Health data in the cloud in Canada
Canadian health information law does not ban the cloud. It holds the custodian accountable, and custodians pass that down in contracts that usually require Canadian storage, audit logs and breach notification.
A Canadian health technology company can host personal health information on AWS, Azure or Google Cloud. Ontario's PHIPA and the other provincial health information laws make the health information custodian accountable, and treat you as an agent or electronic service provider with duties of your own. In practice custodians require Canadian storage, strong access logging, breach notification and often a privacy impact assessment in their contracts. If you also serve US providers, HIPAA applies to that data and the cloud provider signs a business associate agreement.
Which law applies
| Jurisdiction | Law | Cloud implications |
|---|---|---|
| Ontario | PHIPA | Electronic service provider and health information network provider duties, including audit logs and restrictions on use |
| Alberta | Health Information Act | Custodian accountability, privacy impact assessments submitted to the commissioner |
| British Columbia | Public sector and private sector privacy acts, depending on the custodian | Public bodies assess storage outside Canada |
| Quebec | Act respecting health and social services information (2023) and Law 25 | Assessment before communication outside Quebec |
| United States customers | HIPAA | Business associate agreement with you and with the cloud provider |
Provincial detail is covered on GetAudited's PHIPA page and TrazTech's PHIPA guide.
Provider programs
AWS, Microsoft and Google all sign HIPAA business associate agreements for listed services, and all publish Canadian privacy and health compliance documentation. Only use services listed as eligible for health workloads, and keep the agreement on file. For Canadian custodians, what matters more is the Canadian region and your own controls.
Controls custodians ask for
- Canadian storage and backups, enforced by policy, with DR in the second Canadian region.
- Access logging to the record level. PHIPA expects electronic audit logs of who viewed, changed or disclosed records. That means application logs, not just cloud audit logs.
- Encryption at rest and in transit, often with customer-managed keys.
- Breach notification to the custodian within a contractual period.
- Independent assurance: a SOC 2 Type 2 or ISO 27001 certificate, and a penetration test.
- A privacy impact assessment of your service, sometimes required before go-live.
Can Ontario health data be stored on AWS?
Yes. PHIPA does not prohibit cloud hosting. The custodian remains accountable and will require by contract that you protect the data, usually including storage in Canada, audit logging and breach notification.
Do we need HIPAA if we only serve Canadian clinics?
No. HIPAA applies to US covered entities and their business associates. Canadian clinics are governed by provincial health information law. Some Canadian buyers still ask for HIPAA-aligned controls as a benchmark.
Hosting health data?
Firms in the network prepare PIAs and the controls custodians require.
Get matched