Dental privacy rules in Alberta and BC: the IT side

Dental privacy rules in Alberta and BC, and what they mean for your IT

Alberta HIA, Alberta PIPA, BC PIPA and Canadian Dental Association guidance, explained for the person who runs the clinic. We build the technical safeguards. Your clinic and your lawyer own the legal side.

Which privacy rules apply to a dental clinic in Alberta and British Columbia?

In Alberta, dentists are the “custodians” (the people responsible) for patient health information under the Health Information Act (HIA). Alberta PIPA, the Personal Information Protection Act, can also cover things like employee files. In British Columbia, start with BC PIPA and the standards of the British Columbia College of Oral Health Professionals (BCCOHP). The Canadian Dental Association (CDA) publishes cybersecurity guidance, and your cyber insurance policy may set rules of its own. HIPAA is a United States law, so it isn’t the yardstick for a clinic in Vancouver, Edmonton or Calgary.

How the rules line up in your city

The technical safeguards are the same in all three cities. The rulebook you check first depends on the province.

Vancouver, BC

Start with BC PIPA, the BCCOHP standards and guidance from the Office of the Information and Privacy Commissioner for BC. Our Vancouver office is on Seymour St and a local team comes to your clinic.

Dental IT support in Vancouver

Edmonton, AB

Start with the HIA, Alberta PIPA, guidance from the College of Dental Surgeons of Alberta (CDSA) and the Office of the Information and Privacy Commissioner of Alberta. A local team comes to your clinic. Our Edmonton address is for mail only.

Dental IT support in Edmonton

Calgary, AB

Calgary clinics follow the same Alberta rules as Edmonton. Our IT specialists are local in Calgary. We don’t run a walk-in office, so we come to you.

Dental IT support in Calgary

What we build on the IT side

Privacy law says what to protect. These safeguards do the protecting every day. We also offer security awareness training, with monthly report cards, because people are part of the protection. How the training works

Encryption

Patient data is protected on computers, servers and backups, so a lost device isn’t a lost chart.

Multi-factor sign in

A stolen password alone isn’t enough to reach email, remote access or practice systems. A second check, like a code on a phone, makes a stolen password far less useful.

Patching

Updates are planned around clinic hours and tested, so security fixes don’t wait for a quiet year.

Access reviews

Staff see what their role needs. When someone leaves, their access is removed.

Logging

Records of who signed in and what changed help you answer questions after something goes wrong.

Tested backups

A 3-2-1 plan with an immutable copy, locked for 30 days so it can’t be changed or deleted in that time. Restores are tested, and our offsite copy is held in Canada, in Vancouver, BC.

How backups work

Privacy impact assessments in Alberta

Under the HIA, a new system or a change in how you handle health information can call for a privacy impact assessment (PIA). That’s a written review of how the new system protects patient information. Your clinic completes it. We write up the technical side, and we work with lawyer Ritchie Po, part of our MSP, to help. Ask the OIPC and the CDSA when one is needed.

Questions to bring to your lawyer or college

  • Do we need a written agreement with an IT provider who can see patient records?
  • How long must we keep records and backups?
  • What do we do, and who do we tell, if there is a breach?
  • Where is it acceptable to store patient data?

Cyber insurance and your IT

Insurers commonly ask whether you use multi-factor sign in, tested backups and monitoring. Read your policy and answer honestly, because a claim can depend on it. We can help you gather the facts about your setup. Read about dental cybersecurity

What we don’t do

We don’t give legal advice, and we don’t certify that a clinic meets any law. Rules change, so please check current rules with the official sources and your lawyer. Last reviewed: October 3, 2026. Official sources: CDSA, Operating a Dental Practice, OIPC Alberta, reporting a privacy breach, BCCOHP and OIPC BC.

Why it matters, in plain words

The tech behind this page, and why it’s there. See all the plain guides.

Multi-factor sign in

Why a stolen password shouldn’t open the clinic’s email

Passwords leak. A second check on a phone or a security key stops most stolen passwords from working.

Read more about Multi-factor sign in

Immutable backups

Why ransomware goes after the clinic’s backups first

Without backups, the clinic has to pay or rebuild. Our copies are locked for 30 days, and no one, not even us, can delete them early.

Read more about Immutable backups

Business firewall

Why the internet company’s router isn’t a firewall

It connects you. A business firewall inspects traffic, stops known attacks and keeps guests off the clinic’s network.

Read more about Business firewall

Dental privacy questions from Alberta and BC clinics

Does HIPAA apply to my dental clinic in Canada?

No. HIPAA is a United States law. Alberta clinics look to the HIA and Alberta PIPA, and BC clinics look to BC PIPA, along with the rules of their college. Please check current rules with your lawyer.

What does the Alberta Health Information Act mean for my IT?

Dentists are custodians under the HIA. The rules can touch written agreements with IT providers, privacy impact assessments and breach reporting. We build the technical safeguards, and your lawyer advises on the legal side.

Want the IT side of your privacy duties checked?

Local teams serve Vancouver, Edmonton and Calgary. Our regular hours are Monday to Friday, 7am to 5pm MT, and our emergency line is always answered by a person. Call (604) 813-7881 for a free consult with Tony. No pressure, no jargon.