All Articles
Compliance

PIPEDA vs HIPAA: What Canadian Businesses Need to Know

6 min read

Canadian organizations that handle personal or health information often hear both acronyms. They are different laws, in different countries, with different scopes — but the technical safeguards they expect look very similar.

PIPEDA in brief

The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It applies to personal information collected, used or disclosed in the course of commercial activity, except where a province has substantially similar legislation. It requires meaningful consent, appropriate safeguards, and reporting of breaches that pose a real risk of significant harm.

HIPAA in brief

The Health Insurance Portability and Accountability Act is a U.S. law governing protected health information held by covered entities and their business associates. A Canadian company can fall under it when it serves U.S. healthcare organizations or handles their patients' data.

Don't forget provincial health privacy law

In Ontario, personal health information is governed by PHIPA. Other provinces have their own health privacy statutes. Clinics and care providers usually need to satisfy provincial law first.

What this means for your IT

  • Know where personal and health data lives, and who can access it.
  • Encrypt data at rest and in transit, and enforce multi-factor authentication.
  • Log access to sensitive systems and review it regularly.
  • Keep tested backups and a documented incident response plan.
  • Put written agreements in place with vendors that handle your data.

This article is general information, not legal advice. For your specific obligations, speak with privacy counsel — then let us help you build the controls to meet them.

Ready to Transform Your IT?

Schedule a consultation to discuss how INTUITION Consultancies can help your organization.