Free for a week, then $19 for your first month
Expert Advice

How Twofold Handles PIPEDA and PHIPA: Canadian Privacy Compliance for Clinicians (2026)

A plain-language guide to how Twofold handles Canadian privacy law — PIPEDA, PHIPA, Alberta's HIA and Quebec — and what your practice still has to do.

A shield with a maple leaf joined to a clinic building and a secured document — how Twofold and a Canadian practice share privacy responsibilities.

Canada doesn't have one health privacy law. A private practice may be governed by the federal Personal Information Protection and Electronic Documents Act (PIPEDA), by a provincial health information law such as Ontario's Personal Health Information Protection Act (PHIPA), or by both at different times. Each defines the vendor's role a little differently.

This article explains how Twofold, an AI scribe for clinicians, handles each of those frameworks: what Twofold commits to, what it signs, where the data goes, and which obligations stay with your practice. It is written for psychotherapists, counsellors, psychologists, social workers and physicians evaluating Twofold, and for the privacy officers who review it. If you are still comparing tools, see the best AI scribes for Canadian therapists.

Which privacy law applies to your practice?

It depends on your province and the kind of information.

  • Ontario: PHIPA governs personal health information held by health information custodians, including regulated health professionals in private practice.
  • Alberta: the Health Information Act (HIA) governs custodians designated under it. Some private practitioners fall under Alberta's Personal Information Protection Act (PIPA) instead — check which applies to your profession.
  • Quebec: since July 2024, health information held by private clinics, including psychologists' practices, is governed by the Act respecting health and social services information, alongside the private-sector privacy act amended by Law 25.
  • Other provinces: PIPEDA applies to personal information handled in commercial activity unless a provincial law has been recognized as substantially similar.
How Twofold's role changes by province. Ontario, under PHIPA: Twofold works on the custodian's behalf and meets the restrictions on electronic service providers. Alberta, under the Health Information Act: Twofold signs an information manager agreement. Quebec, under the Act respecting health and social services information: Twofold signs a written mandate and supplies material for the privacy impact assessment. Elsewhere, under PIPEDA: Twofold is a service provider with a designated accountable individual and breach reporting.

How does Twofold meet PHIPA in Ontario?

Twofold processes personal health information on behalf of your practice. Under PHIPA, a vendor in that position is either the custodian's agent or an electronic service provider, and either way the substance of the rules is the same:

  • Use only for the service. Twofold uses personal health information only as necessary to produce your documentation.
  • No disclosure. Twofold does not disclose it.
  • Bound staff. Twofold does not let anyone access it who has not agreed to the same restrictions.
  • You stay responsible. Your practice remains the health information custodian and stays accountable to the patient (PHIPA s. 17).

These obligations apply to Twofold directly, with or without a separate contract, because they come from the Act and its regulation (O. Reg. 329/04, s. 6) rather than from an agreement.

How does Twofold meet PIPEDA?

PIPEDA's ten fair information principles apply to Twofold as an organization. The ones that matter most to a clinic:

  • Accountability (Principle 4.1). Twofold has designated a Security Official as the individual accountable for its privacy compliance.
  • Openness (Principle 4.8). Twofold publishes its privacy practices in its privacy policy and on its security page.
  • Breach reporting (s. 10.1). Where a breach of information Twofold holds in its own right poses a real risk of significant harm, Twofold reports it to the Office of the Privacy Commissioner of Canada and notifies affected individuals. For health information it holds for your practice, Twofold notifies you, the custodian, at the first reasonable opportunity.
  • Breach records (s. 10.3). Twofold keeps a record of every breach of security safeguards, regardless of severity. The law requires those records to be kept for at least 24 months.

What does Twofold sign for Alberta and Quebec?

Both provinces require a written agreement before a custodian gives health information to a service provider.

  • Alberta. Under the Health Information Act (s. 66(2)), a custodian must have a written agreement with an information manager. Twofold signs an information manager agreement. Alberta's Health Information Regulation (s. 8(4)) also requires a written agreement before health information is stored outside Alberta; ask Twofold to confirm it is covered in your agreement.
  • Quebec. Twofold signs a written mandate. Before health information is communicated outside Quebec, the clinic must complete a privacy impact assessment and be satisfied the information will be adequately protected. Twofold supplies the architecture, hosting, security and retention documentation that assessment needs.

Does my data have to stay in Canada?

No — not for a private practice. Neither PIPEDA nor PHIPA requires health information to be stored in Canada. The Privacy Commissioner of Canada treats sending information to a service provider abroad as a use, not a prohibited transfer, provided it's protected and patients are told it may be processed in another country and accessible to foreign authorities.

Alberta and Quebec set conditions rather than bans: the agreements and the assessment described above. British Columbia's data‑residency rule applied only to public bodies and was repealed in 2021.

Twofold stores and processes information in the United States, on Microsoft Azure and Google Cloud. It does not offer Canadian hosting. If your organization's own policy requires Canadian storage, Twofold is not the right fit.

What stays your practice's responsibility?

Twofold's commitments don't replace yours. As the custodian, your practice still:

  • Obtains the patient's consent to record the session, as your regulatory college requires, and documents it.
  • Tells patients that their information may be processed outside Canada.
  • Responds to access and correction requests about the clinical record. Twofold directs any request it receives to you.
  • Completes any privacy impact assessment your province or organization requires, using the material Twofold provides.
  • Reviews every AI draft before signing it.
Division of privacy responsibilities between a Canadian practice and Twofold. The practice, as custodian: patient consent to record, telling patients data may be processed outside Canada, access and correction requests, privacy impact assessments, and reviewing every AI draft. Twofold, working on the practice's behalf: uses health information only to provide the service, never discloses it, limits access to bound staff, notifies the custodian of breaches, reports qualifying breaches to the Privacy Commissioner of Canada, and signs Alberta and Quebec agreements.

This article explains how Twofold approaches Canadian privacy law as of September 2026. It is general information, not legal advice. Your obligations depend on your province, profession and practice; confirm them with your regulatory college or a privacy adviser.

References

FAQ

Frequently asked questions

  • Is Twofold PIPEDA compliant?

    Yes. Twofold has a designated individual accountable for privacy compliance, publishes its practices, reports breaches posing a real risk of significant harm to the Office of the Privacy Commissioner of Canada, and keeps a record of every breach.

  • Is Twofold PHIPA compliant?

    Yes. In Ontario, Twofold uses personal health information only as necessary to provide the documentation service, does not disclose it, and limits access to staff who have agreed to the same restrictions. Your practice remains the custodian and accountable to the patient.

  • Where does Twofold store Canadian patient data?

    In the United States, on Microsoft Azure and Google Cloud. Canadian law doesn't require private practices to store health information in Canada, but Alberta and Quebec require an agreement or an assessment first, and Twofold provides both.

  • Does Twofold sign an information manager agreement in Alberta?

    Yes. Twofold signs an information manager agreement under Alberta's Health Information Act, and a written mandate for Quebec clinics.

  • Does Twofold use my patients' information to train AI models?

    No. Twofold states that information is never used for marketing and never used to train or fine‑tune models.

  • Who do I complain to about Twofold's privacy practices?

    First to Twofold, at info@trytwofold.com. You can also complain to the Office of the Privacy Commissioner of Canada or to your provincial commissioner.