You practise in Ontario. A new client moves to Calgary and wants to keep working with you. Which privacy law governs the email you send them now? Most therapists assume PHIPA follows the practitioner. It does not always work that way. Here is a one page reference for figuring out which Canadian privacy law applies to your therapy email, and where PIPEDA enters the picture.
Which law applies?
Use this decision tree. Pick the branch that matches your practice and client base.
- Practice and clients all in Ontario -> PHIPA governs your email. See the PHIPA email requirements guide for therapists.
- Practice and clients all in Alberta -> Alberta PIPA governs most private practices, with CAP standards on top; HIA applies where you work inside a custodian organization. See the HIA and PIPA picture for Alberta therapists.
- Practice and clients all in BC -> BC PIPA governs your email. See the BC PIPA guide for therapists.
- Cross provincial practice (clients in more than one province) -> Multiple laws may apply at once. PIPEDA may also apply for commercial activity that crosses provincial lines. The defensible default is the highest standard approach (see callout below). Read the PHIPA vs HIA vs BC PIPA hub for the full picture, and the telehealth across provincial lines guide for the practical mechanics.
If you are unsure which branch you fall into, default to the cross provincial branch. Over-complying is not a regulatory risk. Under-complying is.
Key differences at a glance
| Requirement | PHIPA (Ontario) | HIA (Alberta) | BC PIPA (British Columbia) |
|---|---|---|---|
| Encryption | Reasonable steps to protect PHI in transit; encryption is the de facto standard (s.12(1)) | Required safeguards under s.60; encryption expected for electronic PHI | Reasonable security arrangements under s.34; encryption expected for sensitive personal information |
| Consent model | Implied consent within the circle of care; express consent for disclosures outside it. PHIPA also lets a patient restrict use or disclosure (the “lock box,” ss.19(1), 20(2), 37(1)(a), 38(1)(a), 50(1)(e)) | Express or implied depending on context; a patient may ask the custodian to limit how their health information is used or disclosed | Consent under Part 3 (ss.6 to 9): express, implied, or deemed; deemed consent is s.8 (s.7 sets the conditions for valid consent) |
| Data residency | No mandate; reasonable safeguards required regardless of location | No mandate; reasonable safeguards required | No mandate for the private sector; reasonable security arrangements required (s.34). Note: the data storage rule for public bodies is FOIPPA, not PIPA |
| Breach notification | Notify affected individuals at the first reasonable opportunity; notify IPC when one of the prescribed circumstances applies (s.12(3) and O. Reg. 329/04 s.6.3) | Mandatory to OIPC Alberta and affected individuals when there is a risk of harm to an individual; as soon as practicable (s.60.1(2)) | No statutory duty for private practices; OIPC BC recommends notifying the commissioner and affected individuals when there is a real risk of significant harm (the mandatory regime, FOIPPA s.36.3, applies to public bodies) |
| PIA requirement | Recommended for new information systems; not statutory | Custodians must prepare a PIA and submit it to OIPC Alberta before implementing a new health information system or practice (s.64); since October 2024 reviews end in a closing letter | Recommended; not statutory for the private sector |
| Regulatory college | CRPO (College of Registered Psychotherapists of Ontario) | CAP (College of Alberta Psychologists); counselling therapist regulation expanding | CHCPBC (College of Health and Care Professionals of BC); psychotherapy regulation begins November 29, 2027 |
The highest standard approach
When your practice spans more than one province, comply with the strictest applicable requirement on each dimension. In practice, that means: encrypt every email containing PHI, document consent in writing for cross jurisdictional clients, maintain an audit trail of every send, and complete a PIA where any of the applicable provincial regimes require one. This protects you under whichever law a regulator decides to apply.
Next steps
- Read the full hub: PHIPA vs HIA vs BC PIPA for Canadian therapists.
- For the multi-province scenario, see the cross-provincial telehealth privacy guide, and apply the highest standard approach.
- Use the cross-provincial consent addendum template to layer the strictest consent language from each applicable province into your intake form.
If you want this layer handled automatically, Curio handles encryption and a Canadian audit trail across all provinces. Join the waitlist.
This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body.