PHIPA & Canadian Privacy Law

How CureCast supports
Canadian requirements.

Built to support PHIPA in Ontario, province-specific health privacy laws elsewhere, and PIPEDA where no provincial law applies, for clinics handling patient photos and records across Canada.

AWS infrastructure, encrypted at rest with AES-256, TLS 1.3 in transit
No federal requirement to keep data within Canada
Quebec Law 25 documentation available for privacy impact assessments
Confidential Patient Access for sensitive health information
Also supports compliance for
HIPAA GDPR Australia Privacy Act
๐Ÿ‡จ๐Ÿ‡ฆ
Canada Account
PHIPA-aligned controls
Active
Staff Access Control
Module & action-level, scoped per clinic
Audit Trail
Staff, device, IP & timestamp on every event
Device Management
End sessions on lost or stolen devices
Encryption
AES-256 at rest, TLS 1.3 in transit
๐Ÿ‡จ๐Ÿ‡ฆ Hosted on AWS ยท Quebec Law 25 documentation available
Ontario custodians
Governed by PHIPA
Breach notice
First reasonable opportunity

The regulation that applies to your practice

Canadian health privacy law depends on your province. Ontario health information custodians are governed by the Personal Health Information Protection Act (PHIPA), enforced by the Information and Privacy Commissioner of Ontario (IPC). Because PHIPA has been declared substantially similar to federal law, it, not PIPEDA, is the operative privacy law for health information held by Ontario custodians.

Outside Ontario, other provinces have their own health-specific privacy statutes, such as Alberta’s Health Information Act and BC’s Personal Information Protection Act combined with its E-Health (Personal Health Information Access and Protection of Privacy) Act. Where no province-specific health law applies, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs. Practices should confirm which law applies in their own province.

What Counts as Sensitive Data Here

Under PHIPA, a privacy breach is any loss, theft, or unauthorized use or disclosure of personal health information. This includes patient photos, clinical notes, and any identifying information collected as part of care.

 

PHIPA requires custodians to notify affected individuals at the first reasonable opportunity once the scope of a breach is understood, rather than working to a fixed deadline like GDPR’s 72 hours. Since 2019, custodians must also notify the IPC when a breach meets specific thresholds, including breaches involving unauthorized use or disclosure, theft of information, or a breach significant enough to require notifying a professional regulator. Custodians must also submit annual breach statistics to the IPC, covering all privacy breaches, not only the ones that triggered individual notification.

Data residency & Data Processing Agreement

CureCast hosts Canada data on AWS’s secure cloud infrastructure, encrypted at rest with AES-256 and protected in transit with TLS 1.3, with TLS 1.2 supported as a fallback.

Canadian federal law doesn’t require patient data to stay within Canada. PIPEDA allows data to be processed outside the country as long as comparable protection travels with it, and Ontario’s PHIPA takes the same approach rather than requiring in-province storage. CureCast’s AWS infrastructure is built to meet that bar.

 

Quebec is the exception worth knowing. Law 25 requires a privacy impact assessment before personal information leaves the province. CureCast can provide the security documentation your practice needs to complete that assessment.

 

If your practice needs a specific regional hosting arrangement, our team can discuss it directly.

How CureCast supports Canada Requirements

Staff Access Control

Administrators control staff access to patient records, clinical photos, albums, and sensitive actions through module-level and action-level permissions. For multi-location practices, access is scoped to each clinic account.
See how staff permissions work โ†’

Audit Trail

CureCast records defined activity across patient records, files, clinical modules, consent workflows, and exports, with staff, device, IP, and timestamp context. Filter and export in CSV or PDF.

See how audit trail works โ†’

Device Management

Administrators can review every device connected to their account and end a session when a device is lost, stolen, or no longer trusted. Deactivating a staff account ends sessions across their devices.

See how device-management work โ†’

Session Timeout

CureCast automatically ends inactive sessions after 2 hours on desktop and 4 hours on supported mobile devices, with a warning before logout and a required sign-in to continue.

Learn about reauthentication โ†’

Encryption

Patient records and clinical photos are encrypted at rest using AES-256 and protected in transit using TLS, with TLS 1.3 as the primary protocol and TLS 1.2 supported as a fallback.

Learn about Encryption โ†’

Confidential Patient Access

Mark a patient confidential and their record no longer appears in search results, patient lists, or before-and-after galleries for staff who don’t hold that specific permission. Only an administrator can grant it, per staff member.
Learn about Confidential Patient Access โ†’

1M+
Patient records managed on CureCast
10M+
Photos, videos and documents stored
4M+
Appointments managed
0%
Churn โ€” clinic stay because it works

Frequently asked Questions

Is CureCast PHIPA compliant?

CureCast supports PHIPA requirements. There is no official third-party PHIPA certification for software vendors. Each practice remains responsible for its own compliance.

Is patient data stored in Canada?

Canadian federal law doesn’t require patient data to stay within Canada. CureCast hosts Canada accounts on AWS’s secure cloud infrastructure, encrypted at rest with AES-256. Quebec practices have an additional requirement under Law 25, which our team can help support.

What counts as a data breach under Canadian privacy law?

Under PIPEDA, a breach must create a real risk of significant harm before notification is required, and affected individuals and the Privacy Commissioner of Canada must be notified as soon as feasible. Ontario’s PHIPA works differently: certain breaches, including theft or unauthorized disclosure, must be reported to the Information and Privacy Commissioner of Ontario at the first reasonable opportunity.

Do I need a separate agreement with CureCast for Canada use?

A Canada-specific Data Processing Agreement is separate from any US-facing agreement. Contact CureCast to confirm the right agreement for your account.

How do patients send photos to CureCast securely in Canada?

Patients can upload photos through CureCast’s secure remote upload link. No app download or account creation is required on their end.

Book a CureCast demo for clinical photo management software

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.