When a therapy software company says their platform is “HIPAA compliant,” it sounds reassuring. But for Canadian therapists in private practice, HIPAA compliance is close to meaningless — and relying on it as a signal of data security could be leaving your clients’ most sensitive health information outside the protection of Canadian law.
PHIPA and HIPAA are not two names for the same thing. They are different laws, in different jurisdictions, with different requirements — and the gaps between them matter significantly for Canadian therapists choosing their practice management software, telehealth platforms, and clinical documentation tools.
This guide explains the difference between PHIPA vs HIPAA in plain language for Canadian therapists — what each law covers, where they overlap, where they diverge, and exactly what you need to confirm before choosing any software tool for your practice.
💡 The short answer: HIPAA is an American law that does not apply to most Canadian therapists. PHIPA is an Ontario law that applies to all health information custodians in Ontario. They overlap in some areas but differ critically on data residency and consent. A “HIPAA compliant” US platform used by a Canadian therapist is not automatically PHIPA compliant — and may be creating regulatory exposure you’re unaware of.
Understanding the Canadian Privacy Law Landscape
Unlike the United States, which has a single federal health privacy law (HIPAA), Canada uses a layered approach — one federal law plus provincial laws that overlap and in some cases supersede the federal framework:
- PIPEDA (Personal Information Protection and Electronic Documents Act): Canada’s federal private-sector privacy law. Governs how private sector organizations collect, use, and disclose personal information in commercial activities — including healthcare providers. Applies in all provinces that do not have their own substantially similar legislation.
- PHIPA (Personal Health Information Protection Act — Ontario): Ontario’s health-specific privacy legislation. More detailed and more stringent than PIPEDA in the healthcare context. Applies specifically to health information custodians in Ontario — which includes registered psychotherapists, social workers, and counsellors in private practice in the province.
- PIPA (BC and Alberta): British Columbia and Alberta have their own private-sector privacy legislation (PIPA) that has been deemed “substantially similar” to PIPEDA. BC therapists are governed by BC PIPA rather than PIPEDA federally.
- Quebec Law 25 (formerly Bill 64): Quebec’s modernized private-sector privacy regime, fully in force since 2024. Adds mandatory privacy officers, privacy impact assessments before sending data outside Quebec, and the steepest penalties in Canada.
- Health Information Act (Alberta — HIA): Alberta’s health-specific legislation governing custodians of health information.
For the purposes of this guide, we’ll focus on PHIPA (the most detailed and most commonly applicable law for Ontario therapists in private practice) and how it compares to HIPAA.
What Is HIPAA? (And Why It Doesn’t Apply to Most Canadian Therapists)
HIPAA — the Health Insurance Portability and Accountability Act — is a United States federal law enacted in 1996. It governs how “covered entities” (US healthcare providers, health plans, and healthcare clearinghouses) and their “business associates” handle protected health information (PHI).
HIPAA does not apply to Canadian organizations operating in Canada — unless those organizations handle health information for US-based covered entities (for example, a Canadian clinic that bills US insurance, or a Canadian software company that processes data for US healthcare providers).
This is the critical point that creates confusion for Canadian therapists: when a US-built software platform markets itself as “HIPAA compliant,” it is telling you it meets US legal requirements for US clients. It is not telling you it meets Canadian legal requirements for Canadian clients. Those are different things.
The most commonly used example of this gap: SimplePractice is HIPAA compliant. It explicitly states that each provider is responsible for complying with the privacy regulations applicable to their location. For a Canadian therapist using SimplePractice, PHIPA compliance is entirely the therapist’s responsibility — not the platform’s. The platform’s HIPAA compliance provides essentially no PHIPA protection.
What Is PHIPA? The Ontario Framework Every Therapist Must Understand
PHIPA is Ontario’s Personal Health Information Protection Act, enacted in 2004 and most recently amended in 2020 (with additional amendments to follow). It governs how “health information custodians” — which includes regulated health professionals such as registered psychotherapists, registered social workers, and registered nurses in private practice — collect, use, disclose, and protect personal health information (PHI).
Every Ontario therapist in private practice is a health information custodian under PHIPA. This is not optional and cannot be contracted away.
What counts as personal health information under PHIPA?
Under PHIPA, personal health information includes any identifying information about an individual that relates to:
- Their physical or mental health condition, including family medical history
- The provision of healthcare to the individual (i.e., the fact that they are your client)
- Payment for healthcare services
- Their health card number or other health identifiers
Practically, this means everything discussed in your therapy sessions, every clinical note you write, every intake form, every invoice, and every appointment record is personal health information under PHIPA and must be handled accordingly.
PHIPA vs HIPAA: The Key Differences That Matter for Your Practice
| Criteria | PHIPA (Ontario) | HIPAA (US) |
|---|---|---|
| Jurisdiction | Ontario, Canada | United States (federal) |
| Who it applies to | Health information custodians (incl. therapists) | Covered entities (US providers, plans) |
| Data residency requirement | Canadian servers strongly implied | No specific residency requirement |
| Consent standard | Express (explicit) consent required | Implied consent permitted for treatment |
| Breach notification to | IPC (Ontario) + affected individuals | HHS + affected individuals (within 60 days) |
| Right of access | Client has right to access their records | Patient has right of access |
| Applies to Canadian therapists? | YES — mandatory | NO (unless seeing US clients) |
| Key gap | HIPAA compliant ≠ PHIPA compliant — this is the critical distinction for Canadian therapists | |
The Data Residency Question: Where Your Client Data Must Live
This is the most practically significant difference between PHIPA and HIPAA for therapists choosing software tools.
HIPAA has no data residency requirement. US healthcare providers can store client data on servers in any country, provided appropriate safeguards are in place. This means a HIPAA-compliant platform may store data in the US, in Europe, or anywhere else.
PHIPA is more protective of cross-border data transfers. While PHIPA doesn’t contain an explicit blanket prohibition on storing data outside Canada, it requires health information custodians to be able to demonstrate that personal health information is protected with “comparable” safeguards regardless of where it’s stored — and the Ontario Information and Privacy Commissioner (IPC) has consistently held that data stored on US servers is subject to US law (including access by US authorities) in ways that may conflict with PHIPA’s protections.
The practical implication: for a Canadian therapist, using a platform that stores client data on US servers creates PHIPA exposure — regardless of whether that platform is HIPAA compliant. This is why data residency (Canadian servers) is one of the primary criteria for evaluating any EMR or practice management tool as a Canadian therapist. See our full EMR comparison for Canadian therapists for how major platforms compare on this criterion.
What PHIPA Compliance Actually Requires of Your Practice
Being PHIPA compliant as a Canadian therapist in private practice means:
- Obtaining express consent before collecting health information. Your informed consent and intake forms must clearly explain what information you’re collecting, why, how it will be stored, and who may have access. Implied consent — common under HIPAA — is generally not sufficient under PHIPA.
- Limiting collection to what’s necessary. The principle of data minimization: you collect only the personal health information necessary for the purpose for which it’s collected.
- Storing records securely. Physical records must be locked. Electronic records must be stored on secure, encrypted systems — ideally on Canadian servers. Your EMR must have appropriate access controls and audit logging.
- Providing clients with access to their records. Under PHIPA, clients have the right to request and receive a copy of their health records. Your records must be organized and accessible enough to fulfill this request within the required timeframe (30 days).
- Reporting breaches to the IPC and affected individuals. If there is a breach of personal health information — a lost laptop, a hacked account, an accidental disclosure — you must notify the Information and Privacy Commissioner of Ontario and, in most cases, the individuals whose information was affected.
- Retaining records for the required period. PHIPA requires health records to be retained for a minimum of 10 years from the last entry, or 10 years after a minor client reaches 18 (whichever is later). Your record-keeping system must support long-term retention.
How to Evaluate Whether Your Software Is Actually PHIPA Compliant
When evaluating any software tool for your practice — EMR, telehealth platform, AI documentation tool, booking system — ask these questions:
- Where is data stored? Ask explicitly for the data centre location(s). Canadian servers are not a guarantee of PHIPA compliance, but US-based servers are a significant flag.
- Does the company have a PHIPA compliance position? Not just “we’re HIPAA compliant” — does the company specifically acknowledge PHIPA and how their platform addresses Ontario’s requirements?
- Is there a data processing agreement available? For platforms that store personal health information on your behalf, you should be able to get a written agreement describing how they protect that data.
- Does the platform have access controls and audit logging? You should be able to see who accessed client records and when.
- What happens to data if you stop using the platform? Understand data export and deletion policies before you sign up.
Wellovis Connect is designed from the ground up to meet PHIPA, HIPAA, and GDPR requirements simultaneously — with Canadian server storage, encrypted data handling, audit logging, and data processing agreements available. This is one of the primary reasons Canadian therapists choose Wellovis Connect over US-built alternatives like SimplePractice, which are HIPAA-compliant but put PHIPA compliance responsibility on the practitioner.
📖 Related Reading
Frequently Asked Questions
Does HIPAA apply to Canadian therapists?
No — HIPAA is a US federal law that applies to US-based covered entities and their business associates. It does not apply to Canadian therapists operating in Canada, unless you handle protected health information for US covered entities (for example, billing US insurance for US-based clients). Canadian therapists are governed by Canadian privacy legislation — primarily PHIPA (Ontario), PIPA (BC/Alberta), or PIPEDA (federally) depending on their province.
What is the difference between PHIPA and HIPAA?
PHIPA is Ontario’s Personal Health Information Protection Act — it governs how health information custodians (including therapists in private practice) handle personal health information in Ontario. HIPAA is the US Health Insurance Portability and Accountability Act — it governs US healthcare providers and their business associates. The key practical differences for Canadian therapists: PHIPA requires express (explicit) consent where HIPAA allows implied consent; PHIPA creates stronger implied data residency requirements (Canadian servers preferred); and PHIPA is enforced by the Ontario Information and Privacy Commissioner rather than a US federal agency.
Is SimplePractice PHIPA compliant for Canadian therapists?
SimplePractice is HIPAA compliant — it explicitly states that each provider is responsible for complying with the privacy regulations applicable to their location. For Canadian therapists, this means PHIPA compliance is the therapist’s responsibility, not SimplePractice’s. SimplePractice’s primary infrastructure is US-based, which raises data residency concerns under PHIPA. Canadian therapists using SimplePractice should seek legal advice about their PHIPA obligations. By contrast, platforms like Wellovis Connect are designed specifically for PHIPA compliance with Canadian server storage.
What happens if a Canadian therapist is not PHIPA compliant?
The Ontario Information and Privacy Commissioner (IPC) can investigate complaints and order remedies for PHIPA violations. Penalties for serious violations can include fines. Beyond regulatory consequences, a privacy breach — particularly one involving sensitive mental health information — can result in reputational damage, loss of client trust, and professional regulatory consequences through your college (CRPO, OCSWSSW, etc.). Most professional liability insurance policies require practitioners to maintain appropriate privacy safeguards.
Does PHIPA apply if I only see virtual clients?
Yes. PHIPA applies to health information custodians in Ontario regardless of whether they see clients in person or virtually. If you are registered as a health professional in Ontario and you collect, use, or disclose personal health information about Ontario residents — which you do every time you see a client — PHIPA applies to you and your practices.




