Privacy and PIA support for Canadian clinics

Last reviewed: 2026-09-26

Your file is masked in your browser and never sent to us. Use these product facts in your clinic's privacy impact assessment (PIA).

PHI Mask at a glance

Masking and OCR

In your browser

Text recognition and masking run on your device.

Processing details
Files sent to PHIMask.com

None

Your source file, masked output and recovery map are never sent to us.

What we receive
Server retention

Zero Data Retention

We keep no copy of the files or text you mask. Website and support data are separate.

Retention details
AI training

No foundation-model training

PHIMask.com does not use files, masked content or feedback to train foundation models.

Training policy
Browser storage

Stored on your device

The online tool holds work in its active tab. The extension also saves rules, contacts and conversation recovery data in your browser.

Browser storage details
Sharing with an AI service

Check the receiving service

Your clinic reviews the AI provider separately. Masked content can still be personal information.

Sharing and detection limits

Get PIA evidence

Send these product facts to your clinic's privacy lead. They complete the assessment for your clinic's workflow.

Evidence to keep with your PIA

What your clinic adds

  1. Record the workflow. Name the tool and version, who will use it, what they will mask, and where they will send the result.
  2. Document the safeguards. Include device access, browser storage and who checks the masked copy before sharing. Detection can miss identifiers.
  3. Record the review. Your privacy lead confirms the applicable law, approvals and any PIA filing. Keep the review date with the evidence.
Review the AI service your clinic choosesCheck training, locations, agreements and retention.

The service receiving a masked copy needs its own review. Keep the following evidence with the PIA or other assessment, and record who reviewed it and when.

  • What the service receives, why it uses it and whether it can use it for training.
  • Providers, subprocessors and countries where information can be accessed or stored.
  • The service role, agreement, security safeguards and incident-reporting process.
  • Retention periods and how deletion covers stored copies and backups.
Privacy Commissioner of Canada: reviewing service providers

Find your province

Which privacy law applies?Start with your organisation, province and information.

PIPEDA can apply to commercial handling of personal information. Provincial private-sector and health-information laws may apply instead of, or alongside, federal requirements.

Record who is accountable, which information is involved and whether it moves between provinces or countries.

AlbertaHIA custodians submit a PIA before covered changes.

Under the Health Information Act, custodians must submit a PIA to the OIPC before implementing a proposed administrative practice or information system involving individually identifying health information.

The clinic documents purposes, authority, information flows and safeguards. Alberta's private-sector PIPA does not impose the same PIA submission requirement. Establish whether the clinic is an HIA custodian.

OntarioA PIA is generally recommended for significant new systems.

Identify the health information custodian, its agents and each service involved under PHIPA. Document the permitted use or disclosure, safeguards and arrangements with providers.

PHIPA generally does not require a custodian to complete a PIA, but the IPC recommends one for significant new systems. Health information network providers have specific assessment duties. Check that role separately.

British ColumbiaPrivate clinics and public bodies follow different processes.

Private clinics generally assess their responsibilities under PIPA. Public bodies and work carried out for them can bring FIPPA requirements into the review.

Use the applicable process to assess collection, use, disclosure, access, retention and security. The OIPC provides separate private-sector PIA guidance.

QuebecEstablish the health-information rules before choosing an assessment.

Determine whether the organisation and health information fall under R-22.1, the Act respecting health and social services information. Other personal information can remain under private-sector rules amended by Law 25 or under public-sector privacy law.

Identify the rules for each data flow before choosing the privacy impact assessment, known in French as an EFVP. R-22.1 and the laws amended by Law 25 have different assessment and transfer provisions. Include the AI service and other recipients in that review.

Other provinces and territoriesFind your privacy regulator and the rules for your clinic.

Use the Privacy Commissioner of Canada's directory to find your provincial or territorial regulator. Your privacy lead can confirm the health-information law and PIA process for your organisation.

Compliance and security