Privacy & Compliance

How to keep Canadian patient
data secure.

Secure patient data management in a Canadian health clinic - PHIPA compliance
TL;DR

PHIPA - Canada's health privacy law - requires that personal health information be collected, stored, and protected appropriately. Using software hosted outside Canada creates real compliance risk. The most important thing your practice management software needs: Canadian data residency, encryption at rest and in transit, access controls, and a Data Processing Agreement (DPA) available on request.

In this post
  1. What PHIPA actually requires
  2. PHIPA vs HIPAA - not the same thing
  3. The risks of using non-Canadian software
  4. What Canadian data residency means
  5. What to look for in your software
  6. How MyoMesh handles data security

What PHIPA actually requires

The Personal Health Information Protection Act (PHIPA) is Ontario's primary health privacy legislation. Similar laws exist across Canadian provinces - Alberta's Health Information Act (HIA), British Columbia's Personal Information Protection Act (PIPA), and Quebec's Law 25. Together, they establish how regulated health professionals must handle personal health information (PHI).

At a practical level, PHIPA requires that health information custodians - which includes physiotherapists, RMTs, chiropractors, osteopaths, and most regulated wellness practitioners - must:

The "agents and service providers" requirement is the one most practitioners overlook. If your practice management software doesn't meet PHIPA's standards, you - as the health information custodian - are responsible.

Canadian health practitioner managing patient records with PHIPA-compliant software
Under PHIPA, health information custodians are responsible for how patient data is collected, stored, and accessed.

Important: This article provides general information about privacy compliance for Canadian practitioners. It is not legal advice. For specific compliance questions, consult a privacy lawyer or your regulatory college.

PHIPA vs HIPAA - not the same thing

Many US-based practice management platforms advertise HIPAA compliance. This is meaningful for US practitioners - but it is not the same as PHIPA compliance, and it does not satisfy Canadian privacy requirements.

The differences matter:

A HIPAA-compliant US platform is not a substitute for PHIPA-compliant Canadian infrastructure. These are different laws with different requirements.

The risks of using non-Canadian software

The practical risks of using non-PHIPA-compliant software fall into two categories:

Regulatory risk: If a privacy complaint is filed against your practice - by a client, or following a breach - your regulator will assess whether your software and practices met PHIPA's requirements. Using software that stores Canadian patient data outside Canada, without appropriate safeguards, is a compliance failure. Penalties can include fines and professional discipline.

Reputational risk: Practitioners who collect health information have an implicit trust relationship with their clients. A breach - or even a disclosure that client data was stored on foreign servers without clients' knowledge - can damage that trust significantly. In a field where referrals and word-of-mouth are critical, reputation matters.

Built and hosted in Canada - PHIPA compliant by design

Canadian data stays
in Canada.

See how MyoMesh handles privacy →

What Canadian data residency means

Data residency refers to where data is physically stored - the geographic location of the servers. Canadian data residency means your client health information lives on servers in Canada, subject to Canadian law.

Why does this matter? Because data stored in another country is subject to that country's laws. A US-hosted platform can be compelled by US courts to produce data stored on its servers - even for non-US customers. That data could theoretically be accessed by a foreign government without your knowledge or your client's consent.

For PHIPA compliance, the clearest and most defensible approach is Canadian data residency. When evaluating practice management software, ask explicitly: where are your servers located? "Cloud-based" or "encrypted" doesn't answer this question.

What to look for in your software

Here's what a PHIPA-conscious practice management platform should offer:

Ask any platform you're evaluating for their privacy documentation and DPA before signing up. A platform that can't produce these promptly is a platform that hasn't taken compliance seriously.

How MyoMesh handles data security

MyoMesh stores identifiable personal health information in Canada, with encryption at rest and in transit. Before a MyoMind request is sent to OpenAI, all clinical content is de-identified. OpenAI processes that de-identified content transiently under an executed Business Associate Agreement and Zero Data Retention amendment: prompts and responses are not retained by OpenAI or used to train its models.

We provide a Data Processing Agreement for every account. We do not sell or share client health data with third parties. Our privacy practices are detailed on our PHIPA compliance page.

Common questions

What is PHIPA?

PHIPA - the Personal Health Information Protection Act - is Ontario's primary health privacy law. It governs how health information custodians collect, use, and disclose personal health information. Similar legislation exists in other provinces. PHIPA sets requirements for consent, access, storage, and breach notification.

Does my practice management software need to be PHIPA compliant?

Yes. If you're a regulated health professional in Canada collecting personal health information through your software, your software and how you use it must comply with PHIPA. Using non-compliant software is a regulatory risk - and as the health information custodian, you are responsible.

Is PHIPA the same as HIPAA?

No. HIPAA is US legislation. PHIPA is Ontario's equivalent. A US platform that is HIPAA compliant is not automatically PHIPA compliant, and may not meet Canadian data residency requirements. These are different laws with different requirements and different regulators.

What does Canadian data residency mean for my practice?

Canadian data residency means your client health information is stored on servers located in Canada and subject to Canadian law. Data stored in the US is subject to US laws - including legislation that may allow US government access. For PHIPA compliance, Canadian data residency is the clearest path to meeting provincial privacy requirements.

What happens if I use software that isn't PHIPA compliant?

You risk regulatory investigation, fines, and reputational damage if a breach occurs. Under PHIPA, health information custodians are responsible for ensuring their agents and service providers meet privacy requirements. 'I didn't know the software wasn't compliant' is not a defence.

PHIPA compliant.
Canadian by design.

MyoMesh is built and hosted in Canada. Every account includes a Data Processing Agreement.

Learn about our privacy practices → Start your experience