Shield with check mark representing layered privacy safeguards across provinces

Cross provincial telehealth privacy for therapists

Gabriel Borges18 min read

Updated

By Gabriel Borges, Curio Health · Reviewed by the Curio compliance team · Published May 21, 2026 · Last updated June 12, 2026

You practice in Ontario. Your new client lives in Calgary. After Friday’s session, you email her a brief summary and a homework worksheet.

Which privacy law just governed that email? PHIPA, because you’re the custodian in Ontario? Alberta’s HIA, because that’s where her PHI now sits on a device? Both?

The pandemic normalized this scenario. The compliance answer didn’t catch up.

There’s no Supreme Court decision squarely on point for private practice therapists doing cross provincial virtual work. What does exist is three different provincial regimes, three different regulators, and three different penalty ceilings. They overlap, but they don’t agree.

This guide walks through the analysis, the scenarios, and a defensible approach you can apply without re-deciding jurisdiction for every client.

Quick answer

  • When a therapist in one province treats a client in another, both provinces’ privacy laws can apply. The therapist is a custodian or organization in their own province; the client’s PHI is also subject to the client’s province’s law on the client side.
  • Ontario PHIPA, Alberta HIA, and BC PIPA each set their own consent, safeguard, breach, and (in Alberta) PIA obligations.
  • The defensible operating model is to apply the higher of the applicable standards across encryption, consent, audit trail, and PIA, rather than re-deciding jurisdiction per client.
  • College registration (CRPO, CAP, CHCPBC) is a separate analysis from privacy law and follows its own province by province rules.

For the full provincial comparison, see our PHIPA vs HIA vs BC PIPA guide.

Which law applies to cross provincial email?

The short answer: potentially both. Sometimes three.

The therapist’s province treats the therapist as the regulated party

In Ontario, a registered psychotherapist sending PHI by email is a health information custodian under PHIPA s.3(1), read with the health care practitioner definition in s.2, and is bound by PHIPA’s safeguard, consent, and breach rules. In Alberta, a private practice therapist is not a HIA custodian; the governing privacy law is Alberta PIPA together with college standards, and HIA reaches the therapist only as an affiliate working inside a custodian organization.

In BC, a counselling therapist in private practice is an organization under BC PIPA.

The client’s province has its own claim

The client’s PHI lives on their device, on their email server, in their inbox.

The regulator in the client’s province has historically asserted jurisdiction over PHI of their residents, especially where the therapist is providing services into that province.

Where PIPEDA fits

Then there’s PIPEDA. PIPEDA applies to commercial activity, and where a province’s private sector or health sector law has been designated substantially similar by the Governor in Council, activity within that province is largely carved out of PIPEDA’s reach.

The designated laws relevant here are Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA. The practical effect: provincial law governs PHI handled by therapists in private practice in these provinces, and PIPEDA is not the operative statute in the run of cases. The carve out does not extend to personal information that moves across a border in a commercial transfer, where PIPEDA can still apply.

The federal Privacy Commissioner can still take an interest in interprovincial transfers, but the rules you build to should be provincial. In practice, that means a therapist’s compliance program references the provincial statute first, then notes how PIPEDA aligns with it as a federal backstop. For the narrower question of when PIPEDA is the operative law rather than the backstop, that comparison has its own guide.

Definition: substantially similar designation

A province’s private sector or health sector privacy law is designated “substantially similar” under PIPEDA when the Governor in Council recognizes it, by Order in Council, as equivalent in protection. The designated laws here are Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA. In a Curio context, that means PIPEDA steps back in favour of those laws for therapists in private practice, while still reaching personal information transferred across a border in a commercial transaction.

What no Canadian appellate court has done is resolve the overlap squarely for private practice psychotherapy. IPC Ontario, OIPC Alberta, and OIPC BC have each published guidance on cross border PHI handling and electronic communication.

None of them has issued binding guidance on which provincial statute wins when therapist and client are in different provinces. We’re not going to invent a rule that the regulators themselves haven’t settled.

What you can do is build to the stricter standard and stop asking the question for every email. We get to that below.

Common cross provincial scenarios

Most therapists doing cross provincial work fall into a handful of repeating patterns. Here are the four that come up most often and the laws that apply to each.

Scenario summary

Scenario summary
Therapist locationClient locationLaws that can applyStricter requirement to plan around
OntarioAlbertaPHIPA (binds you) + Alberta PIPA / CAP standards (client side)Confirm CAP registration or practice permission for the client’s province; a written PIA is prudent risk management, though HIA s.64 binds Alberta custodians, not you.
OntarioBritish ColumbiaPHIPA + BC PIPAPHIPA’s express instruction (lock box) provisions, ss.37(1)(a), 38(1)(a) and 50(1)(e), are the strictest consent regime of the three.
AlbertaOntarioAlberta PIPA / CAP standards (your side) + PHIPA (client side)PHIPA “any unauthorized access” breach threshold is lower than HIA’s “risk of harm to an individual” (s.60.1(2)).
Any provinceClient moves provinces mid courseTherapist’s own province’s law continues to govern the therapistRe-confirm consent and update audit trail jurisdiction tags. The new province’s statute binds custodians and organizations in that province, not an out of province therapist.

Ontario therapist, Alberta client

PHIPA names you a custodian. HIA designates a defined list of Alberta providers and organizations as custodians, and it reaches a private practice therapist only as an affiliate working inside one of those custodian organizations. A solo Ontario therapist treating an Alberta client is not an Alberta custodian, so HIA’s custodian duties do not bind you directly. We work this exact situation through end to end, from intake to email, in the Ontario therapist with an Alberta client scenario.

The duty that does follow you across the border comes from college guidance: the requirement to confirm whether you may register or practise in the client’s province, which we cover below. HIA s.64 PIA submission is an Alberta custodian obligation, not one that attaches to an out of province therapist.

If you’re going to maintain Alberta clients on a Gmail based workflow, a written privacy impact assessment is still worth preparing as a risk management step, even though s.64 does not compel you to file one.

Ontario therapist, BC client

BC PIPA applies on the client side. BC has no statutory lock box equivalent and no mandated audit trail.

PHIPA is the stricter standard for both. OIPC BC has published business guidance recommending Canadian hosting for PHI as a strong market expectation.

It’s not a statutory requirement, but it’s a clear regulator signal.

Alberta therapist, Ontario client

PHIPA’s “any unauthorized access” breach threshold is the lower of the two. An unauthorized access that wouldn’t meet HIA’s “risk of harm to an individual” test (s.60.1(2)) can still trigger PHIPA notification to the IPC.

If you’re an Alberta therapist with Ontario clients, build your breach response around the PHIPA threshold.

Client relocates between provinces

This is the one most therapists miss, and it is usually stated backwards. A client who started in Vancouver and relocated to Toronto does not turn your file into a PHIPA matter. PHIPA’s duties attach to Ontario health information custodians, so if you practise in BC, BC PIPA keeps governing you. What changes is practical rather than statutory: consent, records, and the local expectations your client now lives under are all worth revisiting.

Consent documentation should be re-confirmed and any consent directives originally captured under BC PIPA should be re-validated against PHIPA’s lock box framework. The audit trail should reflect the change, and the consent date should be the date of the re-confirmation, not the original onboarding date.

For the full provincial comparison underpinning these scenarios, see the PHIPA vs HIA vs BC PIPA guide.

The “highest standard” approach

You can’t decide jurisdiction once and walk away. You can, however, build your email and consent practice to the strictest of the standards across the three provinces and stop asking the question.

Stacking the requirements

Here’s what “highest standard” looks like when you stack the requirements:

Stacking the requirements
Operational elementPHIPA (Ontario)PIPA (Alberta) + CAPBC PIPAHighest standard
Encryption at rest and in transitSafeguards duty; CRPO Standard 5.6 names encryption among electronic safeguardsSafeguards duty (Alberta PIPA + CAP standards)Safeguards duty (BC PIPA, “appropriate safeguards”)No statute mandates encryption. Treat it as the practical way to meet the safeguards duty in all three provinces.
Consent formatWritten or oral, ongoing (CRPO Standard 3.4)Written or oral, ongoing (CAP guideline)Written or oral, ongoing (BCACC standards)Express, documented, ongoing.
Lock box / consent directiveSupported (PHIPA ss.37(1)(a), 38(1)(a), 50(1)(e))Not supportedNot supportedHonour a lock box on request even if the client’s province doesn’t mandate it.
Audit trailNot prescribed; audit capability sits in CRPO Standard 5.6 commentary as an example. Clinical record retention is 10 years under Standard 5.1Record keeping expected (Alberta PIPA + CAP standards); immutability not specifiedNot statutorily requiredKeep an access log and retain clinical records for 10 years.
Breach thresholdAny unauthorized access (PHIPA s.12)Real risk of significant harm; notify the Commissioner without unreasonable delay (Alberta PIPA s.34.1), individuals when the Commissioner requires it (s.37.1). The HIA s.60.1 “risk of harm” test binds custodians, not private practice therapistsNo statutory breach duty for private organizations; OIPC BC recommends notice on real risk of significant harmNotify on any unauthorized access.
PIANot mandated for the therapistHIA s.64 binds Alberta custodians, not an out of province therapist; prudent as risk managementNot mandatedMaintain a written PIA as a risk management step.
Retention10 years (CRPO Standard 5.1)10 year minimum (CAP Standards)Commonly seven years in BC practice guidance10 years from end of service.
AI processing on PHIStatute silent on AI; consent rules apply to any disclosureStatute silent on AI; CAP Use of Technology guideline says avoid giving patient data to AI toolsStatute silent on AI; consent rules apply to any disclosureTreat AI processing as a disclosure needing consent; follow CAP guidance and keep patient data out of AI tools that lack safeguards.
Data residencyNot mandated; transfer allowed with express consentNot mandated; Canadian hosting recommendedNot mandated; strong market expectation of Canadian hostingPrefer Canadian hosted infrastructure for compliance data.

Why this clears the bar

Build your operations to that right hand column and you’ve cleared the bar in every province you might touch. Two practical consequences follow from that choice.

First, you stop making jurisdiction calls for individual emails. A new client books from Halifax tomorrow, and your encryption, consent, audit trail, and PIA are already at the highest standard.

You add the client to your audit trail, confirm consent, and continue. The decision tree shrinks to two steps where it used to be five.

What this looks like in a regulator review

Second, you build defensibly. If a regulator does come asking, your file shows you applied the strictest applicable rule rather than the most convenient one.

Discovery during a college complaint or civil litigation looks different when the documentation shows you over indexed on safeguards.

Bottom line

The highest standard approach is: encrypt every email containing PHI, capture express written consent that supports a lock box on request, maintain an immutable audit trail with 10 year retention, write a PIA as risk management (HIA s.64 itself binds Alberta custodians, not an out of province therapist), and use Canadian hosted compliance infrastructure for audit trail and any portal messages. Keep patient data out of AI tools that lack safeguards, and treat any AI processing as a disclosure needing consent. Honour the lowest breach threshold of the three provinces.

College registration across provincial lines

Privacy law and college regulation are separate analyses. They share the word “compliance,” but they answer different questions.

Privacy law asks what the therapist must do with PHI. College regulation asks whether the therapist is permitted to practise in a given province in the first place. Conflating them is a common error.

Colleges by province

The colleges relevant to psychotherapy are different in each province:

  • Ontario. CRPO (College of Registered Psychotherapists of Ontario) regulates Registered Psychotherapists. CPBAO (College of Psychologists and Behaviour Analysts of Ontario) regulates psychologists and behaviour analysts. OCSWSSW regulates social workers. CPSO regulates physicians, including psychiatrists, but not psychotherapists.
  • Alberta. CAP (College of Alberta Psychologists) regulates psychologists. Counselling therapists in Alberta remain unregulated; ACTA membership is voluntary, the standalone CCTA path was abandoned, and the province announced in March 2024 that CAP will take on counselling therapist regulation, still pending. ACSW regulates social workers. CPSA regulates physicians.
  • British Columbia. BCACC (BC Association of Clinical Counsellors) covers counselling therapists today. CHCPBC (College of Health and Care Professionals of BC) takes over psychotherapy regulation under the HPOA effective November 29, 2027. Until then, psychotherapy is not a regulated health profession in BC in the same sense as Ontario or Alberta.

Registering where you practise

If you practise across provinces, you may need to register with the relevant college in each province where you provide services. The colleges have their own rules about virtual practice, supervised practice, and reciprocal recognition.

Cross-college recognition isn’t a settled framework, and we won’t invent rules that the colleges haven’t published. See our cross college comparison guide for a side by side of CRPO, CAP, and the CHCPBC transition.

Check directly with each college before accepting clients in a new province.

Two questions, two answers

The general principle: if you’re sending email containing PHI to a client in another province, the privacy law of that province likely applies. If you’re providing clinical services to a resident of another province, the college rules of that province likely apply.

Both questions need answers. Neither answers the other.

Practical steps for cross provincial compliance

Here’s the workflow.

Step 1. Identify which provinces your clients are located in

Pull your client list. Add a column for province of residence. If you see clients across three provinces, you’re managing three regulatory regimes whether you’ve documented it or not. Update this list when a client moves.

Step 2. Review the privacy law requirements for each province

For each province represented in your client list, confirm the operational requirements. Encryption, consent format, lock box, audit trail, breach threshold, PIA, retention.

The PHIPA vs HIA vs BC PIPA guide covers the full comparison. For depth in a single province, see the PHIPA email requirements, the HIA email requirements for Alberta therapists, or the BC PIPA email privacy obligations post for your specific case.

For the broader cross provincial overview, see email privacy laws across Canada. If your practice runs on Google Workspace, Google Workspace data regions covers how to set data location for Gmail and Drive content.

Step 3. Apply the highest standard approach

Use the comparison table in this post. For each operational element, identify the strictest of the applicable requirements and build to that.

Document the decision. The documentation matters as much as the practice when a regulator asks why you handled a file the way you did.

A single consent form covering all three provincial regimes is cleaner than three separate forms.

The addendum should name the therapist’s province, the client’s province, and the applicable laws; capture express written consent for electronic communication with PHI; describe the lock box option and how to invoke it; and describe the breach notification commitment using the strictest threshold.

The cross provincial compliance quick start lays out the addendum elements and adapts them to PHIPA, HIA, and BC PIPA.

Step 5. Review college registration requirements for each province you practise in

Distinct from privacy law. Check CRPO, CAP, BCACC/CHCPBC, OCSWSSW, ACSW, BCCSW, or the relevant professional body for your designation.

Some colleges require formal registration to provide services into the province; some recognize practice across provinces under specific conditions. Verify directly before booking a client in a new province.

Step 6. Document your cross provincial compliance approach in your email policy

Put the highest standard decision in writing. The email policy template gives you the structure: scope (which provinces, which clients, which client types), operational rules (encryption, consent, lock box, audit trail, retention, PIA), breach response, and review cadence.

Treat this as a working document. Update it when a client relocates or your practice expands into a new province.

A PIA is worth preparing at this step for any therapist with Alberta clients, as risk management. HIA s.64 imposes the submission duty on Alberta custodians, not on an out of province therapist, so this is prudence rather than a statutory obligation that binds you.

Our privacy impact assessment template gives you a starting structure informed by the OIPC Alberta approach.

FAQ

Which privacy law applies if my client is in another province?

Both your province’s law and your client’s province’s law may apply. Your province treats you as a custodian or organization; your client’s province has historically asserted jurisdiction over PHI of its residents. No Canadian court has resolved the overlap squarely for private practice therapists. The defensible approach is to apply the stricter of the applicable requirements rather than re-decide jurisdiction per email.

Do I need to register with the college in my client’s province?

Possibly. College registration is separate from privacy law and follows each college’s rules. CRPO regulates psychotherapy in Ontario, CAP regulates psychology in Alberta, BCACC currently covers counselling in BC, and CHCPBC takes over psychotherapy regulation in BC on November 29, 2027. Check directly with each college before providing services into a new province.

Can I use the same email setup for all provinces?

Yes, provided the setup meets the highest applicable standard across all your client provinces. None of these laws names encryption; each imposes a safeguards duty, and encryption is the practical way to meet it for health information sent by email. Keeping an access log you don’t rewrite after the fact, plus 10 year retention of clinical records, covers Ontario: CRPO Standard 5.1 sets that retention period, and Standard 5.6 treats audit capability as an example of protecting records rather than a prescribed rule. Express written consent, lock box on request, and a written PIA cover the strictest of the other three operational elements.

What if PIPEDA applies instead of a provincial law?

PIPEDA applies to commercial activity, and provinces with private sector or health sector laws the Governor in Council has designated substantially similar are largely carved out of its reach for activity within the province. Ontario’s PHIPA, Alberta’s PIPA, and BC’s PIPA all carry that designation, so provincial law governs PHI handled by therapists in private practice in these provinces. Designation does not switch off PIPEDA for personal information that moves across a border in a commercial transfer, so building to the provincial highest standard, with security and accountability over any cross border handling, is the safer footing.

Where Curio fits

You don’t need a product to apply the highest standard. The consent template, the audit trail discipline, and the PIA are doable independently. What’s harder to do by hand is keep encryption automatic on every email and maintain an immutable audit trail that holds up in a college complaint or an OIPC review.

Curio’s compliance infrastructure handles encryption and audit trail for Canadian health privacy law across PHIPA, HIA, and BC PIPA. One setup, every province. Join the waitlist.

Consent documentation and your PIA submission to OIPC Alberta remain your responsibility. Curio does not write either. The product handles the technical safeguards; the clinical and consent layer is yours.


Regulatory content disclaimer. This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body. Product disclaimer. Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook