A therapist working at a laptop beside a bright office window, where the client email that Alberta PIPA and the CAP standard govern gets written and sent

Alberta therapist email encryption: PIPA, CAP, HIA

Gabriel Borges14 min read

If you searched for HIA email requirements and landed here, start with the part most Alberta guidance gets wrong. You’re probably not a custodian under the Health Information Act.

Custodian status under HIA runs through the definition at s.1(1)(f), which depends on a designation list in the Health Information Regulation (AR 70/2001) s.2. Private practice psychologists, social workers and counselling therapists aren’t on that list. They never were.

What governs your client email in Alberta is the Personal Information Protection Act (PIPA), which reaches you as an organization, plus whatever your college’s standards add on top. HIA has a place in this article, but a small one: who it actually covers, and the two narrow routes by which it can still reach someone in private practice.

That correction changes the answer to almost every question that follows.

What actually binds you

What actually binds you
InstrumentApplies to you?What it asks for
Alberta PIPAYes, as an organizationReasonable security arrangements (s.34), breach notice to the Commissioner (s.34.1), access within 45 days (s.28(1)(a))
College of Alberta Psychologists (CAP) Standards of PracticeOnly if you’re a registered or provisional psychologistNamed safeguards for electronic client records (7.6), written consent for release of information (12.3)
Alberta College of Social Workers (ACSW) Standards of PracticeOnly if you’re a registered social workerYour college’s own record and confidentiality standards
Alberta HIAOnly as a custodian’s affiliate, or under an information manager agreement (s.66)Not your baseline obligation in private practice
PIPEDADisplaced for commercial activity inside AlbertaPIPA is designated substantially similar

Where HIA does reach a therapist in Alberta

Two routes, both narrow. You work as an affiliate inside an organization that is itself a custodian, such as a hospital or a physician led clinic. Or you’ve signed an information manager agreement under HIA s.66 with a custodian, which is a contract, not a status you acquire by treating clients.

Neither describes a solo private practice billing clients directly. If you want the longer version of that boundary, we’ve written it up separately in the Alberta HIA therapist email requirements guide.

What Alberta PIPA says about security

Section 34 is the whole of your statutory security duty. Here it is, complete:

An organization must protect personal information that is in its custody or under its control by making reasonable security arrangements against such risks as unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction.

One sentence. The operative phrase is “reasonable security arrangements,” and the Act doesn’t define what counts.

The word “encrypt” appears in PIPA zero times

Search the full text of the Act, the King’s Printer consolidation current to September 1, 2025, and you get no matches. Not “encrypt,” not “encryption,” not “encrypted.” Nowhere in the statute.

So any page telling you Alberta PIPA requires encrypted email is describing something the legislature didn’t write. The duty is reasonable arrangements measured against the risk. Encryption is how you meet that duty for email in practice, which is a different claim, and a defensible one.

Why does the distinction matter to you rather than to a lawyer? Because “reasonable” gets assessed after something has gone wrong, against what you actually did. A named rule is easier to satisfy than a standard you have to argue you met. Alberta hands you the standard and leaves the rest open.

Where the word encryption does appear

There is a document that says it, and it isn’t the statute. If you’re a registered psychologist, CAP’s Standards of Practice, dated May 31, 2023, sets out safeguards for electronic client records at 7.6:

A psychologist who uses an electronic client record shall ensure the electronic record has safeguards that protect the security and confidentiality of information, including, but not limited to, the following:

Nine items follow. The second one is the reason this piece exists: “appropriate password and encryption controls are used.”

The full list:

  • 7.6.1 only authorized users can access individually identifiable information
  • 7.6.2 appropriate password and encryption controls are used
  • 7.6.3 users can be uniquely identified
  • 7.6.4 users have documented access levels based on their role
  • 7.6.5 audit logging is enabled and meets the requirements of applicable legislation
  • 7.6.6 information is securely transmitted
  • 7.6.7 data integrity is protected, and secure back-up and access protocols are in place
  • 7.6.8 users can be authenticated where electronic signatures are permitted
  • 7.6.9 electronic data is disposed of in a secure manner, disallowing reconstruction

Read the scope before you read the list

The qualifiers do more work here than the list does.

The first is “including, but not limited to.” Those nine items are a floor. Working through them doesn’t finish the job, and CAP wrote the standard so that it couldn’t.

The second is that 7.6 governs the electronic client record. It isn’t a rule about email as such. Where an email exchange forms part of the client record 7.6 reaches it, and where it doesn’t, you’re back on PIPA s.34 and its reasonableness test.

Our fuller walkthrough of CAP practice standards and what they ask of therapist email goes through the record keeping standards clause by clause.

The technology guideline says less than you’d expect

CAP’s Use of Technology practice guideline, approved September 1, 2024, is the document therapists assume covers this ground. It mostly doesn’t.

The word “encryption” appears in it exactly once, in the section on social media: “Psychologists use encryption when sending protected and private information over social media when feasible.” That’s the whole of it. There’s no email encryption clause anywhere in the document.

It also isn’t a Standard of Practice. CAP labels it a Practice Guideline and describes its purpose as helping psychologists, which is a different instrument from the one that sets the bar.

So the honest version is narrow, and worth stating precisely. CAP names encryption once as a standard, scoped to electronic client records, inside a list it declares non exhaustive, in a document separate from the technology guideline. Anyone writing “CAP requires encrypted email” has skipped every qualifier that matters.

Which college standard binds you

Which college standard binds you
If you’reYour regulatorStatusWhere the record security wording sits
Psychologist or provisional psychologistCollege of Alberta Psychologists (CAP)RegulatedCAP Standards of Practice (2023) 7.6
Registered social workerAlberta College of Social Workers (ACSW)RegulatedACSW Standards of Practice
Counselling therapistNone at presentUnregulatedNo college standard applies right now

The counselling therapist row is the one people get wrong in both directions. Counselling therapy in Alberta is currently unregulated. The standalone college path under the Mental Health Services Protection Act was deprioritized in September 2021, and the province’s March 2024 announcement that CAP would take on the profession has stalled pending funding.

Membership in the Association of Counselling Therapy of Alberta stays voluntary in the meantime. We track that file in CAP and counselling therapist regulation in Alberta.

Here’s what that doesn’t mean. No college standard is not the same as no obligation. PIPA binds organizations, not professions, so s.34 applies to a counselling therapist’s client email exactly as it applies to a psychologist’s.

What Alberta expects that Ontario doesn’t

What Alberta expects that Ontario doesn’t
Alberta private practice (PIPA)Ontario custodian (PHIPA)
Are you a custodian of health information?No, you’re an organizationYes
Implied consent inside a circle of careNot availableAvailable (s.20 to s.22)
Lock box or consent directiveNo mechanism existsFormal consent directive (s.37(1)(a), s.38(1)(a), s.50(1)(e))
Must express consent be written?Not under the statuteNot required in writing (s.18)
Breach notice triggerReal risk of significant harm (s.34.1)Any unauthorized access (s.12)
Breach notice timingWithout unreasonable delayAt the first reasonable opportunity
Administrative monetary penaltiesNot available in AlbertaAvailable to the Information and Privacy Commissioner of Ontario since January 1, 2024
Statutory maximum fines$10,000 individual, $100,000 organization (PIPA s.59(2))$200,000 individual, $1,000,000 organization (PHIPA s.72(2))
Data residency mandateNoneNone

If you also see clients in other provinces, the cross provincial comparison of PHIPA, HIA and BC PIPA sets out the rest of the differences.

No circle of care in Alberta means no implied consent for sharing with another provider. Consent is per purpose, and sharing with a third party takes express consent.

PIPA doesn’t require that express consent be in writing. CAP does, for release of information: Standards of Practice 12.3 asks for informed, written, signed and dated consent before a psychologist discloses confidential information to anyone other than the client, stipulating what’s released, to whom, and for how long.

So the practical bar for an Alberta psychologist is written consent, and it arrives through the college rather than the statute. That pattern repeats across this whole topic.

How to set up client email that meets the Alberta bar

  1. Confirm which rules actually bind you. Write down two things: the statute and the college standard. The statute is PIPA. The college standard depends on your registration, and for counselling therapists there currently isn’t one.
  2. Test what your email does when TLS isn’t available. Standard Gmail uses opportunistic transport encryption. It encrypts when the receiving server supports it and sends in the clear when it doesn’t. Send a test to an address on a server without TLS and watch what happens. The failure mode is silent, which is why most therapists have never seen it.
  3. Put a fallback in place for the sends that fail. Decide in advance what happens when transport encryption is unavailable. The two workable answers are a secure portal the recipient logs into, or a hard block that refuses to send in the clear. Doing nothing means the message goes out unprotected and you learn about it later, or never.
  4. Map your setup against CAP 7.6 if you’re a psychologist. Take the nine items above one at a time against what you actually run. Access control, password and encryption controls, unique user identification, documented role based access levels, audit logging, secure transmission, data integrity with secure backup, authentication for electronic signatures, secure disposal. Then remember the list is a floor.
  5. Get consent for email as a channel, per purpose. There’s no circle of care to fall back on in Alberta. For psychologists, CAP 12.3 sets the written consent bar for release of information, and CAP Standards 3.5.5 asks that informed consent cover how communication will happen between you, the client, and third parties.
  6. Keep a record of what you decided and why. A dated note of what you evaluated, what you chose and what you rejected is the difference between showing your reasoning and reconstructing it under pressure. A per send log of which messages went out encrypted is stronger again.
  7. Write the breach steps down before you need them. Draft the notice template and the decision checklist now. Nobody writes a clear decision tree during an incident.

What happens when something goes wrong

Alberta’s breach duty runs through PIPA s.34.1(1), which reads:

An organization having personal information under its control must, without unreasonable delay, provide notice to the Commissioner of any incident involving the loss of or unauthorized access to or disclosure of the personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual as a result of the loss or unauthorized access or disclosure.

Notice goes to the Office of the Information and Privacy Commissioner of Alberta, and s.34.1(2) requires it to include what the regulations prescribe.

Individual notice isn’t automatic

It works differently than most therapists assume. Under s.37.1(1), the Commissioner may require you to notify the individuals at real risk of significant harm, in the form the regulations prescribe and within a time the Commissioner sets. It isn’t automatic, and it isn’t yours to decide. Where the risk is obvious and immediate, s.37.1(3) requires the Commissioner to run an expedited process.

The statutory maximums under PIPA s.59(2) are a fine of not more than $10,000 for an individual and not more than $100,000 for a person other than an individual. Those are the same ceilings BC sets, and they sit well below Ontario’s.

Lower ceiling, different instrument. Alberta’s Commissioner works through order making power under PIPA, and the province doesn’t have an administrative monetary penalty regime of the kind Ontario’s Commissioner has held since January 1, 2024. What that changes is the shape of the consequence, not whether one arrives.

What none of this fixes

Encryption isn’t compliance. It’s one item in a list of nine, in a standard that says the nine aren’t the whole list, layered on a statute that doesn’t name it at all.

Four things a well encrypted mailbox still leaves open:

  • Retention. CAP Standards of Practice 7.4 sets ten years after the last professional service for an adult client, and 7.3 sets a longer clock for minors: two years past the age of majority, or ten years after the last service, whichever is longer. Where email forms part of the record, it inherits that.
  • Access requests. PIPA gives you 45 days under s.28(1)(a), extendable by 30 more under s.31(1) and beyond that only with the Commissioner’s permission. Non response counts as a refusal under s.28(2.1). If client email lives in a mailbox you can’t search or export cleanly, a 45 day clock is a real problem.
  • Canadian hosting. Alberta has no data residency mandate. Cross border transfer is permitted, and Canadian hosting is a preference rather than a requirement. Anyone selling it to you as Alberta law is wrong.
  • Everything that isn’t email. Your video sessions, your notes, your booking system and your backups all sit under the same s.34 duty.

There’s also a question this piece can’t answer for you. If you’re a registered social worker, the wording above is CAP’s, and it doesn’t transfer. Check the ACSW Standards of Practice directly rather than assuming your obligations mirror a psychologist’s.

Where this leaves you

The precise version of the Alberta answer is short. PIPA asks for reasonable security arrangements and never says encryption. CAP names encryption once as a standard, for electronic client records, in a list that’s expressly a floor.

The technology guideline names it once, for social media. And HIA, the statute that brought most readers to this page, doesn’t reach a private practice therapist unless one of those two narrow routes applies.

What follows from that is practical rather than legal. Because Alberta gives you a standard instead of a rule, what you can show becomes the thing that matters: which safeguards you chose, when, and what each message actually did on the way out.

If you’re weighing setups rather than just requirements, the email options open to a Canadian therapist compares the realistic ones side by side, including where the Canadian hosted services beat a Gmail based setup.


Curio encrypts your existing Gmail for Canadian mental health privacy law and logs every send in a Canadian audit trail, with no migration and no second inbox to check. Join the waitlist.

Sources


Regulatory content disclaimer: This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.

Product disclaimer: Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook