Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
home / guides / alberta hia & bc pipa

Alberta HIA and BC PIPA for health and SaaS companies

Western Canada does health privacy differently from Ontario. Alberta has information managers and a Commissioner who reviews your privacy impact assessment before you go live. British Columbia has a residency history that still shapes procurement.

Last reviewed September 2026 · by traztech, security & compliance for startups
Short answer

Alberta's Health Information Act works through custodians, their affiliates, and a third category called an information manager, which is where most software vendors sit and which requires a written information manager agreement. Its distinctive requirement is that custodians must submit a privacy impact assessment to the Office of the Information and Privacy Commissioner of Alberta before implementing a new practice or information system, which puts a regulator in your go-live path rather than only in your incident path. BC PIPA is a general private sector statute that covers employee personal information and now carries mandatory breach notification. British Columbia's public sector residency prohibition was removed in 2021, but the expectation survives in procurement templates and in buyer habit. If you sell health software in the west, budget for the Alberta PIA cycle and answer the BC residency question with a Canadian region rather than an argument.

3 roles
custodian, affiliate and information manager under the Alberta HIA
Before go-live
when an Alberta PIA must be submitted to the Commissioner
2021
year BC removed its public sector data residency prohibition

Why western Canada is a different sale

A health technology company that has sold successfully in Ontario often assumes the western provinces are the same review with different letterhead. They are not, and the differences fall in places that affect schedule rather than paperwork.

Alberta puts a regulator in the deployment path. Under the Health Information Act, a custodian must submit a privacy impact assessment to the Office of the Information and Privacy Commissioner of Alberta for review and comment before implementing proposed administrative practices or information systems relating to the collection, use or disclosure of individually identifying health information. That is not an internal document you file. It goes to the Commissioner, the Commissioner reviews it, and the custodian generally waits for acceptance before proceeding.

The practical effect is that your go-live date depends on a queue you do not control. Vendors who learn this in month four of a sale lose a quarter. Vendors who know it in week one build it into the plan, help the custodian write the assessment quickly and accurately, and often find they are the reason the submission was clean the first time.

British Columbia's difference is historical and cultural rather than procedural. For fifteen years BC public bodies were prohibited from storing or accessing personal information outside Canada except in narrow circumstances. That prohibition was removed in 2021, but a decade and a half of architecture, procurement templates, standard clauses and institutional memory does not evaporate because a section was amended. You will still meet the requirement, expressed as policy rather than law, and arguing the amendment at a procurement officer is not the winning move.

Alberta also has a general private sector statute, Alberta PIPA, which sits alongside the Health Information Act the way PIPEDA sits alongside PHIPA in Ontario. Which one governs a given data store depends on the capacity in which you hold it. Our guide to which Canadian privacy law applies covers that sorting exercise across the country.

The Alberta HIA structure: custodian, affiliate, information manager

The Health Information Act applies to health information, which the Act divides into diagnostic, treatment and care information and registration information. It binds custodians, a defined list that includes Alberta Health Services, the provincial health ministry, regulated health professionals in prescribed circumstances, nursing homes, pharmacies and others. As in Ontario, a software vendor is essentially never a custodian.

An affiliate is roughly Alberta's analogue of Ontario's agent, but the definition is employment-flavoured: individuals employed by the custodian, persons who perform a service for the custodian as an appointee, volunteer or student, and information managers are also brought within the concept for certain purposes. An affiliate may only collect, use and disclose health information in accordance with the custodian's authority and the Act, and must comply with the custodian's policies. Affiliates have direct duties, including a duty not to use or disclose health information except as authorized.

An information manager is the category that matters most to vendors. It covers a person or body that processes, stores, retrieves or disposes of health information for a custodian, that strips, encodes or otherwise transforms individually identifying health information to create non-identifying health information, or that provides information management or information technology services. If you host, process or manage health information for an Alberta custodian, that is you.

A custodian may only provide health information to an information manager, or engage one, under a written information manager agreement. The agreement has to deal with the services, the custodian's authority, the protection of the information, and what happens on termination. Critically, health information held by an information manager remains under the custody or control of the custodian, and the information manager has no independent right to it.

This produces a specific and commonly missed consequence: an information manager may not use health information for its own purposes, including product improvement, analytics, benchmarking or model training, unless the agreement authorizes it and the custodian could lawfully authorize it. The same trap as Ontario, arriving through different vocabulary.

Alberta also has a body of rules around the provincial electronic health record and around prescribed practitioners accessing it. If your product touches Netcare or a provincial repository, the access, logging and authorization rules there are additional to everything in this section and are worth specialist attention early.

The Alberta privacy impact assessment, in practice

The PIA submission requirement is the single most operationally significant difference between Alberta and Ontario for a health technology vendor, so it is worth describing what the document actually contains and how the cycle runs.

The custodian owns the submission. In reality, for a vendor-supplied system, most of the content is yours: a project description, the legal authority for the collection, a detailed description of the information flows, the categories of health information involved, who has access and on what basis, the technical and administrative safeguards, the physical and logical location of the data, the subcontractors involved, retention and disposal, and a risk assessment with mitigations. The Commissioner's office publishes guidance on what it expects to see and it is specific.

The cycle is: draft, internal review by the custodian's privacy office, submission, Commissioner review, questions back, response, acceptance. Review times vary with the office's workload and with the quality of the submission. A clean submission of a well-understood system moves faster than a novel architecture with offshore components and vague safeguard descriptions. Plan for it in months, not weeks, and ask the custodian early what their recent experience of turnaround has been.

What slows submissions down, in order: unclear data flows, unnamed subcontractors, safeguard descriptions written in marketing language, storage or access outside Canada that is mentioned late or vaguely, access models where the vendor has standing production access, absent or weak audit logging, and retention periods that do not match the custodian's obligations.

What speeds them up: a data flow diagram that names every system and every subcontractor, precise safeguard statements naming algorithms and mechanisms, a clear statement of who at the vendor can access health information and under what controls, a documented break-glass process, and evidence that the controls operate, such as a SOC 2 Type II report or an independent penetration test with remediation status.

A PIA is also not a one-time artifact. Material changes to the system or the practice trigger an amended assessment. If your product ships significant changes quarterly, agree with the custodian at the outset what counts as material, or you will end up re-submitting for a UI refresh or failing to submit for an architecture change.

Alberta HIA breach notification

Alberta added mandatory breach notification to the Health Information Act, and its shape is distinctive. Where there has been a loss of health information or an unauthorized access to or disclosure of health information, and there is a risk of harm to an individual as a result, the custodian must notify the affected individual, the Commissioner, and the Minister.

Two features stand out. First, notification goes to the Minister as well as the Commissioner, which is unusual and reflects the provincial health system structure. Second, Alberta's HIA carries offence provisions with penalties attaching to individuals as well as organizations, and the province has been willing to prosecute snooping cases involving individual employees.

Your position as an information manager or affiliate is upstream of all this: you notify the custodian, promptly, and the custodian runs the statutory notifications. Your contract will set the clock, and it is often shorter than the equivalent Ontario clause because the custodian has three parties to notify rather than two.

Alberta PIPA has its own separate breach regime for non-health personal information, described in the next section. If you hold both categories, your incident procedure needs to route correctly at the top, because the thresholds, the recipients and the clocks differ.

Alberta PIPA: the general private sector statute

Alberta's Personal Information Protection Act governs personal information handled by organizations in Alberta, and it has been declared substantially similar to PIPEDA, so it displaces PIPEDA for activity within the province.

Two things distinguish it from PIPEDA for a technology company. It covers employee personal information, providing a route to collect, use and disclose personal employee information without consent where it is reasonable for the purposes of establishing, managing or terminating an employment relationship, subject to giving the employee notice. If you have Alberta staff, your HR processing is regulated in a way it would not be for an Ontario employer.

Its breach mechanic also differs. An organization must notify the Alberta Commissioner without unreasonable delay of any incident involving loss of, unauthorized access to, or unauthorized disclosure of personal information where a reasonable person would consider that a real risk of significant harm to an individual exists. The Commissioner then determines whether the organization must notify affected individuals and may require it to do so. Under PIPEDA, the organization makes that call itself and notifies both the Commissioner and individuals. The Alberta route means the regulator sees your incident earlier and has a decision to make about it.

Alberta PIPA also has a service provider concept and, in the notice requirements, an expectation that an organization tell individuals if personal information will be handled by a service provider outside Canada, including the purposes and a contact who can answer questions. This is a transparency obligation rather than a prohibition, and it means your customer needs an accurate statement from you about where processing happens.

Alberta separately overhauled its public sector access and privacy legislation, replacing the long-standing Freedom of Information and Protection of Privacy Act with newer access and privacy statutes for public bodies. If you sell to Alberta public bodies, check which instrument the procurement is written against, because templates lag legislation by a year or two.

BC PIPA: what it requires

British Columbia's Personal Information Protection Act is the province's general private sector privacy law, also declared substantially similar to PIPEDA. Structurally it resembles Alberta PIPA closely: consent-based, with reasonableness limits, employee personal information within scope, individual access and correction rights, safeguards, and an order-making Commissioner.

The recurring themes in BC enforcement are consent quality, over-collection, and safeguards. The BC Commissioner has been active on employee monitoring, on the use of personal information for purposes beyond what individuals would expect, and on organizations that cannot demonstrate basic access control. None of that is exotic; it is the ordinary discipline of knowing what you hold and limiting who can reach it.

BC PIPA has no mandatory breach notification, and British Columbia is the only jurisdiction in Canada where a private sector organization is not required by statute to report a breach to anybody. The Commissioner publishes guidance encouraging notification and provides the forms, but for an organization under PIPA the decision is discretionary. The mandatory regime in the province sits in FIPPA and binds public bodies, which since 1 February 2023 must notify both the affected individual and the Commissioner where a breach could reasonably be expected to result in significant harm. Do not read the public sector rule across to yourself. What still matters commercially is that your customers and your own contracts will expect notification whatever the statute says, so the harm assessment and the record of it are worth keeping either way.

For health information specifically, British Columbia does not have a standalone private sector health privacy statute in the way Ontario and Alberta do. Health information held by public bodies, which includes the health authorities and most of the hospital system, falls under the province's public sector Freedom of Information and Protection of Privacy Act. Health information held by private providers and by vendors serving them falls under PIPA. So the applicable statute in a BC health deal depends on whether your customer is a public body or a private clinic, and the answer changes the contract shape entirely.

The BC residency question, answered properly

This is the single most misunderstood point in western Canadian procurement, and it is worth getting exactly right because both over-claiming and under-claiming cost deals.

The history: British Columbia's public sector privacy statute contained a provision requiring that personal information in the custody or under the control of a public body be stored only in Canada and accessed only in Canada, subject to narrow exceptions such as individual consent. It was introduced in the mid-2000s and it shaped a generation of BC public sector technology architecture, including a domestic hosting industry that existed largely because of it.

That prohibition was removed by amendment in 2021. The current position is that public bodies must make reasonable security arrangements, and disclosures outside Canada are governed by the general disclosure rules and by the province's assessment expectations rather than by a flat ban. In parallel, BC public bodies are expected to conduct privacy impact assessments, and for systems with meaningful risk, security threat and risk assessments.

What did not change: the procurement templates, the standard clauses, the ministry policies, the health authority requirements and the expectations of the people running the reviews. A BC health authority can still require Canadian hosting as a contractual term whether or not the statute compels it, and many do. Nor did BC PIPA, the private sector statute, ever contain a residency requirement, so a private clinic in Vancouver has always been free to use a US-hosted service subject to the general safeguards and consent rules.

The correct answer in a BC bid therefore has three parts. State the legal position accurately if asked, without lecturing. State where your data actually resides, by region, including backups, logs, support tooling and any subprocessor. And, if you can offer a Canadian region, offer it, because doing so converts a long conversation into a checkbox. Our data residency guide covers how to write that answer when part of your stack cannot be in Canada.

What differs from PHIPA and PIPEDA, concretely

If you have an Ontario-shaped program, these are the deltas to work through rather than rebuilding from scratch.

The vendor category has a different name and a required contract. Ontario has agents and electronic service providers; Alberta has affiliates and information managers with a mandatory written information manager agreement. If you are selling into Alberta with an Ontario-style data processing addendum, expect to be asked for the HIA-specific agreement instead.

The assessment is submitted to a regulator. Ontario custodians run privacy impact assessments as good practice and sometimes as institutional policy. Alberta custodians must submit them to the Commissioner before implementation. This is a schedule difference, not a paperwork difference.

The breach recipients differ. Ontario health breaches go to the IPC in prescribed circumstances. Alberta health breaches go to the Commissioner, the Minister and the individual where there is a risk of harm. Alberta PIPA breaches go to the Commissioner who then decides on individual notification. PIPEDA breaches go to the federal Commissioner and to individuals on a real risk of significant harm test, with a mandatory register of all breaches regardless of threshold.

Employee data is in scope in the west. Alberta and BC PIPA both cover employee personal information; PIPEDA does not for provincially regulated employers. Companies with distributed Canadian teams are frequently non-compliant on this without knowing it.

The health information network provider concept is Ontario-specific. If your product connects multiple custodians to each other, Ontario imposes direct statutory duties including a biennial written assessment. Alberta and BC do not have an identical category, though the underlying obligations arrive through the information manager agreement and through assessment requirements.

Residency expectations are stronger in the west, particularly in the BC public sector and health authority space, even though the legal basis is weaker than it was.

What a western Canadian health buyer asks a vendor for

The document set is recognizable if you have done an Ontario hospital review, with a few additions. Build it once and it serves every subsequent bid in both provinces.

Expect: a completed vendor security questionnaire on the buyer's own template. A data flow description naming every system and subcontractor that can touch health information, including support ticketing, error reporting and analytics. Content for the privacy impact assessment, and in Alberta, content shaped for a Commissioner submission. A threat and risk assessment or a recent penetration test with remediation status. An information manager agreement in Alberta. Hosting locations by region for primary data, backups, logs and support access. Access control detail, specifically who at your company can reach health information and how that is constrained. Audit logging capability at the record level. Retention and secure disposal, with evidence. Incident notification terms. Cyber liability insurance certificates. Business continuity evidence, tested rather than documented. Increasingly, a statement on artificial intelligence components and on whether customer data is used for training.

Two questions get asked in the west more often than in Ontario. The first is about support access from outside Canada: if your support team is distributed, whether a person in another country can view health information matters more here, and the honest answer plus a technical control such as region-restricted access or field-level masking is worth more than a policy statement. The second is about the provincial electronic health record: whether your product integrates with it, what it writes, and how consent directives and access rules are honoured.

The highest-leverage preparation is the same as everywhere: record-level audit logging, no standing production access, a named break-glass process, and a data flow description you can send on the first request. Those four things answer most of the hard questions in both provinces.

Building one program for both provinces

Running separate Alberta and BC programs is a waste. The controls are the same; the paperwork and the recipients differ. The structure that works is a single control set with a jurisdictional overlay.

Concretely: one set of safeguards evidenced once, covering access control and reviews, encryption, record-level logging, change management, vendor management, incident response, business continuity and disposal. One data map with a province column and a capacity column, so you can answer instantly whether a given store is health information under the Alberta HIA, personal information under Alberta PIPA, personal information under BC PIPA, or something under PIPEDA. One retention schedule keyed to the strictest applicable rule per data category. One incident procedure with a decision tree at the top that routes to the right regulator and the right clock.

Then a thin jurisdictional layer: the information manager agreement template for Alberta, the PIA content pack shaped for the Alberta Commissioner's expectations, the BC residency answer, and the employee information notice for Alberta and BC staff.

A SOC 2 or ISO 27001 program sits underneath all of this and does most of the evidence work. Neither is a legal requirement in either province, and neither makes you compliant with a statute. What they buy is the ability to answer the safeguards half of every assessment with a document you already have, which is worth a great deal when a Commissioner submission is waiting on your answers.

If you are also selling in Ontario, the same structure extends: add PHIPA to the capacity column and the health information network provider question to the status assessment. Our PHIPA guide covers that side.

Failure modes specific to the west

Discovering the Alberta PIA submission requirement late. It is a schedule dependency on a regulator queue. Finding out in month four of a sale costs a quarter.

Offering an Ontario-style data processing addendum in Alberta. The custodian needs an information manager agreement, and the substitution signals you have not read their statute.

Arguing the 2021 BC amendment at a procurement officer. The residency requirement in front of you is contractual and institutional. Meet it or explain precisely what cannot be met and why.

Ignoring employee personal information. Alberta and BC PIPA cover it. Distributed Canadian teams are the common case and the common gap.

Support access from outside Canada, undisclosed. This surfaces during review, and it surfaces worse after an incident. Disclose it and control it.

Using health information for product improvement. An information manager has no independent right to the information. Same rule as Ontario, different words.

Treating the PIA as final. Material changes trigger an amended assessment. Agree with the custodian what counts as material before you ship the first big release.

Alberta, British Columbia and Ontario compared

Dimension Alberta British Columbia and Ontario
Health privacy statute Health Information Act, applying to custodians, affiliates and information managers. BC: no standalone private health act; public bodies under FIPPA, private providers under PIPA. Ontario: PHIPA, with custodians, agents, electronic service providers and health information network providers.
Vendor category and contract Information manager, with a mandatory written information manager agreement. BC: service provider under PIPA, contract-driven. Ontario: agent and electronic service provider, with duties in O. Reg. 329/04.
Privacy impact assessment Submitted to the Office of the Information and Privacy Commissioner of Alberta before implementing a new practice or system. BC: required for public bodies under FIPPA, internal to the institution. Ontario: institutional policy for custodians, now statutory for FIPPA institutions under Bill 194.
Health breach notification To the individual, the Commissioner and the Minister where there is a risk of harm. BC: under PIPA or FIPPA depending on the custodian type. Ontario: to the individual at the first reasonable opportunity, and to the IPC in prescribed circumstances.
General private sector law Alberta PIPA, covering employee personal information, with breach notification to the Commissioner who decides on individual notification. BC: PIPA, covering employee personal information, with no statutory breach notification at all. Ontario: no general private sector statute, so PIPEDA applies.
Data residency No statutory residency rule; notice expectations where a service provider outside Canada handles personal information. BC: public sector prohibition removed in 2021, expectation persists in procurement. Ontario: no statutory rule, institutional policy common.
Enforcement Order-making Commissioner, offence provisions reaching individuals, active enforcement on unauthorized access. BC: order-making Commissioner. Ontario: IPC with order-making powers and PHIPA offence provisions up to $200,000 for an individual and $1,000,000 for an organization.

Frequently asked

What is an information manager under the Alberta Health Information Act?

An information manager is a person or body that processes, stores, retrieves or disposes of health information for a custodian, that converts individually identifying health information into non-identifying form, or that provides information management or information technology services. Most software vendors serving Alberta custodians fall into this category. A custodian may only engage one under a written information manager agreement, and the health information remains under the custodian's custody or control throughout.

Does the Alberta Commissioner have to approve our software before a custodian can use it?

Not approve the software as such, but the custodian must submit a privacy impact assessment covering the proposed practice or information system to the Office of the Information and Privacy Commissioner of Alberta before implementing it, and the Commissioner reviews and comments. In practice custodians wait for the review to conclude before going live, which makes the submission a schedule dependency for your deployment. Plan it in months and help the custodian produce a clean submission the first time.

Does BC still require personal information to be stored in Canada?

Not as a matter of statute. The provision in British Columbia's public sector privacy law prohibiting storage and access outside Canada was removed in 2021, and BC PIPA, the private sector statute, never contained such a requirement. What persists is procurement practice: ministries, health authorities and other public bodies frequently require Canadian hosting as a contractual term, and their templates and internal policies still assume it. The practical answer in a BC bid is to offer a Canadian region rather than to argue the amendment.

How is the Alberta HIA different from PHIPA?

The concepts map roughly but the mechanics differ. Alberta uses custodians, affiliates and information managers where Ontario uses custodians, agents and electronic service providers. Alberta requires a written information manager agreement and requires privacy impact assessments to be submitted to the Commissioner before implementation. Alberta health breach notification goes to the individual, the Commissioner and the Minister. Ontario has the health information network provider category with direct statutory duties including a written assessment every two years, which Alberta does not replicate in the same form.

Do Alberta and BC privacy laws cover employee data?

Yes. Both Alberta PIPA and BC PIPA cover employee personal information in the private sector and provide a route to collect, use and disclose it without consent where it is reasonable for purposes of establishing, managing or terminating the employment relationship, subject to giving notice. PIPEDA does not cover employee information for provincially regulated employers, so a company with Alberta or BC staff has obligations an Ontario-only employer does not.

Who do we notify after a breach in Alberta?

It depends which statute the information falls under. For health information under the Health Information Act, the custodian notifies the affected individual, the Commissioner and the Minister where there is a risk of harm, and your duty as an information manager or affiliate is to notify the custodian promptly under your agreement. For personal information under Alberta PIPA, the organization notifies the Alberta Commissioner without unreasonable delay where a real risk of significant harm exists, and the Commissioner then decides whether individuals must be notified.

Can we use Alberta health information to improve our product?

Only if the information manager agreement authorizes it and the custodian could lawfully authorize it, which is rarely the case for product analytics or model training on identifiable health information. Health information held by an information manager remains under the custodian's custody and control, and the information manager has no independent right to use it for its own purposes. Properly non-identifying information is a separate question, but converting identifying health information into non-identifying form is itself an information manager function that has to be covered by the agreement.

Do we need a SOC 2 report to sell health software in Alberta or BC?

No statute requires it in either province. In practice it is the most efficient way to answer the safeguards half of a privacy impact assessment, an information manager agreement negotiation or a health authority security review, because it is independent evidence that your controls operate rather than an assertion that they exist. Buyers increasingly ask for one, and having it available shortens an Alberta Commissioner submission cycle materially by removing rounds of questions about safeguards.

Related

Walk every control yourself

traztech Workspace has every control of whichever frameworks apply to you, written in plain English, with somewhere to attach the proof. Free to use, with no card and no trial clock.

No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote $11,000 off a five-figure quote on one engagement, for a documented readiness position Nothing. The audit firm prices your readiness, not your tooling

Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.

Selling health software in Alberta or BC?

We build the artifact set a western Canadian health buyer asks for, including the content behind an Alberta Commissioner submission, and run the framework work so the safeguards answer is already written.

Book a strategy call

Want the human version?

Get Jacob's take, by email

Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.