
Cross provincial telehealth privacy for therapists
Updated
By Gabriel Borges, Curio Health · Reviewed by the Curio compliance team · Published May 21, 2026 · Last updated June 12, 2026
You practice in Ontario. Your new client lives in Calgary. After Friday’s session, you email her a brief summary and a homework worksheet.
Which privacy law just governed that email? PHIPA, because you’re the custodian in Ontario? Alberta’s HIA, because that’s where her PHI now sits on a device? Both?
The pandemic normalized this scenario. The compliance answer didn’t catch up.
There’s no Supreme Court decision squarely on point for private practice therapists doing cross provincial virtual work. What does exist is three different provincial regimes, three different regulators, and three different penalty ceilings. They overlap, but they don’t agree.
This guide walks through the analysis, the scenarios, and a defensible approach you can apply without re-deciding jurisdiction for every client.
Quick answer
- When a therapist in one province treats a client in another, both provinces’ privacy laws can apply. The therapist is a custodian or organization in their own province; the client’s PHI is also subject to the client’s province’s law on the client side.
- Ontario PHIPA, Alberta HIA, and BC PIPA each set their own consent, safeguard, breach, and (in Alberta) PIA obligations.
- The defensible operating model is to apply the higher of the applicable standards across encryption, consent, audit trail, and PIA, rather than re-deciding jurisdiction per client.
- College registration (CRPO, CAP, CHCPBC) is a separate analysis from privacy law and follows its own province by province rules.
For the full provincial comparison, see our PHIPA vs HIA vs BC PIPA guide.
Which law applies to cross provincial email?
The short answer: potentially both. Sometimes three.
The therapist’s province treats the therapist as the regulated party
In Ontario, a registered psychotherapist sending PHI by email is a health information custodian under PHIPA s.3(1), read with the health care practitioner definition in s.2, and is bound by PHIPA’s safeguard, consent, and breach rules. In Alberta, a private practice therapist is not a HIA custodian; the governing privacy law is Alberta PIPA together with college standards, and HIA reaches the therapist only as an affiliate working inside a custodian organization.
In BC, a counselling therapist in private practice is an organization under BC PIPA.
The client’s province has its own claim
The client’s PHI lives on their device, on their email server, in their inbox.
The regulator in the client’s province has historically asserted jurisdiction over PHI of their residents, especially where the therapist is providing services into that province.
Where PIPEDA fits
Then there’s PIPEDA. PIPEDA applies to commercial activity, and where a province’s private sector or health sector law has been designated substantially similar by the Governor in Council, activity within that province is largely carved out of PIPEDA’s reach.
The designated laws relevant here are Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA. The practical effect: provincial law governs PHI handled by therapists in private practice in these provinces, and PIPEDA is not the operative statute in the run of cases. The carve out does not extend to personal information that moves across a border in a commercial transfer, where PIPEDA can still apply.
The federal Privacy Commissioner can still take an interest in interprovincial transfers, but the rules you build to should be provincial. In practice, that means a therapist’s compliance program references the provincial statute first, then notes how PIPEDA aligns with it as a federal backstop. For the narrower question of when PIPEDA is the operative law rather than the backstop, that comparison has its own guide.
Definition: substantially similar designation
A province’s private sector or health sector privacy law is designated “substantially similar” under PIPEDA when the Governor in Council recognizes it, by Order in Council, as equivalent in protection. The designated laws here are Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA. In a Curio context, that means PIPEDA steps back in favour of those laws for therapists in private practice, while still reaching personal information transferred across a border in a commercial transaction.
What no Canadian appellate court has done is resolve the overlap squarely for private practice psychotherapy. IPC Ontario, OIPC Alberta, and OIPC BC have each published guidance on cross border PHI handling and electronic communication.
None of them has issued binding guidance on which provincial statute wins when therapist and client are in different provinces. We’re not going to invent a rule that the regulators themselves haven’t settled.
What you can do is build to the stricter standard and stop asking the question for every email. We get to that below.
Common cross provincial scenarios
Most therapists doing cross provincial work fall into a handful of repeating patterns. Here are the four that come up most often and the laws that apply to each.
Scenario summary
| Therapist location | Client location | Laws that can apply | Stricter requirement to plan around |
|---|---|---|---|
| Ontario | Alberta | PHIPA (binds you) + Alberta PIPA / CAP standards (client side) | Confirm CAP registration or practice permission for the client’s province; a written PIA is prudent risk management, though HIA s.64 binds Alberta custodians, not you. |
| Ontario | British Columbia | PHIPA + BC PIPA | PHIPA’s express instruction (lock box) provisions, ss.37(1)(a), 38(1)(a) and 50(1)(e), are the strictest consent regime of the three. |
| Alberta | Ontario | Alberta PIPA / CAP standards (your side) + PHIPA (client side) | PHIPA “any unauthorized access” breach threshold is lower than HIA’s “risk of harm to an individual” (s.60.1(2)). |
| Any province | Client moves provinces mid course | Therapist’s own province’s law continues to govern the therapist | Re-confirm consent and update audit trail jurisdiction tags. The new province’s statute binds custodians and organizations in that province, not an out of province therapist. |
Ontario therapist, Alberta client
PHIPA names you a custodian. HIA designates a defined list of Alberta providers and organizations as custodians, and it reaches a private practice therapist only as an affiliate working inside one of those custodian organizations. A solo Ontario therapist treating an Alberta client is not an Alberta custodian, so HIA’s custodian duties do not bind you directly. We work this exact situation through end to end, from intake to email, in the Ontario therapist with an Alberta client scenario.
The duty that does follow you across the border comes from college guidance: the requirement to confirm whether you may register or practise in the client’s province, which we cover below. HIA s.64 PIA submission is an Alberta custodian obligation, not one that attaches to an out of province therapist.
If you’re going to maintain Alberta clients on a Gmail based workflow, a written privacy impact assessment is still worth preparing as a risk management step, even though s.64 does not compel you to file one.
Ontario therapist, BC client
BC PIPA applies on the client side. BC has no statutory lock box equivalent and no mandated audit trail.
PHIPA is the stricter standard for both. OIPC BC has published business guidance recommending Canadian hosting for PHI as a strong market expectation.
It’s not a statutory requirement, but it’s a clear regulator signal.
Alberta therapist, Ontario client
PHIPA’s “any unauthorized access” breach threshold is the lower of the two. An unauthorized access that wouldn’t meet HIA’s “risk of harm to an individual” test (s.60.1(2)) can still trigger PHIPA notification to the IPC.
If you’re an Alberta therapist with Ontario clients, build your breach response around the PHIPA threshold.
Client relocates between provinces
This is the one most therapists miss, and it is usually stated backwards. A client who started in Vancouver and relocated to Toronto does not turn your file into a PHIPA matter. PHIPA’s duties attach to Ontario health information custodians, so if you practise in BC, BC PIPA keeps governing you. What changes is practical rather than statutory: consent, records, and the local expectations your client now lives under are all worth revisiting.
Consent documentation should be re-confirmed and any consent directives originally captured under BC PIPA should be re-validated against PHIPA’s lock box framework. The audit trail should reflect the change, and the consent date should be the date of the re-confirmation, not the original onboarding date.
For the full provincial comparison underpinning these scenarios, see the PHIPA vs HIA vs BC PIPA guide.
The “highest standard” approach
You can’t decide jurisdiction once and walk away. You can, however, build your email and consent practice to the strictest of the standards across the three provinces and stop asking the question.
Stacking the requirements
Here’s what “highest standard” looks like when you stack the requirements:
| Operational element | PHIPA (Ontario) | PIPA (Alberta) + CAP | BC PIPA | Highest standard |
|---|---|---|---|---|
| Encryption at rest and in transit | Safeguards duty; CRPO Standard 5.6 names encryption among electronic safeguards | Safeguards duty (Alberta PIPA + CAP standards) | Safeguards duty (BC PIPA, “appropriate safeguards”) | No statute mandates encryption. Treat it as the practical way to meet the safeguards duty in all three provinces. |
| Consent format | Written or oral, ongoing (CRPO Standard 3.4) | Written or oral, ongoing (CAP guideline) | Written or oral, ongoing (BCACC standards) | Express, documented, ongoing. |
| Lock box / consent directive | Supported (PHIPA ss.37(1)(a), 38(1)(a), 50(1)(e)) | Not supported | Not supported | Honour a lock box on request even if the client’s province doesn’t mandate it. |
| Audit trail | Not prescribed; audit capability sits in CRPO Standard 5.6 commentary as an example. Clinical record retention is 10 years under Standard 5.1 | Record keeping expected (Alberta PIPA + CAP standards); immutability not specified | Not statutorily required | Keep an access log and retain clinical records for 10 years. |
| Breach threshold | Any unauthorized access (PHIPA s.12) | Real risk of significant harm; notify the Commissioner without unreasonable delay (Alberta PIPA s.34.1), individuals when the Commissioner requires it (s.37.1). The HIA s.60.1 “risk of harm” test binds custodians, not private practice therapists | No statutory breach duty for private organizations; OIPC BC recommends notice on real risk of significant harm | Notify on any unauthorized access. |
| PIA | Not mandated for the therapist | HIA s.64 binds Alberta custodians, not an out of province therapist; prudent as risk management | Not mandated | Maintain a written PIA as a risk management step. |
| Retention | 10 years (CRPO Standard 5.1) | 10 year minimum (CAP Standards) | Commonly seven years in BC practice guidance | 10 years from end of service. |
| AI processing on PHI | Statute silent on AI; consent rules apply to any disclosure | Statute silent on AI; CAP Use of Technology guideline says avoid giving patient data to AI tools | Statute silent on AI; consent rules apply to any disclosure | Treat AI processing as a disclosure needing consent; follow CAP guidance and keep patient data out of AI tools that lack safeguards. |
| Data residency | Not mandated; transfer allowed with express consent | Not mandated; Canadian hosting recommended | Not mandated; strong market expectation of Canadian hosting | Prefer Canadian hosted infrastructure for compliance data. |
Why this clears the bar
Build your operations to that right hand column and you’ve cleared the bar in every province you might touch. Two practical consequences follow from that choice.
First, you stop making jurisdiction calls for individual emails. A new client books from Halifax tomorrow, and your encryption, consent, audit trail, and PIA are already at the highest standard.
You add the client to your audit trail, confirm consent, and continue. The decision tree shrinks to two steps where it used to be five.
What this looks like in a regulator review
Second, you build defensibly. If a regulator does come asking, your file shows you applied the strictest applicable rule rather than the most convenient one.
Discovery during a college complaint or civil litigation looks different when the documentation shows you over indexed on safeguards.
Bottom line
The highest standard approach is: encrypt every email containing PHI, capture express written consent that supports a lock box on request, maintain an immutable audit trail with 10 year retention, write a PIA as risk management (HIA s.64 itself binds Alberta custodians, not an out of province therapist), and use Canadian hosted compliance infrastructure for audit trail and any portal messages. Keep patient data out of AI tools that lack safeguards, and treat any AI processing as a disclosure needing consent. Honour the lowest breach threshold of the three provinces.
College registration across provincial lines
Privacy law and college regulation are separate analyses. They share the word “compliance,” but they answer different questions.
Privacy law asks what the therapist must do with PHI. College regulation asks whether the therapist is permitted to practise in a given province in the first place. Conflating them is a common error.
Colleges by province
The colleges relevant to psychotherapy are different in each province:
- Ontario. CRPO (College of Registered Psychotherapists of Ontario) regulates Registered Psychotherapists. CPBAO (College of Psychologists and Behaviour Analysts of Ontario) regulates psychologists and behaviour analysts. OCSWSSW regulates social workers. CPSO regulates physicians, including psychiatrists, but not psychotherapists.
- Alberta. CAP (College of Alberta Psychologists) regulates psychologists. Counselling therapists in Alberta remain unregulated; ACTA membership is voluntary, the standalone CCTA path was abandoned, and the province announced in March 2024 that CAP will take on counselling therapist regulation, still pending. ACSW regulates social workers. CPSA regulates physicians.
- British Columbia. BCACC (BC Association of Clinical Counsellors) covers counselling therapists today. CHCPBC (College of Health and Care Professionals of BC) takes over psychotherapy regulation under the HPOA effective November 29, 2027. Until then, psychotherapy is not a regulated health profession in BC in the same sense as Ontario or Alberta.
Registering where you practise
If you practise across provinces, you may need to register with the relevant college in each province where you provide services. The colleges have their own rules about virtual practice, supervised practice, and reciprocal recognition.
Cross-college recognition isn’t a settled framework, and we won’t invent rules that the colleges haven’t published. See our cross college comparison guide for a side by side of CRPO, CAP, and the CHCPBC transition.
Check directly with each college before accepting clients in a new province.
Two questions, two answers
The general principle: if you’re sending email containing PHI to a client in another province, the privacy law of that province likely applies. If you’re providing clinical services to a resident of another province, the college rules of that province likely apply.
Both questions need answers. Neither answers the other.
Practical steps for cross provincial compliance
Here’s the workflow.
Step 1. Identify which provinces your clients are located in
Pull your client list. Add a column for province of residence. If you see clients across three provinces, you’re managing three regulatory regimes whether you’ve documented it or not. Update this list when a client moves.
Step 2. Review the privacy law requirements for each province
For each province represented in your client list, confirm the operational requirements. Encryption, consent format, lock box, audit trail, breach threshold, PIA, retention.
The PHIPA vs HIA vs BC PIPA guide covers the full comparison. For depth in a single province, see the PHIPA email requirements, the HIA email requirements for Alberta therapists, or the BC PIPA email privacy obligations post for your specific case.
For the broader cross provincial overview, see email privacy laws across Canada. If your practice runs on Google Workspace, Google Workspace data regions covers how to set data location for Gmail and Drive content.
Step 3. Apply the highest standard approach
Use the comparison table in this post. For each operational element, identify the strictest of the applicable requirements and build to that.
Document the decision. The documentation matters as much as the practice when a regulator asks why you handled a file the way you did.
Step 4. Use a cross provincial consent addendum for clients in other provinces
A single consent form covering all three provincial regimes is cleaner than three separate forms.
The addendum should name the therapist’s province, the client’s province, and the applicable laws; capture express written consent for electronic communication with PHI; describe the lock box option and how to invoke it; and describe the breach notification commitment using the strictest threshold.
The cross provincial compliance quick start lays out the addendum elements and adapts them to PHIPA, HIA, and BC PIPA.
Step 5. Review college registration requirements for each province you practise in
Distinct from privacy law. Check CRPO, CAP, BCACC/CHCPBC, OCSWSSW, ACSW, BCCSW, or the relevant professional body for your designation.
Some colleges require formal registration to provide services into the province; some recognize practice across provinces under specific conditions. Verify directly before booking a client in a new province.
Step 6. Document your cross provincial compliance approach in your email policy
Put the highest standard decision in writing. The email policy template gives you the structure: scope (which provinces, which clients, which client types), operational rules (encryption, consent, lock box, audit trail, retention, PIA), breach response, and review cadence.
Treat this as a working document. Update it when a client relocates or your practice expands into a new province.
A PIA is worth preparing at this step for any therapist with Alberta clients, as risk management. HIA s.64 imposes the submission duty on Alberta custodians, not on an out of province therapist, so this is prudence rather than a statutory obligation that binds you.
Our privacy impact assessment template gives you a starting structure informed by the OIPC Alberta approach.
FAQ
Which privacy law applies if my client is in another province?
Both your province’s law and your client’s province’s law may apply. Your province treats you as a custodian or organization; your client’s province has historically asserted jurisdiction over PHI of its residents. No Canadian court has resolved the overlap squarely for private practice therapists. The defensible approach is to apply the stricter of the applicable requirements rather than re-decide jurisdiction per email.
Do I need to register with the college in my client’s province?
Possibly. College registration is separate from privacy law and follows each college’s rules. CRPO regulates psychotherapy in Ontario, CAP regulates psychology in Alberta, BCACC currently covers counselling in BC, and CHCPBC takes over psychotherapy regulation in BC on November 29, 2027. Check directly with each college before providing services into a new province.
Can I use the same email setup for all provinces?
Yes, provided the setup meets the highest applicable standard across all your client provinces. None of these laws names encryption; each imposes a safeguards duty, and encryption is the practical way to meet it for health information sent by email. Keeping an access log you don’t rewrite after the fact, plus 10 year retention of clinical records, covers Ontario: CRPO Standard 5.1 sets that retention period, and Standard 5.6 treats audit capability as an example of protecting records rather than a prescribed rule. Express written consent, lock box on request, and a written PIA cover the strictest of the other three operational elements.
What if PIPEDA applies instead of a provincial law?
PIPEDA applies to commercial activity, and provinces with private sector or health sector laws the Governor in Council has designated substantially similar are largely carved out of its reach for activity within the province. Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA all carry that designation, so provincial law governs PHI handled by therapists in private practice in these provinces. Designation does not switch off PIPEDA for personal information that moves across a border in a commercial transfer, so building to the provincial highest standard, with security and accountability over any cross border handling, is the safer footing.
Where Curio fits
You don’t need a product to apply the highest standard. The consent template, the audit trail discipline, and the PIA are doable independently. What’s harder to do by hand is keep encryption automatic on every email and maintain an immutable audit trail that holds up in a college complaint or an OIPC review.
Curio’s compliance infrastructure handles encryption and audit trail for Canadian health privacy law across PHIPA, HIA, and BC PIPA. One setup, every province. Join the waitlist.
Consent documentation and your PIA submission to OIPC Alberta remain your responsibility. Curio does not write either. The product handles the technical safeguards; the clinical and consent layer is yours.
Regulatory content disclaimer. This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body. Product disclaimer. Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.
Coming soon
Gmail encryption, built for Canadian therapists.



