For Canadian practices outside Quebec
Privacy breach reporting by province: rules for therapy clinics
Privacy breach reporting by province falls into three groups. Most health privacy Acts make a clinic tell the affected individual, and several also name a regulator to tell, always or in listed cases. Nova Scotia turns the structure around and has the clinic tell the Review Officer when it decides not to notify. British Columbia’s PIPA and Saskatchewan’s HIPA have no mandatory breach notification at all, and both commissioners say so on their official pages. On the official pages we read, a private clinic in the Northwest Territories or Nunavut falls back on the federal PIPEDA test. This page lines up each rule with its official source, read on 2026-10-08.
This page is information, not legal advice. Each rule links to the official source we read on 2026-10-08; confirm it there before acting.
Last checked: 2026-10-08
Privacy breach reporting by province at a glance
The table groups jurisdictions by what the law requires. It summarizes the detailed table in the next section, where each rule links to the statute or commissioner page it came from. In the statutes and regulations we could open, none sets a number of days for a clinic’s breach notice. The wording is “first reasonable opportunity”, “as soon as practicable”, “without unreasonable delay”, “as soon as reasonably possible” or “as soon as feasible”.
| What the law requires | Where it applies | Who the clinic tells |
|---|---|---|
| Mandatory notice to the individual and a regulator | Ontario (the Commissioner in listed cases), Alberta for health-information custodians such as physiotherapists, Manitoba, New Brunswick, Prince Edward Island, Newfoundland and Labrador (the Commissioner for material breaches) and Yukon. | The affected individual and, depending on the Act, the Commissioner, Ombudsman, Ombud or Minister. |
| Mandatory notice to a regulator, which may then require notice to individuals | Alberta for private-sector organizations under PIPA. | The Information and Privacy Commissioner of Alberta. |
| Mandatory notice to the individual, and to the regulator when the clinic decides not to notify | Nova Scotia. | The individual, or the Review Officer if the clinic decides notice is not required. |
| No mandatory notice; reporting is voluntary | British Columbia (PIPA) and Saskatchewan (HIPA). | The commissioner’s office, if the clinic chooses to report. |
| Federal PIPEDA applies by default | Private clinics in the Northwest Territories and Nunavut, and information that crosses provincial or national borders anywhere. | The Privacy Commissioner of Canada and affected individuals when there is a real risk of significant harm. |
Breach notification rules for every province and territory
Read the “Who must be told, and when” column together with the statute section it cites. A few cells have conditions that matter: Ontario tells the Commissioner only in seven listed circumstances, Newfoundland and Labrador only for a “material breach”, and Alberta applies two different tests to two groups of clinicians. Where we could not read the source wording, the cell says so. Quebec is outside the scope of this page.
| Jurisdiction and law | Who it covers | What triggers a notice | Who must be told, and when | Where to report |
|---|---|---|---|---|
| Federal: PIPEDA ss. 10.1 to 10.3 and SOR/2018-64 | Organizations subject to PIPEDA, including those in the territories, which the OPC treats as federally regulated, and for information that crosses provincial or national borders.www.priv.gc.ca | A breach of security safeguards that creates a real risk of significant harm to an individual. The OPC says to weigh the sensitivity of the information and the probability of misuse.laws-lois.justice.gc.ca | The OPC and affected individuals as soon as feasible after the organization determines the breach occurred (s. 10.1), plus other organizations that can reduce harm (s. 10.2). Keep a record of every breach for 24 months (s. 10.3; Regulations s. 6).laws-lois.justice.gc.ca | The OPC’s secure online form or its PDF form.www.priv.gc.ca |
| Ontario: PHIPA s. 12 and O. Reg. 329/04 ss. 6.3 and 6.4 | Health information custodians under PHIPA.www.ontario.ca | Information is stolen or lost, or used or disclosed without authority. The Commissioner must also be told in seven listed circumstances, such as use by someone who knew they lacked authority, theft, a further unauthorized use or disclosure, a pattern, a required notice to a College, or a breach the custodian judges significant.www.ontario.ca | The individual at the first reasonable opportunity, with a statement of the right to complain to the Commissioner (s. 12(2)). The Commissioner at the first reasonable opportunity in the listed circumstances (Reg. s. 6.3). An annual count of incidents is due to the Commissioner on or before 1 March for the previous calendar year, including incidents never reported (Reg. s. 6.4).www.ontario.ca | The IPC online breach form; the IPC annual statistics page.www.ipc.on.ca |
| British Columbia: PIPA | Private-sector organizations, including healthcare providers running their own practices.www.oipc.bc.ca | PIPA has no breach-notification provision.www.bclaws.gov.bc.ca | No statutory duty or timing. The OIPC says organizations can report breaches, strongly recommends it as a best practice, and lists factors for deciding whether to notify individuals. CHCPBC licensees must report a breach in a manner that complies with privacy legislation.www.oipc.bc.ca | The OIPC online breach report form (voluntary).www.oipc.bc.ca |
| Alberta: HIA s. 60.1 and Health Information Regulation ss. 8.1 to 8.3 | Custodians, which since 22 June 2026 include physiotherapists. An affiliate tells the custodian.oipc.ab.ca | Loss of, or unauthorized access to or disclosure of, individually identifying health information where there is a risk of harm. The custodian weighs factors that include misuse, identity theft, embarrassment, effect on care and encryption.kings-printer.alberta.ca | The Commissioner, the Minister of Health and the individual, as soon as practicable. If notice could risk the individual’s mental or physical health, the custodian may decide not to give it but must immediately tell the Commissioner the decision and the reasons.kings-printer.alberta.ca | The OIPC breach page, which links the HIA form and assessment tool.oipc.ab.ca |
| Alberta: PIPA ss. 34.1 and 37.1 | Private-sector organizations with personal information under their control, including clinic records to which the HIA does not apply.oipc.ab.ca | A reasonable person would consider that there is a real risk of significant harm as a result of the loss or unauthorized access or disclosure.kings-printer.alberta.ca | The Commissioner, without unreasonable delay. The Commissioner may then require notice to individuals and set a deadline; the organization may also notify them on its own.kings-printer.alberta.ca | The OIPC breach page, which links the PIPA form.oipc.ab.ca |
| Saskatchewan: HIPA | Trustees, which include health professionals and, under the regulations, every person who owns or operates a privately owned facility where a health professional provides health services.publications.saskatchewan.ca | The Act and the 2023 Regulations contain no breach-notification section.publications.saskatchewan.ca | No statutory duty or timing. The IPC says proactive reporting is not mandatory but encouraged, and its form asks for a report within seven days of discovery. A vendor must tell the trustee of any breach of the agreement at the first reasonable opportunity (Regulations s. 7).oipc.sk.ca | The IPC proactively reported breach form.oipc.sk.ca |
| Manitoba: PHIA s. 19.0.1 and Personal Health Information Regulation ss. 8.7 to 8.9 | Trustees.web2.gov.mb.ca | A breach that could reasonably be expected to create a real risk of significant harm to the individual, after considering the factors in the regulation. In force since 1 January 2022.web2.gov.mb.ca | The individual, in writing and directly, as soon as practicable after the breach becomes known. The Ombudsman, at the time and in the form and manner the Ombudsman requires (s. 19.0.1(3) and (4)).web2.gov.mb.ca | The Ombudsman’s breach form and its key-steps guide.www.ombudsman.mb.ca |
| Nova Scotia: PHIA ss. 69 and 70 | Custodians.nslegislature.ca | Information is stolen, lost or subject to unauthorized access, use, disclosure, copying or modification, and there is potential for harm or embarrassment to the individual.nslegislature.ca | The individual at the first reasonable opportunity (s. 69). If the custodian decides on a reasonable basis that notice is not required, it must notify the Review Officer as soon as possible (s. 70).nslegislature.ca | The OIPC guide to reporting under s. 70, with its form.oipc.novascotia.ca |
| New Brunswick: PHIPAA s. 49 | Custodians.laws.gnb.ca | Personal health information is stolen, lost, disposed of except as the Act permits, or disclosed to or accessed by an unauthorized person. Section 49(2) sets an exception tied to adverse impact on care, well-being and identification; read its wording.laws.gnb.ca | The individual and the Ombud, at the first reasonable opportunity.laws.gnb.ca | The Ombud’s privacy breach notification form.ombudnb.ca |
| Prince Edward Island: HIA s. 36 | Custodians.www.princeedwardisland.ca | Personal health information is stolen, lost, disposed of except as the Act permits, or disclosed to or accessed by an unauthorized person. No duty if the custodian reasonably believes there will be no adverse impact on health care, benefits or well-being (s. 36(2)).www.princeedwardisland.ca | The individual and the Commissioner, in writing, at the first reasonable opportunity. The Commissioner’s guidelines add a written Breach Investigation Report once containment and investigation are done.www.assembly.pe.ca | The Commissioner’s privacy breach reporting guidelines.www.assembly.pe.ca |
| Newfoundland and Labrador: PHIA s. 15 and Personal Health Information Regulations s. 5 | Custodians.www.assembly.nl.ca | Information is stolen, lost, disposed of except as the Act permits, or disclosed to or accessed by an unauthorized person. The Commissioner is told of a “material breach”, judged by the sensitivity of the information, the number of people, the potential for misuse and whether the cause suggests a systemic problem.www.assembly.nl.ca | The individual at the first reasonable opportunity (s. 15(3)). The Commissioner for a material breach (s. 15(4)); the OIPC encourages custodians to report every breach.www.oipc.nl.ca | The OIPC page on reporting a privacy breach, and its form.www.oipc.nl.ca |
| Yukon: HIPMA ss. 30 and 31 | Custodians, which the IPC says include most health care providers and operators of health facilities.yukonaccountability.ca | A security breach that exposes an individual to a risk of significant harm, judged against the factors in s. 30(3).yukonaccountability.ca | The individual. If the custodian notifies the individual, it must also notify the IPC, with a copy of the notice and a written report (s. 30(2) and s. 31(1), as the IPC guide describes them). We could not open the statute’s timing wording.yukonaccountability.ca | The IPC guide for small custodians and the territorial government’s sample breach form (a sample, not an IPC form).yukon.ca |
| Northwest Territories: Health Information Act s. 87 | Health information custodians as the Act defines them: the Department, a medical practitioner, a pharmacist, and prescribed organizations or persons. We did not find private therapy clinics named, so PIPEDA is the default law for them.www.justice.gov.nt.ca | Under the Act: information used or disclosed other than as permitted, lost or stolen, or altered or destroyed without authorization.www.justice.gov.nt.ca | Under the Act: the individual and any prescribed person or organization, as soon as reasonably possible. For a private clinic under PIPEDA, see the federal row.www.justice.gov.nt.ca | The Act; the OPC’s breach reporting page for PIPEDA.www.priv.gc.ca |
| Nunavut | Private clinics. We did not find a Nunavut health-information Act that applies to private therapy clinics on the official pages we read. The OPC says PIPEDA covers organizations in Nunavut.www.priv.gc.ca | Under PIPEDA: a real risk of significant harm (see the federal row).www.priv.gc.ca | Under PIPEDA: the OPC and affected individuals as soon as feasible.www.priv.gc.ca | The OPC’s breach reporting page; the territory’s access-and-privacy statute page.www.nunavutlegislation.ca |
Row order: federal, then provinces from west to east, then the territories. The table describes what each Act or regulation says on the dates linked. It does not say whether a particular incident in a particular clinic must be reported.
Official sources
- [BR-1] Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5). Current to 21 September 2026. Breach reporting, notification and records, ss. 10.1 to 10.3; offence s. 28.
- [BR-2] Breach of Security Safeguards Regulations (SOR/2018-64). Current to 21 September 2026. Section 6 requires a record of every breach for 24 months after the day the organization determines the breach occurred.
- [BR-3] Office of the Privacy Commissioner of Canada: what you need to know about mandatory reporting of breaches. Real risk of significant harm, what the report must contain, and keeping records of all breaches. The page moved from its earlier address.
- [BR-4] Personal Health Information Protection Act, 2004 (Ontario). Consolidation period from 1 January 2026, e-Laws currency date 6 October 2026. Section 12.
- [BR-5] Ontario Regulation 329/04 under PHIPA. Same currency. Section 6.3 sets the seven circumstances and the timing; section 6.4 sets the annual report.
- [BR-6] Personal Information Protection Act (British Columbia). Current to 22 September 2026. The text contains no breach-notification provision.
- [BR-7] Health Information Act (Alberta). Current as of 2 July 2026. Section 60.1.
- [BR-8] Health Information Regulation, AR 70/2001 (Alberta). Current as of 2 July 2026. Sections 8.1 to 8.3 on risk of harm and notices. Expires 30 April 2027 unless repassed.
- [BR-9] Personal Information Protection Act (Alberta). Current as of 1 September 2025. Sections 34.1 and 37.1.
- [BR-10] The Health Information Protection Act (Saskatchewan). Consolidation with amendments through 2024 c 4. The text has no breach-notification section.
- [BR-11] The Health Information Protection Regulations, 2023 (Saskatchewan). In force 1 August 2023. Section 4 prescribes trustees; section 7 requires an information management service provider to notify the trustee of a breach of the agreement at the first reasonable opportunity.
- [BR-12] The Personal Health Information Act (Manitoba), C.C.S.M. c. P33.5. Current as of 6 October 2026. Section 19.0.1, in force 1 January 2022.
- [BR-13] Personal Health Information Regulation, M.R. 245/97 (Manitoba). Sections 8.7 to 8.9 on risk factors and the form and manner of notice.
- [BR-14] Personal Health Information Act (Nova Scotia). Consolidated 1 April 2026. Sections 69 and 70.
- [BR-15] Personal Health Information Privacy and Access Act (New Brunswick). Consolidated to 1 January 2024. Section 49.
- [BR-16] Health Information Act (Prince Edward Island). Current to 30 March 2026. Section 36.
- [BR-17] Personal Health Information Act (Newfoundland and Labrador). Section 15 and the regulation-making power for material breach.
- [BR-18] Health Information Act (Northwest Territories). Consolidation shows amendments to SNWT 2026 c. 2. Custodian definition and section 87.
- [BR-19] Yukon Information and Privacy Commissioner: HIPMA guide for small custodians. March 2026 file. Describes mandatory breach notification in ss. 30 and 31.
Federal PIPEDA: the territories, cross-border information and breach records
PIPEDA applies to private-sector organizations that collect, use or disclose personal information in the course of commercial activity. The Office of the Privacy Commissioner of Canada (OPC) says organizations in the Northwest Territories, Yukon and Nunavut are considered federally regulated and are covered by PIPEDA, and that businesses handling personal information that crosses provincial or national borders are subject to it even in provinces with similar laws [BR-3] [BR-20]. Alberta’s and British Columbia’s private-sector Acts and the health Acts of Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador are the laws the OPC lists as substantially similar; Manitoba’s, Saskatchewan’s, Prince Edward Island’s and Yukon’s laws are not on that list, so whether PIPEDA also applies to a fee-for-service clinic there is a question for the OPC or counsel [BR-21].
Under PIPEDA a breach of security safeguards must be reported to the OPC and notified to affected individuals when it is reasonable to believe it creates a real risk of significant harm, as soon as feasible after the organization determines that the breach has occurred (s. 10.1) [BR-1]. The OPC says the risk turns on the sensitivity of the information and the probability of misuse [BR-3]. Every breach must be recorded, whether or not it is reportable, and the record is kept for 24 months after the day the organization determines the breach occurred [BR-2]. Knowingly contravening the reporting, notification or record-keeping duties is an offence (s. 28) [BR-1].
Official sources
- [BR-20] Office of the Privacy Commissioner of Canada: PIPEDA requirements in brief. Who PIPEDA covers, cross-border flows, and the note about the three territories.
- [BR-21] Office of the Privacy Commissioner of Canada: provincial laws that may apply instead of PIPEDA. The substantially similar private-sector and health laws, and where PIPEDA still applies.
Where breach reporting is voluntary: British Columbia and Saskatchewan
British Columbia. PIPA contains no breach-notification provision [BR-6]. The Information and Privacy Commissioner’s breach page says the Commissioner continues to call on government to amend PIPA to require organizations to report breaches to the OIPC and to affected individuals facing a risk of significant harm. In the meantime: “we strongly recommend that breaches be reported to our office as a best practice.” [BR-22] The OIPC’s quick reference for small and medium-sized businesses lists containment, risk assessment, notification and reporting, and prevention, and says organizations can report breaches to the OIPC [BR-23]. For regulated professionals, the CHCPBC Privacy and Confidentiality standard (s. 7) requires a breach to be contained promptly and reported in a manner that complies with privacy legislation [BR-24].
Saskatchewan. The Health Information Protection Act as consolidated through 2024 has no breach-notification section, and the 2023 Regulations mention a breach only in the clause that makes a vendor tell the trustee of a breach of its agreement [BR-10] [BR-11]. The Information and Privacy Commissioner’s guidelines for trustees list the affected individuals among those to notify unless there are compelling reasons not to, and say: “While not mandatory, the IPC does encourage organizations to proactively report.” [BR-25] The Commissioner’s form for proactive reports asks that it be sent within seven days of discovery, or shortly after; that is the form’s request and not a statutory deadline [BR-26].
Voluntary does not mean optional for every clinic. A Saskatchewan or British Columbia clinic may still owe a notice under a contract, a funder’s agreement, a professional regulator’s standard or the federal rules described above, and this page does not cover those. Ask the regulator of each clinician and your own counsel.
Official sources
- [BR-22] OIPC British Columbia: report a privacy breach (organizations and public bodies). States that public bodies must notify the Commissioner and individuals, and that the Commissioner calls on government to extend the duty to organizations under PIPA.
- [BR-23] OIPC British Columbia: privacy breach quick reference guide for small and medium-sized businesses. Four steps for responding to a breach, and when to report to the OIPC.
- [BR-24] CHCPBC Practice Standard: Privacy and Confidentiality. Effective 1 April 2026. Section 7.
- [BR-25] Saskatchewan Information and Privacy Commissioner: privacy breach guidelines for trustees. Containment, notification, investigation, prevention, and proactive reporting.
- [BR-26] Saskatchewan Information and Privacy Commissioner: proactively reported breach of privacy form. The form asks for a report within seven days of discovery and describes the investigation questionnaire that follows.
What to record: incident logs, annual counts and breach records
Two sources require records of incidents, not only notices. PIPEDA requires a record of every breach of security safeguards for 24 months, reportable or not [BR-2]. Ontario requires each custodian to give the Commissioner, on or before 1 March, the number of times in the previous calendar year that information was stolen, lost, used without authority or disclosed without authority, or collected without authority through the electronic health record; the IPC’s page lists the breakdowns it expects, such as theft by an internal party or a stranger, ransomware or another cyberattack, and the number of individuals affected [BR-27].
Our reading: a clinic in Ontario has to be able to count incidents by type at the end of each year, including ones it never reported, which in practice means keeping a running incident log. The Ontario IPC page tells custodians to keep this information over the course of the calendar year so they are ready to report, and the pages we read for other provinces do not set an equivalent annual count.
Official sources
- [BR-27] Information and Privacy Commissioner of Ontario: annual reporting of health privacy breach statistics. Quotes O. Reg. 329/04 s. 6.4 and lists the information the annual report requires.
Mixed clinics: Alberta’s two tests in one building
Alberta is the one province where one clinic can be subject to two breach tests. Physiotherapists became custodians under the Health Information Act on 22 June 2026, so their records follow the “risk of harm” test and a three-way notice to the Commissioner, the Minister and the individual. Occupational therapists, speech-language pathologists and psychologists are not on the list of custodian colleges, so their clinic records follow PIPA’s “real risk of significant harm” test and a notice to the Commissioner [BR-7] [BR-9] [BR-28]. We did not find guidance from the Alberta OIPC on how a clinic divides one incident between the two laws, so ask the OIPC or counsel. The Alberta page sets out who is a custodian and where each profession’s college standards sit.
Official sources
- [BR-28] Health Information (Ministerial) Regulation, AR 106/2026 (Alberta). Current as of 2 July 2026. Names the 13 colleges whose regulated members are custodians, including physiotherapists.
Privacy breach reporting dates to watch
Every date below is absolute and links to the official page that states it. Re-read the page before a date arrives, because dates and wording on government pages change.
| Date | What happens |
|---|---|
| 1 January 2022 | Manitoba’s PHIA breach notification section, s. 19.0.1, comes into force.web2.gov.mb.ca |
| 1 August 2023 | Saskatchewan’s Health Information Protection Regulations, 2023, come into force; they contain no breach-notification section.publications.saskatchewan.ca |
| 22 June 2026 | Alberta physiotherapists become custodians under the Health Information Act, adding the HIA breach test to mixed clinics.oipc.ab.ca |
| 1 March each year | Ontario custodians send the Commissioner the annual count of incidents for the previous calendar year.www.ipc.on.ca |
| 30 April 2027 | Alberta’s Health Information Regulation (AR 70/2001), which holds the breach-content rules, expires unless it is repassed.kings-printer.alberta.ca |
Official breach reporting pages and forms
These are the regulator pages and forms a clinic is least likely to find from a general government site. Each line says what the page holds. Several regulator sites block automated tools, so a page that loads for you may still fail a scripted link check.
Official sources
- [BR-29] Information and Privacy Commissioner of Ontario: report a privacy breach at your organization. Online form for health information custodians; lists the PHIPA subsection and regulation that require the report.
- [BR-30] OIPC Alberta: how to notify the OIPC of a privacy breach. HIA and PIPA breach forms, the HIA assessment tool, and the section references for each test.
- [BR-31] Manitoba Ombudsman: privacy breach key steps for FIPPA and PHIA. Steps to contain, evaluate and notify as soon as possible, and how to assess real risk of significant harm.
- [BR-32] OIPC Nova Scotia: reporting breaches under s. 70 of PHIA. The form and instructions for telling the Review Officer when notification is not required. The printed date is 24 January 2022.
- [BR-33] Office of the Ombud New Brunswick: privacy breach notification form. Last revised July 2025. The four steps and who to notify.
- [BR-34] Prince Edward Island Information and Privacy Commissioner: privacy breach reporting guidelines. April 2024. Who to notify, the four actions the Commissioner expects, and the Breach Investigation Report.
- [BR-35] OIPC Newfoundland and Labrador: how to report a privacy breach. Material breach factors and the reporting email address.
- [BR-36] OIPC Newfoundland and Labrador: reporting a privacy breach form. The PHIA reporting form.
- [BR-37] Government of Yukon: sample breach reporting form. Last updated 25 June 2016. A sample under HIPMA from the Department of Health and Social Services, not an IPC form.
- [BR-38] Yukon Information and Privacy Commissioner: Acts. Describes HIPMA, in force 31 August 2016, and the custodians it covers.
- [BR-39] Nunavut Legislation: Access to Information and Protection of Privacy Act, official consolidation. Current version from 31 May 2024. The page links the PDF; we did not read the PDF text.
- [BR-40] Office of the Privacy Commissioner of Canada: PIPEDA breach report form. PDF version of the breach report form.
How TherapyCRM fits
TherapyCRM is practice management software with a clinical record, for English-language clinics in Canada outside Quebec. It has an audit log of activity on practice records that staff with the audit-log permission can review, which a clinic can use when it investigates what happened in an incident. TherapyCRM does not decide whether a breach must be reported, and it does not replace a clinic’s incident log, its breach response plan or advice from its regulators, the commissioner’s office or counsel. TherapyCRM holds no privacy or security certification.
Frequently asked questions
Is BC PIPA breach notification mandatory?
No. PIPA has no breach-notification provision. The Commissioner says organizations can report breaches to the OIPC, strongly recommends it as a best practice and calls on government to amend PIPA to require it. CHCPBC licensees must still report a breach in a manner that complies with privacy legislation.
Is Saskatchewan HIPA breach reporting mandatory?
The Health Information Protection Act and the 2023 Regulations have no breach-notification section. The Information and Privacy Commissioner says proactive reporting is not mandatory but is encouraged, and its form asks for a report within seven days of discovery. Vendors must tell the trustee of a breach of their agreement at the first reasonable opportunity.
Which provinces require a clinic to tell both the individual and a regulator?
Manitoba (the individual and the Ombudsman), New Brunswick (the individual and the Ombud), Prince Edward Island (the individual and the Commissioner) and Alberta for health-information custodians (the Commissioner, the Minister and the individual). Ontario and Newfoundland and Labrador tell the Commissioner only in listed or material cases, and Yukon requires a report to the IPC when the individual is notified.
Must an Ontario clinic report every privacy breach to the IPC?
No. A custodian notifies the individual of a theft, loss or unauthorized use or disclosure at the first reasonable opportunity, and notifies the Commissioner only in the seven circumstances in O. Reg. 329/04 s. 6.3. Every custodian must, however, send the Commissioner an annual count of incidents on or before 1 March, including incidents it never reported.
What breach rule applies to a private clinic in the Northwest Territories or Nunavut?
On the official pages we read, PIPEDA is the default law. The OPC says organizations in the three territories are considered federally regulated, and PIPEDA requires reporting to the OPC and notifying individuals as soon as feasible when a breach creates a real risk of significant harm, and keeping a record of every breach for 24 months.
Do Alberta clinics follow one breach test or two?
Two, if the clinic has a physiotherapist and another therapy profession. HIA custodians use a risk-of-harm test and notify the Commissioner, the Minister and the individual as soon as practicable. PIPA organizations use a real-risk-of-significant-harm test and notify the Commissioner without unreasonable delay. We found no OIPC guidance on dividing records between the two.
How quickly must a clinic report a privacy breach?
No statute or regulation we could open sets a number of days. The wording is first reasonable opportunity, as soon as practicable, without unreasonable delay, as soon as reasonably possible or as soon as feasible, depending on the law. Saskatchewan’s voluntary form asks for a report within seven days of discovery, but that is a request and not a legal deadline.
Does Nova Scotia require a clinic to tell the regulator about a breach?
Only when the clinic decides not to notify the individual. A custodian notifies the individual at the first reasonable opportunity when information is stolen, lost or accessed without authority and there is potential for harm or embarrassment (s. 69). If it decides on a reasonable basis that notice is not required, it notifies the Review Officer as soon as possible (s. 70).