Open laptop and phone on a wooden desk, the setup a Canadian therapist uses to compare email options

PHIPA compliant email options for therapists

Gabriel Borges19 min read

Updated

  1. No Canadian privacy statute names encryption as a requirement.
  2. All three provinces impose a safeguards duty instead.
  3. Encryption is how you meet that duty for email.
  4. No Canadian law requires client email to stay in Canada.
  5. Four options exist, and they differ more than the marketing suggests.
  6. Hushmail stores data in Canada. A Gmail based setup does not.
  7. Hushmail replaces your inbox. It offers no Gmail plugin.

A PHIPA compliant email service is a marketing phrase, not a legal category. What exists in law is a safeguards duty, an obligation to take steps reasonable in the circumstances to protect personal health information. Products meet that duty to different degrees, and no product discharges it on your behalf.

Key takeaways

  • No Canadian privacy statute names encryption as a requirement. Ontario, Alberta and BC each impose a safeguards duty, and encryption is how you meet it for email.
  • There is no Canadian data residency mandate. Under PHIPA, cross border transfer is permitted with express consent and needs no privacy impact assessment.
  • You have four real options: unencrypted email, a dedicated encrypted service, a US HIPAA product, or keeping your existing inbox and adding encryption to it.
  • Hushmail keeps all its data in Canada. If full Canadian residency is your requirement, a Gmail based setup does not meet it and Hushmail does.
  • Hushmail replaces your inbox. There is no Gmail plugin, and their own guidance is not to add one.
  • Paubox is a US HIPAA product. Its security page makes no reference to Canadian privacy law at all.

A therapist in Ontario asks a reasonable question and gets an unreasonable answer. The question is “what email am I allowed to use with clients?” The answer, from most of the internet, is a product recommendation dressed up as a legal requirement.

This piece is the version without the sales pitch. It starts with what the law actually says, which is less than most people claim, and then walks the four options that are genuinely open to you.

Curio makes one of those options. You’ll see where it wins and where it loses, including one comparison where a competitor is straightforwardly better.

What does Canadian privacy law actually require of therapist email?

It requires safeguards appropriate to the sensitivity of the information. It does not require encryption by name.

That distinction matters more than it sounds. Under PHIPA s.12(1) an Ontario health information custodian must take steps that are reasonable in the circumstances to protect personal health information. Alberta PIPA and BC PIPA impose comparable duties in their own language, and PIPEDA frames it as security appropriate to sensitivity.

Not one of those statutes says the word “encryption” as a mandate. If you go looking for the section number that requires you to encrypt email, you won’t find it, because it isn’t there.

Why encryption is still the answer

What follows from the duty is fairly obvious. Client mental health information is about as sensitive as personal information gets. Sending it across the open internet in plain text is not a reasonable step by any reading.

So encryption is the practical way a therapist meets a safeguards duty for email. That’s why it has become the working expectation even though no statute names it.

Why the distinction is worth holding onto

Be careful with anyone who tells you otherwise. A vendor claiming “PHIPA requires encryption” is overstating the law.

A vendor overstating the law is a vendor to read carefully elsewhere too. It’s a useful filter when you’re comparing products that all sound equally confident.

What your college expects is a separate question

Your regulatory college sets practice standards on top of the statute, and those are where more specific technology expectations tend to live. CRPO in Ontario, CAP in Alberta and CHCPBC in BC each address electronic practice, with different terminology and different levels of detail.

Check your own college’s current standard rather than relying on a summary, including this one. College standards get revised, and they get revised more often than statutes do.

For the statutory layer across provinces, the cross provincial guide covers where PHIPA, Alberta PIPA and BC PIPA diverge.

Does any Canadian law require your client email to stay in Canada?

No. There is no Canadian data residency mandate for therapist email.

Under PHIPA, cross border transfer is permitted, the condition is express consent, and no privacy impact assessment is required for the transfer itself. Alberta and BC likewise impose no residency requirement on private sector organizations.

This one deserves care, because residency is where the marketing gets loudest and the law is quietest.

Where the belief comes from

BC has a public sector storage regime under FOIPPA, and it does not apply to you in private practice. The former FOIPPA s.30.1 requirement was repealed in 2021 in any case.

Don’t let anyone convert a public sector rule into a private practice obligation. It’s the single most common error in this category.

Residency as a preference, not a rule

So residency is not a legal requirement. It’s a risk preference, and a legitimate one.

Some therapists want Canadian storage because it narrows the set of foreign legal processes that could theoretically reach client records. Others because their client population expects it, or because it’s easier to explain to a client who asks.

Those are real reasons. They just aren’t statutory ones.

The practical consequence: if you want Canadian residency, choose for it deliberately. Don’t assume you’re required to have it, and don’t assume a product gives it to you because it sounds Canadian.

What are your real options?

Four, and they’re genuinely different from each other.

What are your real options?
OptionWhat it isWhere it fits
Unencrypted emailYour current inbox, no additional protectionNot defensible for content containing client health information
Dedicated encrypted serviceA separate email service built for healthcare, with its own inboxYou’re willing to change email providers and want one vendor
US HIPAA productEncryption tooling built for the American regulatory regimeYour practice has a specific US connection
Keep your inbox, add encryptionYour existing email, with encryption applied to outbound messagesYou want to keep your address and workflow

The rest of this piece works through the last three. The first isn’t an option so much as the thing you’re trying to stop doing.

Is Hushmail a good fit for a Canadian therapist?

For some therapists, yes, and on one dimension it beats what Curio does. Start there, because it’s the part a comparison written by a competitor tends to bury.

Hushmail keeps its data in Canada. We read their page for Canadian practitioners on July 25, 2026, and the claim is unambiguous: “Our servers are in Canada, which means all your Hushmail data stays in Canada.” They also state their support staff are located in Canada.

That’s a stronger residency position than any Gmail based setup can offer, including Curio’s. If your message content living in Canada is a firm requirement, Hushmail meets it and a Gmail based setup does not.

No amount of framing changes that, and you should weigh it.

What that residency does and doesn’t buy

What it does not do is satisfy a legal requirement, because as covered above, there isn’t one. It satisfies a preference.

Whether that preference is worth what it costs you elsewhere is the actual decision, and it depends on how much your existing inbox is worth to you.

What Hushmail asks of you in exchange

Hushmail is a replacement, not an addition. You move to their service and use their inbox. There is no Hushmail plugin for Gmail, and their healthcare plans page is explicit that you should not try to solve this with a plugin at all: “You will not be able to use the free versions of Gmail or Outlook.”

For a new practice, that’s close to costless. You’re choosing an email provider for the first time and Hushmail is a credible choice.

What migration actually costs you

For an established practice, it’s a migration. Your address changes or has to be redirected, your history sits in the old account, and your intake forms, directory listings and signatures all point at the old address.

None of that is fatal. It’s just work, and it’s work you should price in honestly rather than discover afterward.

Hushmail also says it works “on its own or alongside your EHR,” which is worth noting if your practice management system already handles some client communication.

There’s a longer side by side treatment in the Hushmail and Gmail comparison if you’re weighing those two specifically.

Who Hushmail suits

A therapist starting a practice, or one who has never settled on an email address they care about keeping, and who wants Canadian storage and a single vendor to call. That’s a real profile, and if it’s yours, Hushmail is the straightforward answer.

It suits you less if your address is embedded in a referral network you’ve spent years building, or if you’ve already paid for Google Workspace and use the calendar, documents and video calling that come with it. Leaving email means either running two systems or leaving all of it.

Is Paubox a good fit?

Probably not, and the reason is jurisdictional rather than technical.

Paubox is a serious product. Their security page describes HITRUST CSF certification covering their Encrypted Email, Secure Email API, Email DLP Suite and Inbound Security solutions, and HITRUST is a genuinely demanding standard in the American healthcare market.

The jurisdictional problem

The American healthcare market is what it’s built for. When we read that same security page on July 25, 2026, it contained no reference to PHIPA, to PIPEDA, or to Canada at all. Their compliance posture, documentation and agreements are organized around HIPAA.

HIPAA is not your law. A product engineered against HIPAA may well be secure enough to satisfy your safeguards duty, but it isn’t designed around your consent rules, your breach thresholds, or your provincial regulator.

Its contractual instruments are built for a different statute. You’d be doing the translation work yourself.

There’s a more detailed treatment in the Paubox assessment if you’re evaluating it seriously.

What about keeping your Gmail and adding encryption?

This is the fourth option, and it’s the category Curio is in, so read this section knowing that.

It’s also the category Hushmail argues against directly. Their healthcare page runs a side by side comparison whose left column is this entire approach, with four objections. They’re worth taking seriously and worth answering, so here they are, in their words, with an honest response to each.

“Not cheap, even for a single user ($38–119 / mo.)”

This figure is Hushmail’s estimate for a category, not a quote for any particular setup, and the category it describes spans enterprise grade encryption tooling aimed at large organizations. It isn’t a like for like comparison with a single practitioner adding encryption to an existing Workspace account.

That said, the underlying point survives: you’re paying for two things instead of one. Whether the total is higher than a bundled service depends entirely on which products you’re comparing, and you should do that arithmetic for your own situation rather than trusting either vendor’s version of it.

“Manage an extra layer of tech on top of a professional email”

Partly fair, and it depends on where the layer sits.

If the encryption is something you invoke, a button you remember to press or a subject line tag you have to type, then yes, it’s an extra layer and it will fail on the day you’re rushing between sessions. That’s a real failure mode and it’s the strongest version of Hushmail’s argument.

If the encryption happens at the gateway, applied automatically to outbound mail before it leaves, there’s nothing to manage day to day. The layer exists at setup and then stops asking anything of you. Curio works this way, which is why the product describes itself as compliance you never think about.

So the objection is a good question to ask any product in this category. Ask where the encryption decision is made, and whether you can forget about it.

“Each user in your practice needs to install the plugin separately”

This one doesn’t apply to a gateway based setup. It’s an objection about a different architecture than the one Curio uses.

A plugin genuinely does need per user installation, and in a group practice that’s a real administrative burden plus a real gap when someone new joins and nobody remembers. But a gateway isn’t installed per user at all. It’s configured once for the domain and it applies to mail from every account on it.

If you’re evaluating this category, that’s the distinction to ask about, because the two architectures behave very differently as a practice grows.

“You may find yourself contacting two separate customer support teams”

True, and the mitigation is smaller than it sounds.

You do have two vendors. But one of them is your email provider, which you already have, already pay, and already contact when email breaks. The second relationship is the new one, and it’s scoped to the encryption and compliance layer.

The honest version: for a problem that’s clearly encryption, you know who to call. For a problem that’s ambiguous, you may start in the wrong place. Weigh that against a single vendor relationship where the same team handles everything, which is a genuine convenience Hushmail is right to claim.

What the category actually buys you

Your inbox doesn’t change. Your address doesn’t change. Your history stays where it is, your filters and labels survive, your signature is still right, and every referral source that has your address on file still has a working one.

For an established practice, that’s the whole argument. You’re not being asked to move; you’re being asked to add something to what you already run.

For a new practice with no history to preserve, the argument is much weaker, and a dedicated service deserves a serious look.

What does an audit trail have to do with email?

It’s how you demonstrate the safeguards you took, rather than asserting them.

A safeguards duty is assessed after the fact. If a complaint reaches your college or your provincial Commissioner, the question is what steps were reasonable in the circumstances and whether you took them.

A record of what your setup did, and when, answers that question. A description of what you intended does not.

This is the part of the evaluation that comparisons skip, because it isn’t a feature you notice day to day. You notice encryption when it breaks. You notice an audit trail exactly once, on the worst day of your professional year.

How the conversation actually goes

A client says their partner saw a message they shouldn’t have. A former client requests their records and disputes what was sent. A laptop goes missing.

In each case you’re asked to reconstruct what happened, and the useful answer is a record showing which messages were sent, whether each was encrypted, and when. The breach notification guide covers what you’re obliged to do once you know.

Without a record you’re relying on memory. You’ll say you always encrypt client email, which is probably true, and you’ll have no way to show it for the message in dispute.

Two questions to ask any option

First, does it log every send, or only the ones it encrypted? A log that records successes and stays silent about failures tells you less than you think.

Second, can you retrieve the record yourself, or do you have to ask the vendor? Ontario’s retention expectations run long, and a record you can’t get at is not much of a record.

None of this is exotic. It’s the difference between a tool that protects you and a tool that protects you and can prove it.

What if you’ve already been emailing clients unencrypted?

Stop the ongoing exposure first, then assess whether anything that already happened needs to be reported.

Switching your setup is the straightforward part. The harder question is whether past unencrypted messages constitute a privacy breach that triggers a notification duty, and that depends on your province and on what actually happened to the messages.

A weak safeguard is not the same thing as an incident. Sending email over opportunistic transport encryption is the former. A breach involves unauthorized access, use or disclosure, and “the message might theoretically have been readable in transit” does not on its own meet that description.

What does count as an incident

Something concrete has to have gone wrong. A message went to the wrong recipient, an account was accessed by someone else, or a device was lost with mail cached on it.

Those are events, and events are what notification duties attach to.

The thresholds differ by province

This is one of the places the differences genuinely matter. Ontario’s PHIPA sets a low bar for notifying the individual, at the first reasonable opportunity, with reporting to the Commissioner required in defined circumstances.

Alberta’s PIPA requires notification to the Commissioner where there is a real risk of significant harm, without unreasonable delay. In BC, private sector breach notification under PIPA is voluntary rather than mandatory, though the Commissioner recommends it on a real risk of significant harm.

The cross provincial guide sets the three side by side.

What to do if you’re unsure

If you don’t know whether something crosses the line, that’s a question for a privacy lawyer or your college’s practice advisory service, not for a blog post.

What you can do without advice is close the gap going forward, and document the date you closed it.

That’s also the easier conversation with clients. You don’t need to send an alarming notice about historical practice. You do need your consent discussion to describe what you’re doing now, accurately.

How should you choose?

Work down the questions in order. The first one that gives you a firm answer is the one that decides it.

  1. Does message content have to be stored in Canada? If that’s firm, choose a Canadian hosted service. A Gmail based setup will not satisfy it.
  2. Are you established or starting out? An established practice pays a migration cost that a new practice doesn’t.
  3. Is your encryption automatic or manual? Anything you have to remember will eventually be forgotten.
  4. Does it produce a record? You need to be able to show what you did, not just assert it.
  5. Is it built for Canadian law or translated from American law? The consent rules and breach thresholds differ.

Why question four matters most

A safeguards duty is about steps you took, and “reasonable in the circumstances” gets assessed after something has gone wrong.

Being able to show what your setup did on a given date is a different capability from encryption itself, and not every option provides it.

Frequently asked questions

Is Gmail PHIPA compliant on its own?

No. In its default configuration Gmail does not meet the safeguards expectation for client health information, chiefly because its transport encryption is opportunistic and depends on the receiving server. There’s a full treatment in is Gmail PHIPA compliant.

Does a Google Workspace BAA make my email compliant?

No. A business associate agreement is a contractual instrument from the American HIPAA regime.

It doesn’t substitute for express consent, and it doesn’t discharge your safeguards duty under PHIPA. See what the Google Workspace BAA covers.

You need consent for the communication, and under PHIPA that consent must be knowledgeable, which means the client understands the risk they’re agreeing to. PHIPA prescribes no written form, but it does require express consent for a disclosure to anyone who isn’t a health information custodian (s.18(3)(a)), which is what an AI vendor or an out of province recipient usually is, and it requires consent to a disclosure outside Ontario (s.50(1)(a)). The PHIPA email requirements guide covers the consent mechanics.

What happens if I get this wrong?

Under PHIPA, penalties reach $200,000 for individuals and $1,000,000 for organizations, and administrative monetary penalties have been available to the Information and Privacy Commissioner of Ontario since January 1, 2024. In practice the more common consequence is a complaint to your college or a privacy complaint to the Commissioner, either of which asks you to show what safeguards you had in place.

Can I use one email setup for clients in several provinces?

Yes, if it meets the strictest standard among the provinces you practise into. Your own province’s law governs you; it doesn’t switch based on where your client currently lives. The cross provincial guide sets out the differences.

Where this leaves you

There’s no single correct answer, which is why a page claiming one should be treated with suspicion.

If Canadian storage of message content is your firm requirement, choose a Canadian hosted service and accept the migration. If you’re building a practice from scratch, a dedicated service is the cleaner path.

If you have an established practice and an address your referral network has on file, adding encryption to what you already run will cost you less disruption.

What no tool does

None of these options makes you compliant. Compliance is a set of practices, and email is one part of it. Your college’s electronic practice standards cover the rest of that surface.

What the right tool does is stop email from being the weak part, and stop you from having to think about it.


Curio encrypts your existing Gmail for Canadian mental health privacy law and keeps a Canadian audit trail of every send, with no migration and no new inbox to learn. Join the waitlist.


Product disclaimer: Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.

Regulatory content disclaimer: This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook