Local teams serve Vancouver, Edmonton and Calgary. Our regular hours are Monday to Friday, 7am to 5pm MT, and our emergency line is always answered by a person. Call (604) 813-7881 for a free consult with Tony. No pressure, no jargon.
Dental privacy rules in Alberta and BC: the IT side
Dental privacy rules in Alberta and BC, and what they mean for your IT
Alberta HIA, Alberta PIPA, BC PIPA and Canadian Dental Association guidance, explained for the person who runs the clinic. We build the technical safeguards. Your clinic and your lawyer own the legal side.
Which privacy rules apply to a dental clinic in Alberta and British Columbia?
In Alberta, dentists are the “custodians” (the people responsible) for patient health information under the Health Information Act (HIA). Alberta PIPA, the Personal Information Protection Act, can also cover things like employee files. In British Columbia, start with BC PIPA and the standards of the British Columbia College of Oral Health Professionals (BCCOHP). The Canadian Dental Association (CDA) publishes cybersecurity guidance, and your cyber insurance policy may set rules of its own. HIPAA is a United States law, so it isn’t the yardstick for a clinic in Vancouver, Edmonton or Calgary.
How the rules line up in your city
The technical safeguards are the same in all three cities. The rulebook you check first depends on the province.
Vancouver, BC
Start with BC PIPA, the BCCOHP standards and guidance from the Office of the Information and Privacy Commissioner for BC. Our Vancouver office is on Seymour St and a local team comes to your clinic.
Edmonton, AB
Start with the HIA, Alberta PIPA, guidance from the College of Dental Surgeons of Alberta (CDSA) and the Office of the Information and Privacy Commissioner of Alberta. A local team comes to your clinic. Our Edmonton address is for mail only.
Calgary, AB
Calgary clinics follow the same Alberta rules as Edmonton. Our IT specialists are local in Calgary. We don’t run a walk-in office, so we come to you.
What we build on the IT side
Privacy law says what to protect. These safeguards do the protecting every day. We also offer security awareness training, with monthly report cards, because people are part of the protection. How the training works
Encryption
Patient data is protected on computers, servers and backups, so a lost device isn’t a lost chart.
Multi-factor sign in
A stolen password alone isn’t enough to reach email, remote access or practice systems. A second check, like a code on a phone, makes a stolen password far less useful.
Patching
Updates are planned around clinic hours and tested, so security fixes don’t wait for a quiet year.
Access reviews
Staff see what their role needs. When someone leaves, their access is removed.
Logging
Records of who signed in and what changed help you answer questions after something goes wrong.
Tested backups
A 3-2-1 plan with an immutable copy, locked for 30 days so it can’t be changed or deleted in that time. Restores are tested, and our offsite copy is held in Canada, in Vancouver, BC.
Privacy impact assessments in Alberta
Under the HIA, a new system or a change in how you handle health information can call for a privacy impact assessment (PIA). That’s a written review of how the new system protects patient information. Your clinic completes it. We write up the technical side, and we work with lawyer Ritchie Po, part of our MSP, to help. Ask the OIPC and the CDSA when one is needed.
Questions to bring to your lawyer or college
- Do we need a written agreement with an IT provider who can see patient records?
- How long must we keep records and backups?
- What do we do, and who do we tell, if there is a breach?
- Where is it acceptable to store patient data?
Cyber insurance and your IT
Insurers commonly ask whether you use multi-factor sign in, tested backups and monitoring. Read your policy and answer honestly, because a claim can depend on it. We can help you gather the facts about your setup. Read about dental cybersecurity
What we don’t do
We don’t give legal advice, and we don’t certify that a clinic meets any law. Rules change, so please check current rules with the official sources and your lawyer. Last reviewed: October 3, 2026. Official sources: CDSA, Operating a Dental Practice, OIPC Alberta, reporting a privacy breach, BCCOHP and OIPC BC.
Why it matters, in plain words
The tech behind this page, and why it’s there. See all the plain guides.
Multi-factor sign in
Why a stolen password shouldn’t open the clinic’s email
Passwords leak. A second check on a phone or a security key stops most stolen passwords from working.
Immutable backups
Why ransomware goes after the clinic’s backups first
Without backups, the clinic has to pay or rebuild. Our copies are locked for 30 days, and no one, not even us, can delete them early.
Business firewall
Why the internet company’s router isn’t a firewall
It connects you. A business firewall inspects traffic, stops known attacks and keeps guests off the clinic’s network.
Dental privacy questions from Alberta and BC clinics
Does HIPAA apply to my dental clinic in Canada?
No. HIPAA is a United States law. Alberta clinics look to the HIA and Alberta PIPA, and BC clinics look to BC PIPA, along with the rules of their college. Please check current rules with your lawyer.
What does the Alberta Health Information Act mean for my IT?
Dentists are custodians under the HIA. The rules can touch written agreements with IT providers, privacy impact assessments and breach reporting. We build the technical safeguards, and your lawyer advises on the legal side.
