A therapist takes notes on a tablet during a counselling session with a client, representing an Ontario therapist weighing how AI and digital tools handle client health data under PHIPA

AI and client health data under PHIPA in Ontario

Gabriel Borges19 min read

Updated

Sometime in the last year, an AI note-taker probably showed up in your practice. Maybe it came built into your video software. Maybe a colleague swore by the one that joins the session, transcribes it, and hands you a tidy summary before your next client sits down.

In January 2026, Ontario’s Information and Privacy Commissioner (IPC) put out guidance on exactly this: AI scribes in the health sector. The worry it addresses is the one you’ve probably already felt. When an AI tool listens in on a therapy session, where does that recording go, and did your client agree to any of it?

Here’s the short version, and the rest of this piece is the long one. Where an outside AI tool isn’t acting as your agent, handing it client health information is a disclosure to someone who isn’t a health information custodian, and PHIPA s.18(3)(a) says that consent “must be express, and not implied.” What PHIPA never says is that the consent has to be in writing. Documenting it is how you prove you asked, not a form the statute imposes. The IPC’s new guidance is a reminder that the regulator is paying attention to how these tools land in real practices. If you want the base layer this builds on, our PHIPA email requirements guide for therapists covers the ground-level rules first.

Key takeaways

  • Implied consent within a client’s circle of care does not stretch to cover an outside AI tool. Where using the tool discloses personal health information to a vendor that isn’t a health information custodian, PHIPA s.18(3)(a) requires the consent to be express and not implied. PHIPA nowhere requires it to be in writing: consent must be knowledgeable (s.18(1)), and documenting it is your evidence, not a statutory form.
  • In January 2026 the IPC published guidance and a checklist on AI scribes for the health sector, centred on governance, accountability, and protecting personal health information. The guidance is specifically about AI scribes, not a blanket ruling on every AI tool.
  • Ontario solo psychotherapists are health information custodians under PHIPA. The accountability for how an AI tool handles client information sits with you, not with the software vendor.
  • PHIPA does not ban training AI on client data. What it asks for is knowledgeable consent and proper governance, which is a higher bar than most consumer AI tools meet out of the box, but it is consent, not prohibition.
  • An AI tool hosted outside Canada is allowed. PHIPA sets no Canadian data residency rule, but s.50(1)(a) permits disclosure outside Ontario only if the individual consents to it, and where the recipient isn’t a custodian that consent has to be express (s.18(3)(a)). Still no writing requirement, and still your job to be able to show you asked.
  • Curio encrypts your outbound email and logs every send in a Canadian audit trail. It does not manage your AI consent for you, and it won’t claim to.

What did the IPC’s January 2026 AI guidance actually say?

The IPC’s January 2026 guidance is about AI scribes: the tools that record a clinical encounter and generate a note from it. It came out alongside a companion checklist for the health sector and the IPC’s public event on trustworthy AI in health. If you want the primary document, the full AI scribes guidance is published as a PDF.

Read it for what it is. This is the regulator telling health information custodians how to think before they bring an AI scribe into practice, not a new law and not a verdict on any particular product.

An AI scribe is a tool that captures a clinical session, usually by recording audio, and produces a transcript or a summary note using automated speech recognition and a language model. In a therapy context, that means the tool is processing personal health information: what your client said, and what it reveals about their mental health.

The substance, at the level the IPC frames it, is a posture that puts privacy first, built on governance and accountability. Protect the personal health information the tool touches. Reduce the risk of bias and inaccuracies in what the AI produces. And work through a checklist before you develop, buy, or turn on an AI system that handles health data. The guidance sits within a broader set of principles the IPC issued jointly with the Ontario Human Rights Commission.

The IPC and the Ontario Human Rights Commission set out six principles for the responsible use of AI: AI systems should be valid and reliable, safe, privacy protective, human rights affirming, transparent, and accountable.

What did the IPC’s January 2026 AI guidance actually say?
PrincipleWhat it means for a therapist using an AI tool
Valid and reliableThe AI’s output has to be accurate enough to trust in a clinical record. A wrong summary is a wrong note.
SafeThe tool should not create new risks to your client or their information.
Privacy protectivePersonal health information is protected by design, not as an afterthought.
Human rights affirmingThe tool should not encode bias that disadvantages a client.
TransparentYour client should understand that an AI tool is involved and how it works.
AccountableSomeone is answerable for the tool’s use. Under PHIPA, that someone is you.

One honest caveat up front, because it shapes everything below. The guidance names AI scribes specifically. The wider rule, the one that applies whether the tool is a scribe or a chatbot or a summarizer, comes from PHIPA itself. So the guidance is the news hook. The statute is the spine.

Can Ontario therapists use AI tools with client health information?

Yes, with conditions. An Ontario therapist can use an AI tool that processes client personal health information, provided the client has given express consent, it is recorded, and the therapist has met their governance and safeguard obligations under PHIPA. The tool being useful, or popular, does not remove the consent step.

Start with who you are under the law, because it decides how much of this lands on your shoulders. In Ontario, a health care practitioner who provides health care is a health information custodian under PHIPA s.3(1). A solo psychotherapist is a custodian. That is not a technicality. It means the personal health information in your practice is yours to protect, and an agent or service provider you bring in, an AI vendor included, acts under your accountability.

And the information an AI scribe touches is squarely personal health information. Under PHIPA s.4, that category is broad, and it plainly covers mental health information: the content of a session, a diagnosis, the fact that someone is your client at all.

So the question isn’t “am I allowed to use AI?” You are. The question is whether you’ve done the two things PHIPA asks of a custodian who hands client information to a tool: get the right consent, and keep the information protected. The next sections take those one at a time.

Processing personal health information with an AI tool falls outside the consent a client is assumed to have already given for their care. That is why the implied consent you rely on day to day doesn’t reach it, and why, for a tool that isn’t your agent, PHIPA s.18(3)(a) requires the consent to be express rather than implied.

To see why, look at how PHIPA handles ordinary consent. Within a client’s circle of care, the providers involved in that person’s treatment can generally rely on implied consent to share what they need to share (PHIPA s.20 to s.22). That’s what lets you send a referral without a signature for every step. It’s efficient, and clients expect it.

An AI scribe is a different animal. It isn’t a member of the circle of care. It’s a tool, often run by a company your client has never heard of, frequently on servers in another country, sometimes with terms that let the vendor use inputs to improve its own product. A client walking into therapy does not reasonably expect any of that. Implied consent covers what people would assume is happening. It does not cover the surprise.

That’s the gap express consent closes. “Express” means the client actively agrees rather than simply not objecting. Writing it down means there’s a record of what they agreed to. Put plainly: you have to ask, in words your client understands, and you have to be able to show you asked. The statute backs this up. Consent must be knowledgeable (s.18(1)), and while s.18(2) allows consent to be express or implied, it says so expressly “subject to subsection (3)”. Subsection 18(3)(a) then removes the implied option for a disclosure to anyone who isn’t a health information custodian. What no subsection does is require writing. The record is how you evidence the ask, not a box the statute makes you tick.

Consent under PHIPA is also granular by purpose. Consenting to receive therapy is not consenting to have the session fed through an AI tool. Those are separate purposes, and they need separate agreement.

What counts as an AI tool that touches client health data?

Wider than most people picture. It’s tempting to think “AI” means a scribe that records the session, but the same consent logic applies to anything that processes the content of your client’s information through an automated model.

Tools that process personal health information, and therefore fall under the consent rule, include:

  • AI scribes and note-takers that record or transcribe sessions
  • Standalone transcription services fed session audio
  • Chatbots or assistants you paste client details into to draft a note or a letter
  • Summarizing or “smart reply” features that read client email or documents
  • General consumer AI tools, such as a public chatbot, used on real client content

Here’s a concrete one. A therapist turns on an AI note-taker that records the session, sends the audio to a server in the United States, transcribes it, generates a summary, and keeps a copy under the vendor’s terms. Every one of those steps is the processing of personal health information by a third party. Useful tool. Still needs consent, and still needs a look at where the data goes.

Some of these are baked into software you already run. If you’re on Google Workspace, the AI and personalization features are a good example, and they’re framed as the “smart features and personalization” setting, which lets Google use your Workspace data to personalize features across its products. That’s a core service versus personalization question, not a claim that Google trains its foundation models on your client email. We walk through which Google Workspace AI features therapists should turn off separately, and the Google Workspace PHIPA setup guide covers where those toggles live.

Does PHIPA ban training AI on client health information?

No. PHIPA does not prohibit training or improving an AI model on personal health information. What it asks for is the client’s consent and appropriate governance, and where the vendor isn’t your agent, s.18(3)(a) makes that consent express rather than implied. The obligation is consent and accountability, not an outright ban, and that distinction matters when you read a vendor’s terms.

This one gets stated wrong a lot, usually by people trying to be careful. They’ll say PHIPA forbids letting an AI train on client data. It doesn’t say that. If it did, the answer would be a flat no and you could stop reading.

What the law actually does is put the decision back in the client’s hands and hold you accountable for the arrangement. A vendor can process, and even learn from, personal health information if your client has knowingly agreed to it in writing and the handling is governed properly. The reason so many consumer AI tools fail the test isn’t that training is banned. It’s that their default terms assume a consent your client never gave, for a use your client never saw.

So when you read an AI tool’s terms and find a clause about using inputs to improve the service, that isn’t an automatic disqualification. It’s a flag that says: this needs explicit, informed, written agreement from the person whose information it is, or it needs to be switched off.

What about AI tools hosted outside Canada?

An AI tool hosted outside Canada is permitted. PHIPA imposes no Canadian data residency requirement, so there is no rule that client health data must stay on Canadian servers. Where using the tool sends personal health information across the border, s.50(1)(a) permits the disclosure only if the individual consents to it, and s.18(3)(a) makes that consent express where the recipient isn’t a custodian.

Most AI tools run on infrastructure in the United States or elsewhere, and therapists reasonably wonder whether that alone is a problem. It isn’t. We work through the location question in depth in the Google Workspace data residency guide, and the short answer holds here too: no Canadian province requires private practice therapists to store client information domestically.

What crossing the border does trigger is the consent step, again. Sending session content to a US server so a tool can process it is a cross-border handling of personal health information, and PHIPA wants your client to have agreed to it knowingly. If you see clients in more than one province, the consent rules and college expectations shift, and the PHIPA vs HIA vs BC PIPA therapist guide maps those differences.

Location isn’t nothing. But it’s an input into your safeguard judgment, not the whole question. Encrypted data on a US server is safer than plain-text data anywhere.

If you decide an AI tool earns its place in your practice, the consent doesn’t have to be a legal ordeal. It has to be honest and on the record. Here’s a sequence that meets the PHIPA standard without turning intake into paperwork theatre.

  1. Map what the AI tool does with the session. Before you mention it to a client, find out what it records, where the data goes, whether the vendor uses it to improve its models, and who can access it. You can’t describe the handling to a client if you don’t know it yourself.
  2. Write the consent in plain language. Name the tool, the information it processes (audio, transcript, session content), where that information goes, the purpose, and any transfer outside Canada. PHIPA consent has to be knowledgeable, which means the client genuinely understands what they’re agreeing to.
  3. Ask separately from intake, and record it. Consent under PHIPA is granular by purpose. Give the AI tool its own consent instead of folding it into a general intake form, and keep a written record of it. A separate line the client signs or checks keeps the agreement, and its scope, clear.
  4. Offer a genuine alternative. The client has to be able to say no to the tool and still get care. If declining the note-taker means declining therapy, the consent isn’t real. Keep a manual option ready for anyone who opts out.
  5. Record the consent and honour withdrawal. Log that consent was given, when, and for what. A client can withdraw consent, or issue a consent directive, at any time, and you stop using the tool for them from that point forward. Withdrawal isn’t retroactive, so it doesn’t undo what was already processed.
  6. Keep the safeguard and the record. Encrypt anything the tool sends by email, and keep a record that the safeguard was running. If a client ever asks how their information was handled, that documentation is the answer.

If you already use a PHIPA and CRPO consent form for email, the AI tool consent slots in as its own section, not a rewrite of the whole thing.

The consequences aren’t hypothetical, and they aren’t small. It’s worth knowing the shape of them, not to scare yourself off good tools, but so the consent step gets the seriousness it deserves.

Under PHIPA, mishandling personal health information is an offence enforced by the Information and Privacy Commissioner of Ontario. An individual convicted can face a fine of up to $200,000 CAD and up to 12 months imprisonment. For an organization, the maximum fine is $1,000,000 CAD. Since January 1, 2024, the IPC can also issue administrative monetary penalties, separate from any prosecution, and it holds order-making power.

Those are the ceilings, not the routine outcome, and most matters never reach them. But the IPC does act, and it publishes what it finds. We broke down one real enforcement decision in what PHIPA’s administrative monetary penalties and Decision 298 mean for your practice, which is a clearer picture of how this plays out than any maximum fine figure.

The quieter cost is the one that shows up first: a client who feels their trust was spent without asking. That’s the thing an AI tool can put at risk faster than any fine.

Where Curio fits

Curio doesn’t sit between you and your AI note-taker, and it won’t pretend to manage that consent for you. What it does is narrower, and you can verify all of it.

Curio encrypts every outbound email automatically and logs every send in a Canadian audit trail, on servers in Montreal, working with the Gmail you already use. When an AI tool generates a client summary and it goes out by email, that message is encrypted, and the send is on the record. The audit trail is the kind of documentation the IPC would ask to see if a client ever questioned how their information was handled.

The consent for the AI tool itself is still yours to get, in writing, using the steps above. Curio covers the email channel and the record. It doesn’t cover the decision to use the tool, and being precise about that boundary is the point.

If you want to see where your current email setup leaves client information exposed, join the Curio waitlist.

What this guidance doesn’t settle

A few honest limits, because AI and privacy law is moving faster than anyone’s guidance.

The IPC’s January 2026 guidance is about AI scribes. It’s a strong signal of how the regulator reads the rules, but it isn’t the whole rulebook, and it isn’t law. PHIPA is the statute; the guidance is the IPC’s read on applying it. Follow both, and don’t stretch the scribes guidance into a general AI ruling it doesn’t claim to be.

Your college has a say too. The College of Registered Psychotherapists of Ontario (CRPO) sets expectations for electronic and technology-assisted practice that sit on top of PHIPA, and its electronic practice standards are worth reading alongside this. If you practise outside Ontario, Alberta’s PIPA and British Columbia’s PIPA set comparable consent and safeguard expectations, mapped in the cross-provincial guide linked above.

This is also a snapshot. AI tools change their terms, their hosting, and their defaults constantly, and the IPC will keep issuing guidance as the technology moves. Before you rely on a vendor’s setting or a specific consent wording, confirm it still reads the way you remember. And when a situation is a close call, one conversation with a privacy lawyer costs less than mishandling a disclosure.

Frequently asked questions

In practice, yes. Implied consent within the circle of care does not cover handing session content to an outside AI tool, so express consent is what holds up before an AI note-taker records or processes a client’s personal health information, and it has to be asked for and documented.

Is an AI scribe PHIPA compliant?

“PHIPA compliant” is not a certification a product can hold. Under PHIPA, the custodian, meaning you, stays accountable for how an agent or service provider handles client information. Whether a given AI scribe is defensible depends on your consent, your safeguards, and your agreement with the vendor, not a badge on the tool.

Can I use ChatGPT or a general AI tool for therapy notes?

Only with the client’s express, recorded consent and a clear picture of where the data goes. General consumer AI tools often send inputs outside Canada and may use them under terms your client never saw. Treat pasting client content into one as a disclosure of personal health information that needs consent first.

No. Implied consent within the circle of care, under PHIPA s.20 to s.22, covers sharing among the providers treating a client. An AI vendor is not part of that circle. Using an AI tool to process personal health information is a separate purpose, and one your client would not assume. Where the vendor isn’t acting as your agent, s.18(3)(a) requires that consent be express and not implied.

Does PHIPA require Canadian data residency for AI tools?

No. PHIPA sets no Canadian data residency requirement, so an AI tool hosted outside Canada is not automatically off-limits. What it asks for is knowledgeable consent to that cross-border disclosure, which in practice means express consent you have recorded, plus reasonable safeguards such as encryption.

Does turning off Google Workspace AI features make my practice compliant?

Turning off the “smart features and personalization” setting limits how Google uses your Workspace data to personalize features. It’s one useful safeguard, not compliance on its own. You still need consent for any AI tool that processes client information and encryption for client email.


This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with the Information and Privacy Commissioner of Ontario and consult a qualified privacy professional for your specific situation.

Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice.

Sources

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook