (7.6), written consent for release of information (12.3) |
| Alberta College of Social Workers (ACSW) Standards of Practice | Only if you’re a registered social worker | Your college’s own record and confidentiality standards |
| Alberta HIA | Only as a custodian’s affiliate, or under an information manager agreement (s.66) | Not your baseline obligation in private practice |
| PIPEDA | Displaced for commercial activity inside Alberta | PIPA is designated substantially similar |
Where HIA does reach a therapist in Alberta
Two routes, both narrow. You work as an affiliate inside an organization that is itself a custodian, such as a hospital or a physician led clinic. Or you’ve signed an information manager agreement under HIA s.66 with a custodian, which is a contract, not a status you acquire by treating clients.
Neither describes a solo private practice billing clients directly. If you want the longer version of that boundary, we’ve written it up separately in the Alberta HIA therapist email requirements guide.
What Alberta PIPA says about security
Section 34 is the whole of your statutory security duty. Here it is, complete:
An organization must protect personal information that is in its custody or under its control by making reasonable security arrangements against such risks as unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction.
One sentence. The operative phrase is “reasonable security arrangements,” and the Act doesn’t define what counts.
The word “encrypt” appears in PIPA zero times
Search the full text of the Act, the King’s Printer consolidation current to September 1, 2025, and you get no matches. Not “encrypt,” not “encryption,” not “encrypted.” Nowhere in the statute.
So any page telling you Alberta PIPA requires encrypted email is describing something the legislature didn’t write. The duty is reasonable arrangements measured against the risk. Encryption is how you meet that duty for email in practice, which is a different claim, and a defensible one.
Why does the distinction matter to you rather than to a lawyer? Because “reasonable” gets assessed after something has gone wrong, against what you actually did. A named rule is easier to satisfy than a standard you have to argue you met. Alberta hands you the standard and leaves the rest open.
Where the word encryption does appear
There is a document that says it, and it isn’t the statute. If you’re a registered psychologist, CAP’s Standards of Practice, dated May 31, 2023, sets out safeguards for electronic client records at 7.6:
A psychologist who uses an electronic client record shall ensure the electronic record has safeguards that protect the security and confidentiality of information, including, but not limited to, the following:
Nine items follow. The second one is the reason this piece exists: “appropriate password and encryption controls are used.”
The full list:
- 7.6.1 only authorized users can access individually identifiable information
- 7.6.2 appropriate password and encryption controls are used
- 7.6.3 users can be uniquely identified
- 7.6.4 users have documented access levels based on their role
- 7.6.5 audit logging is enabled and meets the requirements of applicable legislation
- 7.6.6 information is securely transmitted
- 7.6.7 data integrity is protected, and secure back-up and access protocols are in place
- 7.6.8 users can be authenticated where electronic signatures are permitted
- 7.6.9 electronic data is disposed of in a secure manner, disallowing reconstruction
Read the scope before you read the list
The qualifiers do more work here than the list does.
The first is “including, but not limited to.” Those nine items are a floor. Working through them doesn’t finish the job, and CAP wrote the standard so that it couldn’t.
The second is that 7.6 governs the electronic client record. It isn’t a rule about email as such. Where an email exchange forms part of the client record 7.6 reaches it, and where it doesn’t, you’re back on PIPA s.34 and its reasonableness test.
Our fuller walkthrough of CAP practice standards and what they ask of therapist email goes through the record keeping standards clause by clause.
The technology guideline says less than you’d expect
CAP’s Use of Technology practice guideline, approved September 1, 2024, is the document therapists assume covers this ground. It mostly doesn’t.
The word “encryption” appears in it exactly once, in the section on social media: “Psychologists use encryption when sending protected and private information over social media when feasible.” That’s the whole of it. There’s no email encryption clause anywhere in the document.
It also isn’t a Standard of Practice. CAP labels it a Practice Guideline and describes its purpose as helping psychologists, which is a different instrument from the one that sets the bar.
So the honest version is narrow, and worth stating precisely. CAP names encryption once as a standard, scoped to electronic client records, inside a list it declares non exhaustive, in a document separate from the technology guideline. Anyone writing “CAP requires encrypted email” has skipped every qualifier that matters.
Which college standard binds you
| If you’re | Your regulator | Status | Where the record security wording sits |
|---|---|---|---|
| Psychologist or provisional psychologist | College of Alberta Psychologists (CAP) | Regulated | CAP Standards of Practice (2023) 7.6 |
| Registered social worker | Alberta College of Social Workers (ACSW) | Regulated | ACSW Standards of Practice |
| Counselling therapist | None at present | Unregulated | No college standard applies right now |
The counselling therapist row is the one people get wrong in both directions. Counselling therapy in Alberta is currently unregulated. The standalone college path under the Mental Health Services Protection Act was deprioritized in September 2021, and the province’s March 2024 announcement that CAP would take on the profession has stalled pending funding.
Membership in the Association of Counselling Therapy of Alberta stays voluntary in the meantime. We track that file in CAP and counselling therapist regulation in Alberta.
Here’s what that doesn’t mean. No college standard is not the same as no obligation. PIPA binds organizations, not professions, so s.34 applies to a counselling therapist’s client email exactly as it applies to a psychologist’s.
What Alberta expects that Ontario doesn’t
| Alberta private practice (PIPA) | Ontario custodian (PHIPA) | |
|---|---|---|
| Are you a custodian of health information? | No, you’re an organization | Yes |
| Implied consent inside a circle of care | Not available | Available (s.20 to s.22) |
| Lock box or consent directive | No mechanism exists | Formal consent directive (s.37(1)(a), s.38(1)(a), s.50(1)(e)) |
| Must express consent be written? | Not under the statute | Not required in writing (s.18) |
| Breach notice trigger | Real risk of significant harm (s.34.1) | Any unauthorized access (s.12) |
| Breach notice timing | Without unreasonable delay | At the first reasonable opportunity |
| Administrative monetary penalties | Not available in Alberta | Available to the Information and Privacy Commissioner of Ontario since January 1, 2024 |
| Statutory maximum fines | $10,000 individual, $100,000 organization (PIPA s.59(2)) | $200,000 individual, $1,000,000 organization (PHIPA s.72(2)) |
| Data residency mandate | None | None |
If you also see clients in other provinces, the cross provincial comparison of PHIPA, HIA and BC PIPA sets out the rest of the differences.
The consent difference that catches people
No circle of care in Alberta means no implied consent for sharing with another provider. Consent is per purpose, and sharing with a third party takes express consent.
PIPA doesn’t require that express consent be in writing. CAP does, for release of information: Standards of Practice 12.3 asks for informed, written, signed and dated consent before a psychologist discloses confidential information to anyone other than the client, stipulating what’s released, to whom, and for how long.
So the practical bar for an Alberta psychologist is written consent, and it arrives through the college rather than the statute. That pattern repeats across this whole topic.
How to set up client email that meets the Alberta bar
- Confirm which rules actually bind you. Write down two things: the statute and the college standard. The statute is PIPA. The college standard depends on your registration, and for counselling therapists there currently isn’t one.
- Test what your email does when TLS isn’t available. Standard Gmail uses opportunistic transport encryption. It encrypts when the receiving server supports it and sends in the clear when it doesn’t. Send a test to an address on a server without TLS and watch what happens. The failure mode is silent, which is why most therapists have never seen it.
- Put a fallback in place for the sends that fail. Decide in advance what happens when transport encryption is unavailable. The two workable answers are a secure portal the recipient logs into, or a hard block that refuses to send in the clear. Doing nothing means the message goes out unprotected and you learn about it later, or never.
- Map your setup against CAP 7.6 if you’re a psychologist. Take the nine items above one at a time against what you actually run. Access control, password and encryption controls, unique user identification, documented role based access levels, audit logging, secure transmission, data integrity with secure backup, authentication for electronic signatures, secure disposal. Then remember the list is a floor.
- Get consent for email as a channel, per purpose. There’s no circle of care to fall back on in Alberta. For psychologists, CAP 12.3 sets the written consent bar for release of information, and CAP Standards 3.5.5 asks that informed consent cover how communication will happen between you, the client, and third parties.
- Keep a record of what you decided and why. A dated note of what you evaluated, what you chose and what you rejected is the difference between showing your reasoning and reconstructing it under pressure. A per send log of which messages went out encrypted is stronger again.
- Write the breach steps down before you need them. Draft the notice template and the decision checklist now. Nobody writes a clear decision tree during an incident.
What happens when something goes wrong
Alberta’s breach duty runs through PIPA s.34.1(1), which reads:
An organization having personal information under its control must, without unreasonable delay, provide notice to the Commissioner of any incident involving the loss of or unauthorized access to or disclosure of the personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual as a result of the loss or unauthorized access or disclosure.
Notice goes to the Office of the Information and Privacy Commissioner of Alberta, and s.34.1(2) requires it to include what the regulations prescribe.
Individual notice isn’t automatic
It works differently than most therapists assume. Under s.37.1(1), the Commissioner may require you to notify the individuals at real risk of significant harm, in the form the regulations prescribe and within a time the Commissioner sets. It isn’t automatic, and it isn’t yours to decide. Where the risk is obvious and immediate, s.37.1(3) requires the Commissioner to run an expedited process.
The statutory maximums under PIPA s.59(2) are a fine of not more than $10,000 for an individual and not more than $100,000 for a person other than an individual. Those are the same ceilings BC sets, and they sit well below Ontario’s.
Lower ceiling, different instrument. Alberta’s Commissioner works through order making power under PIPA, and the province doesn’t have an administrative monetary penalty regime of the kind Ontario’s Commissioner has held since January 1, 2024. What that changes is the shape of the consequence, not whether one arrives.
What none of this fixes
Encryption isn’t compliance. It’s one item in a list of nine, in a standard that says the nine aren’t the whole list, layered on a statute that doesn’t name it at all.
Four things a well encrypted mailbox still leaves open:
- Retention. CAP Standards of Practice 7.4 sets ten years after the last professional service for an adult client, and 7.3 sets a longer clock for minors: two years past the age of majority, or ten years after the last service, whichever is longer. Where email forms part of the record, it inherits that.
- Access requests. PIPA gives you 45 days under s.28(1)(a), extendable by 30 more under s.31(1) and beyond that only with the Commissioner’s permission. Non response counts as a refusal under s.28(2.1). If client email lives in a mailbox you can’t search or export cleanly, a 45 day clock is a real problem.
- Canadian hosting. Alberta has no data residency mandate. Cross border transfer is permitted, and Canadian hosting is a preference rather than a requirement. Anyone selling it to you as Alberta law is wrong.
- Everything that isn’t email. Your video sessions, your notes, your booking system and your backups all sit under the same s.34 duty.
There’s also a question this piece can’t answer for you. If you’re a registered social worker, the wording above is CAP’s, and it doesn’t transfer. Check the ACSW Standards of Practice directly rather than assuming your obligations mirror a psychologist’s.
Where this leaves you
The precise version of the Alberta answer is short. PIPA asks for reasonable security arrangements and never says encryption. CAP names encryption once as a standard, for electronic client records, in a list that’s expressly a floor.
The technology guideline names it once, for social media. And HIA, the statute that brought most readers to this page, doesn’t reach a private practice therapist unless one of those two narrow routes applies.
What follows from that is practical rather than legal. Because Alberta gives you a standard instead of a rule, what you can show becomes the thing that matters: which safeguards you chose, when, and what each message actually did on the way out.
If you’re weighing setups rather than just requirements, the email options open to a Canadian therapist compares the realistic ones side by side, including where the Canadian hosted services beat a Gmail based setup.
Curio encrypts your existing Gmail for Canadian mental health privacy law and logs every send in a Canadian audit trail, with no migration and no second inbox to check. Join the waitlist.
Sources
- Alberta Personal Information Protection Act, S.A. 2003, c. P-6.5, King’s Printer consolidation current to September 1, 2025. Sections 28, 31, 34, 34.1, 37.1 and 59.
- Alberta PIPA on CanLII, for section level browsing.
- CAP Standards of Practice, May 31, 2023. Sections 3.5.5, 7.3, 7.4, 7.6 and 12.3.
- CAP Use of Technology practice guideline, September 1, 2024.
- Office of the Information and Privacy Commissioner of Alberta.
- ACSW Standards of Practice.
- Ontario Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A, s.72(2), for the Ontario comparison figures.
Regulatory content disclaimer: This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.
Product disclaimer: Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.
Coming soon
Gmail encryption, built for Canadian therapists.



