On this page

HIPAA is a US law, not Canadian law, but it can still reach a Canadian vendor. If you create, receive, maintain, or transmit protected health information (PHI) on behalf of a HIPAA covered entity or another business associate, you can have direct business-associate duties on top of any BAA, and a missing BAA does not remove them. Canadian privacy law is assessed separately for each activity: PIPEDA or a substantially similar provincial law, plus health laws such as Ontario’s PHIPA.

HIPAA regulates covered entities and their business associates. The relevant question is what work you perform and whose protected health information (PHI) you handle, not simply the patient’s citizenship. HHS’s business-associate guidance explains that certain HIPAA provisions apply directly to business associates. Start with our HIPAA overview for the framework’s scope, and our compliance framework comparison for how SOC 2 stacks up against the other frameworks.

How HIPAA’s Rules Cross the Border into Canada

Smiling businessman using laptop with a Canada-USA map and US flag contract documents, representing international agreements.

Serving Canadian customers does not automatically make an organization a HIPAA covered entity or business associate. But creating, receiving, maintaining, or transmitting PHI on behalf of a HIPAA covered entity or business associate may make your service a business-associate function. Assess the relationship and data flows before accepting the work.

A Business Associate Agreement (BAA) is required for a business-associate relationship and sets permitted uses, safeguards, reporting, and other duties. Signing it is not what creates business-associate status. HHS’s cloud-computing guidance, question 5 says a provider that meets the definition must comply with applicable HIPAA provisions even without an executed BAA. The agreement adds enforceable terms; it does not replace direct obligations.

Put the required BAA in place before the service handles PHI, and check its permitted uses, subcontractor requirements, security duties, and reporting timelines. HHS OCR FAQ 2083 permits offshore cloud storage when the HIPAA requirements are met. Address location risks in the Security Rule risk analysis and check any additional hosting restriction in the customer’s contract.

Failure to meet these BAA obligations can lead to severe consequences:

  • Contractual Liability: Review indemnities, liability limits, and remedies in the agreement; responsibility for the customer’s losses is not automatic in every breach.
  • Contract Termination: A material violation may require efforts to cure the issue or termination, depending on the applicable requirements and circumstances.
  • Customer Due Diligence: An incident may prompt additional evidence requests, safeguards, or a reassessment of the relationship.

Use the BAA and applicable legal duties to identify relevant service commitments and risks. A HIPAA Security Rule risk analysis can inform risk identification and analysis under CC3.2, but a SOC 2 examination does not automatically assess every HIPAA requirement.

Understanding Canada’s Data Privacy Maze

Canada has federal and provincial privacy regimes. The US also has state health-privacy laws alongside HIPAA. Identify which rules apply to your organization’s role, activities, and data flows rather than treating either country as a single-law jurisdiction.

Document the applicable requirements and the controls intended to meet them. For SOC 2, agree the system, service commitments, categories, and controls in scope with the auditor. The report provides assurance within that scope; it is not a legal opinion that every applicable privacy law has been satisfied.

The Federal Baseline: PIPEDA

The Personal Information Protection and Electronic Documents Act (PIPEDA) covers private-sector commercial activities within its scope. The Office of the Privacy Commissioner of Canada explains the provincial exemptions and continuing application to interprovincial and international commercial data flows. Bill C-36, introduced on 15 June 2026, proposes privacy-law changes; Parliament lists it at second reading as of 2 October 2026. It has not replaced PIPEDA.

Organizations subject to a substantially similar provincial law are generally exempt from PIPEDA for the covered activities within that province. PIPEDA can still govern cross-border commercial flows and federally regulated organizations. Where Privacy is included in your SOC 2 scope, explain how notices, consent, and other controls address the commitments relevant to the system.

Canada has no single health-privacy law identical to HIPAA. PIPEDA, provincial private-sector laws, and health-specific laws such as Ontario’s PHIPA have different scopes. Determine which applies to the activity before designing the control.

Provincial Health Laws

Ontario’s Personal Health Information Protection Act (PHIPA) and Alberta’s Health Information Act (HIA) are examples of provincial health-specific laws. Their scope and duties differ; neither is simply a stricter version of PIPEDA.

Two critical examples are:

  • Ontario’s PHIPA: Governs health information custodians and their agents. Whether a service provider is an agent depends on its role. Consent may be express or implied, and some activities are permitted without consent.
  • Alberta’s Health Information Act (HIA): Similar to PHIPA, the HIA outlines detailed rules for custodians managing health information, including specific requirements for security safeguards and breach reporting.

For a service handling data under multiple regimes, determine the applicable purposes, permissions, restrictions, and notification duties. Where Privacy is in SOC 2 scope, retain evidence that the relevant controls follow the stated commitments. Data origin alone does not settle which law applies.

HIPAA vs PIPEDA vs PHIPA Key Differences

Compliance AreaHIPAA (U.S.)PIPEDA (Canada-Federal)PHIPA (Ontario)
Primary ScopeProtected Health Information (PHI) held by Covered Entities & Business Associates.Personal Information in commercial activities by private-sector orgs.Personal Health Information (PHI) held by Health Information Custodians (HICs) & their agents.
Consent ModelGenerally permits TPO uses and disclosures without individual authorization, subject to limits and exceptions.Consent must be appropriate to the sensitivity and circumstances; exceptions also apply.Allows express or implied consent, including assumed implied consent within the circle of care; requires express consent for specified purposes, subject to exceptions.
Data Subject RightsRight of access, amendment, and accounting of disclosures.Right of access and correction to one’s personal information.Robust rights of access and correction; right to “lock box” parts of their health record.
Breach NotificationCovered entities notify affected individuals for breaches of unsecured PHI regardless of count; HHS reporting differs at 500 individuals. Business associates notify the covered entity.Notify affected individuals and report to the OPC when the breach creates a real risk of significant harm; retain records of all safeguard breaches.Custodians notify affected individuals as required by PHIPA; notify the IPC in prescribed circumstances and submit annual breach statistics.
Key Enforcement BodyOffice for Civil Rights (OCR) within the Dept. of Health and Human Services (HHS).Office of the Privacy Commissioner of Canada (OPC).Information and Privacy Commissioner of Ontario (IPC).

Hand holding a medical consent form with checkmarks, and a watercolor silhouette of a person.

HIPAA generally permits treatment, payment, and healthcare-operations (TPO) uses and disclosures without the individual’s authorization, subject to applicable limits and exceptions. This is not an implied-consent rule. The HHS Privacy Rule summary distinguishes these permitted activities from uses requiring authorization.

Configure permissions according to the applicable law, purpose, and customer commitments. A permission allowed under HIPAA does not establish that the same use is permitted under PHIPA or PIPEDA. Where Privacy is in your SOC 2 scope, the auditor evaluates the relevant controls rather than assuming one consent model fits every activity.

Under PHIPA, consent can be express or implied. Custodians can assume implied consent for certain healthcare activities within the circle of care, unless consent has been withheld or withdrawn. Express consent is required for specified disclosures and purposes, subject to statutory exceptions. The Ontario IPC’s consent guidance explains these distinctions.

Document when each use requires consent or authorization, when an exception applies, and how the system records restrictions or withdrawal. Avoid treating either HIPAA permission or PHIPA express consent as a universal default.

Choose controls based on the applicable rules and the commitments in scope. The following are design examples, not technologies prescribed by SOC 2:

  • Data and Purpose Classification: Record the customer relationship, data type, permitted purpose, and relevant jurisdiction. Use these together to select the appropriate handling rules.
  • Permission Checks: Record consent or authorization when required, enforce purpose restrictions, and block a use when the necessary permission or legal basis is missing.
  • Consent and Authorization Records: Retain who gave permission, when, for which purposes, and any withdrawal or restriction. Protect the records against unauthorized alteration and retain them for the required period.

Where Privacy is included in the examination, retain evidence of how these controls implement the system’s privacy commitments throughout the reporting period.

Your Obligations as a Canadian Business Associate

Hand signing a secure business associate agreement on a tablet, with server racks in a digital watercolor setting. A Canadian vendor should identify applicable business-associate duties and the additional obligations in its BAA. HHS’s direct-liability guidance covers duties including Security Rule compliance and reporting breaches to the covered entity.

HIPAA and SOC 2 have overlapping security objectives, so a control and its evidence may support both programs. They are not a one-to-one equivalence. Check each requirement, the control’s scope, and the assurance the customer actually requests.

Mapping HIPAA Safeguards to SOC 2 Criteria

The HIPAA Security Rule has administrative, physical, and technical safeguards. Some controls can also support SOC 2 criteria, but the requirements and examination scopes differ.

  • Administrative Safeguards: These are the policies and procedures that govern your security program, such as conducting a formal risk analysis (maps to SOC 2 CC3.2), implementing security awareness training (maps to CC2.2), and assigning a security officer.
  • Physical Safeguards: Physical access restrictions can support CC6.4. Secure disposal or reuse of devices can support CC6.5. Workstation protections may also involve logical access controls.
  • Technical Safeguards: Access controls can support CC6.1 and CC6.3, protection of data in transit can support CC6.7, and monitoring audit logs for anomalies can support CC7.2. Encryption at rest may support C1.1 when Confidentiality is in scope.

Agree which controls address the SOC 2 criteria in scope and what evidence the auditor needs. A HIPAA safeguard does not automatically become a SOC 2 test.

Building a Unified Control Framework

A shared control framework can reduce duplicate work where requirements overlap. Keep the obligations, control mappings, and evidence for each program explicit.

This table illustrates overlapping control objectives using the AICPA Trust Services Criteria. It is not an official HIPAA crosswalk or proof that meeting one framework satisfies the other. Our provision-by-provision SOC 2 vs HIPAA mapping covers every Security Rule standard and implementation specification.

HIPAA Safeguard (Technical)DescriptionCorresponding SOC 2 Criterion
Access Control (164.312(a))Implement technical policies and procedures to allow access only to those persons or software programs that have been granted access rights.CC6.1, CC6.3: The entity implements logical access security measures to protect against unauthorized access.
Audit Controls (164.312(b))Implement mechanisms to record and examine activity in systems containing ePHI.CC7.2: Monitoring system components for anomalies and analyzing potential security events.
Transmission Security (164.312(e))Guard against unauthorized access to ePHI transmitted over an electronic network.CC6.7: Restrict information transmission to authorized users and processes and protect it during transmission. Encryption in transit can support this objective; CC6.8 concerns malicious software.

A Type 2 SOC 2 examination evaluates the design and operating effectiveness of controls over the reporting period. Access reviews, audit logs, and encryption evidence may also support a HIPAA assessment, but reusing evidence does not establish that both sets of requirements have been met.

Managing Cross Border Breach Notifications

An incident may trigger several legal and contractual notification duties. Your response program should identify the affected data, the entities responsible for notification, applicable thresholds, and deadlines. These procedures can support CC7.3 event evaluation and CC7.4 response.

Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of PHI is generally presumed to be a breach unless an exception applies or the required assessment establishes a low probability of compromise. Notification duties concern unsecured PHI. PIPEDA uses a different real-risk-of-significant-harm test.

The Critical Timeline Differences

A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and within 60 days of discovery; the BAA may require a shorter interval. The covered entity is responsible for individual notices, also without unreasonable delay and within 60 days, regardless of the number affected. HHS notice is due within 60 days for breaches affecting 500 or more individuals; smaller breaches are reported within 60 days after the end of the calendar year in which they were discovered.

Under PIPEDA, the organization with the information under its control must report and notify as soon as feasible when a safeguard breach creates a real risk of significant harm. It must retain records of all safeguard breaches, including those below the reporting threshold. A service provider should promptly alert the accountable customer and follow its own contractual duties. See the OPC’s reporting guidance.

Turn the applicable notification duties into procedures that name the responsible parties, deadlines, and escalation contacts. Decision trees can help staff follow them, but SOC 2 does not prescribe that document format. The auditor evaluates the controls against the criteria and commitments in scope.

Building a Dual-Compliant Incident Response Framework

For a service subject to both US and Canadian requirements, the following workflow can help coordinate the applicable duties:

  1. Containment and Triage: Coordinate containment, evidence preservation, and the assessment of affected information. These activities can support CC7.3 event evaluation and CC7.4 response; the sequence depends on the incident.
  2. Applicability Assessment: Identify the customer relationship, affected information, purposes, locations, and laws involved. Several regimes can apply to the same incident; patient nationality alone does not determine the reporting path.
  3. Risk Evaluation: Assess each applicable regime without delaying a notification while another investigation continues:
    • HIPAA Track: Determine whether unsecured PHI is involved and whether an exception or documented low-probability-of-compromise assessment applies. Record the discovery date and relevant legal and BAA reporting deadlines; an investigation does not automatically restart the clock.
    • Canadian Track: Apply the notification rules for each relevant law. PIPEDA uses a real-risk-of-significant-harm assessment; PHIPA has its own individual-notice and prescribed IPC-reporting rules. See the IPC breach-reporting guidance.
  4. Coordinated Notification Workflow: Assign notices to the party responsible under each law and contract. Keep relevant templates and contacts available. A business associate’s notice to its covered-entity customer is distinct from the covered entity’s notices to individuals and HHS.

For a Type 2 examination, retain evidence that the response controls operated as described during the reporting period. A detailed plan alone does not establish operating effectiveness or guarantee an unmodified opinion.

Using SOC 2 as Security Evidence for Healthcare Clients

HHS does not issue a general HIPAA compliance certification or endorse a specific technology as compliant. A customer may request a SOC 2 report as security evidence, but HIPAA does not require a SOC 2 report.

SOC 2 provides independent assurance about the description and controls within its agreed scope. Type 1 addresses design at a date; Type 2 also addresses operating effectiveness over a period. Neither automatically proves HIPAA compliance or every BAA obligation.

Mapping Overlapping Controls

Use the applicable HIPAA requirements and the AICPA Trust Services Criteria to document where control objectives overlap. Keep any crosswalk separate from a conclusion that the auditor examined HIPAA criteria.

For example:

  • HIPAA Security Rule § 164.312(a)(1) - Access Control: Requires implementation of technical policies and procedures to allow access only to authorized persons or programs.
  • SOC 2 Common Criteria CC6.1: Requires the entity to implement logical access security measures over software, infrastructure, and architectures.

The access-control objectives overlap, but their requirements and examination scope differ. Document the access model, reviews, and evidence relevant to each program. Neither framework prescribes a universal quarterly access-review schedule.

Structuring Your SOC 2 Report for U.S. Clients

Discuss the customer’s assurance needs with the auditor before agreeing the scope. Two areas to consider are:

  1. System Description: Describe the services, relevant commitments, and controls included in the examination. Explain applicable business-associate commitments where relevant, without implying that the report gives an opinion on every HIPAA requirement. Report section numbering can vary.
  2. Control Mapping Appendix: A crosswalk can help the customer locate relevant controls. It is not a separate HIPAA assurance opinion. If the buyer needs assurance against additional HIPAA criteria, agree those criteria and reporting scope explicitly with the auditor.

Customers should read the opinion, system description, tests, and exceptions to determine what assurance the report provides. If notification controls are in scope, check which duties were tested and what the results show. To compare the frameworks, refer to this SOC 2 compliance framework comparison chart. If a healthcare buyer asks for HITRUST certification instead of a SOC 2 report, see SOC 2 vs HITRUST.

Choosing the Right Audit Partner

Look for an audit firm with experience relevant to your healthcare service and the assurance your customers request. Ask what its SOC 2 examination covers and whether additional HIPAA assessment work is needed.

Ask potential audit firms these specific questions:

  • Can you provide examples of SOC 2 reports you have issued for other Canadian BAs that include HIPAA mappings?
  • Which HIPAA requirements would you examine, and which would only appear in a supplemental mapping?
  • How would the system description address the relevant service commitments and controls?
  • Can you provide a supplemental HIPAA control mapping, and what assurance would it provide?

Compare the firms’ proposed scope, experience, and reporting deliverables. Browse healthcare-focused SOC 2 auditors for candidates to assess.

For Canadian vendors serving US healthcare clients, identify business-associate duties, BAA terms, and applicable Canadian privacy requirements before selecting the audit scope. A SOC 2 report can support customer due diligence when its scope matches the service, but it does not replace compliance with those duties.

Frequently Asked Questions

What is the Canadian version of HIPAA?

Canada has no single law identical to HIPAA. PIPEDA governs private-sector commercial activities within its scope, while provincial laws such as Ontario’s PHIPA and Alberta’s HIA address health information. Which law applies depends on the organization, activity, and data flow.

Does HIPAA apply in Canada?

HIPAA is a US law, not a Canadian health-privacy statute. A Canadian vendor performing business-associate functions for a HIPAA covered entity or another business associate can have applicable HIPAA duties as well as required BAA contract obligations. A missing BAA does not remove business-associate duties.

What is PHIPA?

PHIPA is Ontario’s Personal Health Information Protection Act (2004). It governs health information custodians and their agents and is enforced by Ontario’s Information and Privacy Commissioner. Consent can be express or implied; assumed implied consent can apply within the circle of care, while specified purposes and disclosures require express consent, subject to exceptions.

What does HIPAA protect in Canada?

HIPAA protects PHI within covered-entity and business-associate relationships. A Canadian vendor’s obligations depend on the services it performs and the information it handles, not simply patient citizenship or whether a BAA has been signed. Canadian privacy laws may also apply to those activities.

Is the US the only country with a law like HIPAA?

HIPAA is a US statute. Other countries protect health information through their own laws; Canada uses federal and provincial regimes, including PIPEDA and PHIPA. Those regimes have different roles, scopes, and duties, so there is no universal HIPAA compliance status across countries.

Is PIPEDA like HIPAA?

Both protect personal information, but their scopes differ. PIPEDA covers private-sector commercial activities within its scope, including relevant cross-border flows. HIPAA regulates covered entities and business associates handling PHI. A Canadian vendor may need to address applicable duties under both, plus relevant provincial law.

Does HIPAA apply internationally?

HIPAA is not a uniform international privacy law. A non-US vendor performing business-associate functions for a HIPAA covered entity or another business associate should assess applicable HIPAA duties and put the required BAA in place. The contract supplements those duties; it is not their only source.

Can a Canadian company host US PHI in a Canadian cloud?

HIPAA does not categorically prohibit storing ePHI outside the United States. HHS requires the applicable safeguards and BAA arrangements, with location risks addressed in the Security Rule risk analysis. Check the customer’s contract too, because it may impose a US-only hosting requirement.