Every healthcare provider in Canada is a custodian of some of the most sensitive personal information that exists. The legal framework governing how that information is stored, protected, and recovered is not optional.
Which Law Applies to Your Practice?
- Ontario: Personal Health Information Protection Act (PHIPA)
- British Columbia: Personal Information Protection Act (PIPA-BC)
- Alberta: Health Information Act (HIA)
- Other provinces: PIPEDA at the federal level, supplemented by provincial college requirements
What BC Privacy Legislation Specifically Requires Around Backup
In British Columbia, health information custodians are governed by either the Personal Information Protection Act (PIPA) for private practice providers or the Freedom of Information and Protection of Privacy Act (FIPPA) for health authorities and public sector health institutions. Both Acts require organizations to implement “reasonable security safeguards” to protect personal health information.
The Office of the Information and Privacy Commissioner of BC interprets this requirement to include:
- Regular, tested backups of all electronic health records with documented restore testing procedures
- Secure storage with access controls equivalent to those protecting primary records
- Offsite or secure cloud backup capabilities with encryption to prevent unauthorized access
- Written policies documenting backup procedures, retention schedules (minimum 7 years after last patient encounter), and recovery testing protocols
- Assignment of responsibility for monitoring and testing backup restoration
These policies are subject to audit and must be disclosed in privacy impact assessments when required under the BC e-Health Act for designated health information banks.
The Three Backup Gaps Most Clinics Have
No offsite copy. A fire, flood, or break-in eliminates backup and primary data simultaneously.
No immutability. Ransomware that reaches a connected backup drive encrypts it as readily as the primary data.
No tested recovery. The IPC has noted in investigation reports that practices believed they had adequate backups but discovered during a breach that recovery was incomplete or impossible.
Why Canadian Jurisdiction Matters for Health Data
Health data stored with US-owned cloud providers — even in Canadian server regions — is subject to the US Cloud Act. True compliance means storing patient data with a provider that operates exclusively under Canadian law, with no US parent company, and no pathway for foreign government data access.



