Privacy and PIA support for Canadian clinics
Last reviewed: 2026-09-26
Your file is masked in your browser and never sent to us. Use these product facts in your clinic's privacy impact assessment (PIA).
PHI Mask at a glance
- Masking and OCR
In your browser
Text recognition and masking run on your device.
Processing details- Files sent to PHIMask.com
None
Your source file, masked output and recovery map are never sent to us.
What we receive- Server retention
Zero Data Retention
We keep no copy of the files or text you mask. Website and support data are separate.
Retention details- AI training
No foundation-model training
PHIMask.com does not use files, masked content or feedback to train foundation models.
Training policy- Browser storage
Stored on your device
The online tool holds work in its active tab. The extension also saves rules, contacts and conversation recovery data in your browser.
Browser storage details- Sharing with an AI service
Check the receiving service
Your clinic reviews the AI provider separately. Masked content can still be personal information.
Sharing and detection limits
Get PIA evidence
Send these product facts to your clinic's privacy lead. They complete the assessment for your clinic's workflow.
Evidence to keep with your PIA
- PHI Mask vendor attestation
Dated product statements, scope and exclusions. Save a PDF from the attestation.
- Processing, storage and data residency
What stays in the browser and what PHIMask.com receives.
- Website and support data
The separate handling of operational metadata and information you submit.
What your clinic adds
- Record the workflow. Name the tool and version, who will use it, what they will mask, and where they will send the result.
- Document the safeguards. Include device access, browser storage and who checks the masked copy before sharing. Detection can miss identifiers.
- Record the review. Your privacy lead confirms the applicable law, approvals and any PIA filing. Keep the review date with the evidence.
Review the AI service your clinic choosesCheck training, locations, agreements and retention.
The service receiving a masked copy needs its own review. Keep the following evidence with the PIA or other assessment, and record who reviewed it and when.
- What the service receives, why it uses it and whether it can use it for training.
- Providers, subprocessors and countries where information can be accessed or stored.
- The service role, agreement, security safeguards and incident-reporting process.
- Retention periods and how deletion covers stored copies and backups.
Find your province
Which privacy law applies?Start with your organisation, province and information.
PIPEDA can apply to commercial handling of personal information. Provincial private-sector and health-information laws may apply instead of, or alongside, federal requirements.
Record who is accountable, which information is involved and whether it moves between provinces or countries.
AlbertaHIA custodians submit a PIA before covered changes.
Under the Health Information Act, custodians must submit a PIA to the OIPC before implementing a proposed administrative practice or information system involving individually identifying health information.
The clinic documents purposes, authority, information flows and safeguards. Alberta's private-sector PIPA does not impose the same PIA submission requirement. Establish whether the clinic is an HIA custodian.
OntarioA PIA is generally recommended for significant new systems.
Identify the health information custodian, its agents and each service involved under PHIPA. Document the permitted use or disclosure, safeguards and arrangements with providers.
PHIPA generally does not require a custodian to complete a PIA, but the IPC recommends one for significant new systems. Health information network providers have specific assessment duties. Check that role separately.
British ColumbiaPrivate clinics and public bodies follow different processes.
Private clinics generally assess their responsibilities under PIPA. Public bodies and work carried out for them can bring FIPPA requirements into the review.
Use the applicable process to assess collection, use, disclosure, access, retention and security. The OIPC provides separate private-sector PIA guidance.
QuebecEstablish the health-information rules before choosing an assessment.
Determine whether the organisation and health information fall under R-22.1, the Act respecting health and social services information. Other personal information can remain under private-sector rules amended by Law 25 or under public-sector privacy law.
Identify the rules for each data flow before choosing the privacy impact assessment, known in French as an EFVP. R-22.1 and the laws amended by Law 25 have different assessment and transfer provisions. Include the AI service and other recipients in that review.
Other provinces and territoriesFind your privacy regulator and the rules for your clinic.
Use the Privacy Commissioner of Canada's directory to find your provincial or territorial regulator. Your privacy lead can confirm the health-information law and PIA process for your organisation.