Healthcare organizations in Canada operate under privacy legislation that goes beyond PIPEDA and places specific requirements on how personal health information is collected, stored, and transmitted. For Ontario organizations, the Personal Health Information Protection Act (PHIPA) is the primary legislation. For Quebec organizations, the Act Respecting Health Services and Social Services (LSSSS) and Law 25 apply. This guide focuses on Ontario's PHIPA but the general principles apply across provinces.
What counts as personal health information under PHIPA
Personal health information under PHIPA is broadly defined. It includes any information about an individual's physical or mental health, the provision of health care to an individual, payments for health care, the donation of body parts, and the individual's health card number. Importantly, information is PHI regardless of whether it appears in a paper record or an electronic one, and regardless of whether it is stored on your server or transmitted through your website. If your website has a patient portal, an appointment booking system, a form that collects health conditions, or a telehealth interface, those systems are processing PHI and PHIPA's requirements apply.
PHIPA requirements that directly affect hosting
PHIPA requires that health information custodians have administrative, technical, and physical safeguards appropriate to the sensitivity of the personal health information they hold. For a hosted website, the technical safeguards requirement means: encryption in transit (HTTPS), encryption at rest for stored PHI, access controls that limit who can read PHI, and audit logging that records access to PHI. Physical safeguards for hosted infrastructure mean choosing a data centre with appropriate physical security and access controls. Your hosting provider is a "service provider" under PHIPA if they store, process, or otherwise have access to PHI as part of their service.
PHIPA requires a written agreement with any service provider who handles PHI on your behalf. This agreement must require the service provider to protect PHI, use it only for the purposes you have specified, and notify you in the event of a privacy breach. Ask your hosting provider for a service provider agreement or data processing agreement that meets PHIPA requirements before hosting any PHI on their servers.
Data residency for healthcare data in Canada
PHIPA does not explicitly prohibit transferring PHI outside Canada, but the Information and Privacy Commissioner of Ontario has been clear in guidance that organizations should assess the risk before doing so, and that the CLOUD Act's implications for US-hosted data are a relevant risk factor. The practical position of most healthcare organizations in Ontario is to keep PHI on Canadian servers operated by Canadian companies, to avoid the complexity of cross-border transfer assessments. This is the conservative and defensible approach that regulators are unlikely to question.
What to verify before choosing a host for a healthcare website
Ask whether the provider can execute a service provider agreement that addresses PHIPA's requirements. Ask where the servers are physically located and confirm this in writing. Ask whether data at rest on your account is encrypted. Ask what logging is in place for administrative access to your account. Ask about the provider's own security incident response process. Ask whether they have experience hosting healthcare clients and what their approach to PHIPA compliance is. A provider that cannot answer these questions clearly, or that has never considered them, is not the right host for a healthcare organization.
Quebec healthcare data: what changes
Quebec healthcare organizations are subject to Law 25 in addition to healthcare-specific legislation. The combination means all the general Law 25 requirements apply: Privacy Impact Assessments for new technology projects, contractual requirements for third-party data processors, and breach notification to the CAI. For public health sector organizations, the Act Respecting Access to Documents Held by Public Bodies and the Protection of Personal Information also applies and has its own data residency implications. Keeping healthcare data in Quebec on Quebec-managed servers is the approach that satisfies all applicable frameworks simultaneously without requiring complex cross-border assessments.
Gotekky
Need help deciding what to do next?
Tell us what you are seeing and what outcome you need. We will identify whether a managed service, scoped project or paid technical assessment is the right next step.