CloudCompliance

Health data in the cloud in Canada

Canadian health information law does not ban the cloud. It holds the custodian accountable, and custodians pass that down in contracts that usually require Canadian storage, audit logs and breach notification.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

A Canadian health technology company can host personal health information on AWS, Azure or Google Cloud. Ontario's PHIPA and the other provincial health information laws make the health information custodian accountable, and treat you as an agent or electronic service provider with duties of your own. In practice custodians require Canadian storage, strong access logging, breach notification and often a privacy impact assessment in their contracts. If you also serve US providers, HIPAA applies to that data and the cloud provider signs a business associate agreement.

Which law applies

Health information laws relevant to cloud hosting
JurisdictionLawCloud implications
OntarioPHIPAElectronic service provider and health information network provider duties, including audit logs and restrictions on use
AlbertaHealth Information ActCustodian accountability, privacy impact assessments submitted to the commissioner
British ColumbiaPublic sector and private sector privacy acts, depending on the custodianPublic bodies assess storage outside Canada
QuebecAct respecting health and social services information (2023) and Law 25Assessment before communication outside Quebec
United States customersHIPAABusiness associate agreement with you and with the cloud provider

Provincial detail is covered on GetAudited's PHIPA page and TrazTech's PHIPA guide.

Provider programs

AWS, Microsoft and Google all sign HIPAA business associate agreements for listed services, and all publish Canadian privacy and health compliance documentation. Only use services listed as eligible for health workloads, and keep the agreement on file. For Canadian custodians, what matters more is the Canadian region and your own controls.

Controls custodians ask for

  • Canadian storage and backups, enforced by policy, with DR in the second Canadian region.
  • Access logging to the record level. PHIPA expects electronic audit logs of who viewed, changed or disclosed records. That means application logs, not just cloud audit logs.
  • Encryption at rest and in transit, often with customer-managed keys.
  • Breach notification to the custodian within a contractual period.
  • Independent assurance: a SOC 2 Type 2 or ISO 27001 certificate, and a penetration test.
  • A privacy impact assessment of your service, sometimes required before go-live.
Can Ontario health data be stored on AWS?

Yes. PHIPA does not prohibit cloud hosting. The custodian remains accountable and will require by contract that you protect the data, usually including storage in Canada, audit logging and breach notification.

Do we need HIPAA if we only serve Canadian clinics?

No. HIPAA applies to US covered entities and their business associates. Canadian clinics are governed by provincial health information law. Some Canadian buyers still ask for HIPAA-aligned controls as a benchmark.

Hosting health data?

Firms in the network prepare PIAs and the controls custodians require.

Get matched