Treadstone Associates
Article · 8 min read

AI in Canadian healthcare records

There is no separate Canadian law for “AI in healthcare.” There is a health-privacy regime that already applies to the custodian using the tool — and Alberta is the one province with a regulator that has written down, in detail, what that means for an AI scribe.

Treadstone Associates · Updated 2026

Key takeaways

  • • Alberta's Health Information Act is not consent-based — it runs on a circle-of-care model, unlike PIPEDA and most other Canadian privacy statutes.
  • • Alberta's OIPC has published dedicated AI Scribe PIA guidance under HIA s.64 — the most specific Canadian regulatory document found on AI in a clinical setting.
  • • The OIPC flags a genuinely AI-specific risk: a vendor contract that lets an AI scribe use patient data to train its own model likely fails HIA.
  • • Health information disclosed to a private-sector vendor can fall under a different statute (Alberta's PIPA) the moment the vendor, not the custodian, holds it.
  • • Federal, provincial and territorial privacy commissioners have flagged health care as one of the “highly impactful contexts” for AI fairness risk.

An AI scribe that listens to a patient encounter and drafts the chart note is not covered by some separate “AI law.” It is covered by whatever privacy regime already governs health information in that province, and in Canada that regime is usually stricter and more specific than the general private-sector privacy statute. The honest starting point is that there is no single Canadian AI-and-health-records rule — there is a patchwork of provincial health-information statutes sitting on top of the federal baseline, and the AI tool inherits whichever one applies to the custodian using it.

The federal baseline: PIPEDA still applies to health information as personal information

Under PIPEDA, “personal information is defined broadly as information about an identifiable individual — meaning it can reasonably be linked back to a specific person, whether alone or combined with other information a business has or can access.” (treadstonelaw.ca, PIPEDA personal information) That general definition — addressing the underlying PIPEDA question, not any AI application of it — does not carve health data out for lighter treatment; if anything, Canada’s federal, provincial and territorial privacy commissioners have specifically flagged health care as one of the “highly impactful contexts” where biased or unfair AI outcomes cause the most damage, alongside employment, policing, immigration, criminal justice and access to finance. (OPC, generative AI principles, 2025-05-06)

Where it gets more specific: Alberta’s Health Information Act

Alberta is the one province where a Canadian regulator has published guidance addressing an AI tool in a clinical setting by name. Alberta’s Office of the Information and Privacy Commissioner published an AI Scribe Privacy Impact Assessment Guidance in September 2025, built around section 64 of the Health Information Act (HIA) — the section that requires a custodian to submit a PIA to the Commissioner describing the effect of any system involving the collection, use and disclosure of identifying health information. (OIPC AB, AI Scribe PIA Guidance, Sept 2025)

The guidance opens with a structural point that changes the whole analysis: “Alberta’s Health Information Act (HIA) is not like other health information laws in Canada. It is not consent-based.” Instead it runs on a circle-of-care model that permits collection, use and disclosure among people involved in a patient’s care, subject to its own limitation and security rules. (OIPC AB, AI Scribe PIA Guidance)

The one AI-specific finding worth reading twice

Most of the guidance is procedural — what a PIA for an AI scribe has to describe: the features in use, a table of the health information categories involved, a data-flow diagram covering “if the AI scribe implements a dynamic AI model, then it has the ability to self-learn, fine tune and update itself using the health information it ingests,” and how the limitation principle in HIA section 58 is met. (OIPC AB, AI Scribe PIA Guidance) But one line is a genuinely AI-specific regulatory position, rare in Canadian guidance: custodians “should be on the lookout for any contract provisions that permit the use of health information by the AI scribe vendor for the purposes of training its AI,” because “HIA would likely not permit a vendor to use health information provided to it from a custodian, or that is otherwise accessible, to train the AI.” (OIPC AB, AI Scribe PIA Guidance)

A second regime can attach the moment data leaves the clinic

The guidance also flags a pitfall specific to using a private-sector vendor: many vendor contracts are drafted against PIPEDA, Alberta’s general private-sector law (PIPA), or the American HIPAA — none of which is the operative law once the information is health information collected by an Alberta custodian. And once health information is disclosed to a private-sector vendor, it “becomes personal information subject to another Act and in the control of the private sector vendor” — typically Alberta’s own Personal Information Protection Act — so the same file can cross from one statute into another depending on who is holding it at that moment. (OIPC AB, AI Scribe PIA Guidance)

What this sheet does not claim

Alberta is the province where this guidance was actually read and verified, section by section — it is not a claim that every province regulates health information the same way, or that HIA’s circle-of-care model applies outside Alberta. Alberta’s own OIPC lists a separate, further resource on its AI page — “AI: Guidance for Small Custodians on the use of Artificial Intelligence” — alongside the AI Scribe guidance, which is a further sign that this is an active, developing area of Alberta regulatory attention rather than a settled national position. (OIPC AB, AI resources index) A custodian outside Alberta needs to check its own province’s health-information statute rather than assume HIA’s rules, or PIPEDA’s, transfer across automatically.

A worked scenario

A family clinic in Edmonton wants to deploy an AI scribe to draft SOAP notes from patient visits. Under the OIPC’s guidance, the clinic (the custodian) needs a PIA describing the tool’s specific features, a table of exactly what health information categories flow through it, and a data-flow diagram tracking any self-learning behaviour. Its vendor contract has to name HIA specifically — not just PIPEDA boilerplate — state that the vendor cannot use the transcripts to train its own model without independent HIA authority, and commit the vendor to returning or securely destroying the health information when the relationship ends, because “a custodian has no authority to relinquish control of health information other than in accordance with HIA.” (OIPC AB, AI Scribe PIA Guidance) None of that changes because the tool is “just transcription” — the PIA duty is triggered by the system, not by how sophisticated its output looks.

Related: why professional bodies are cautious on AI, regulated professions and AI guidance, and the AI Operations hub on running a deployed tool day to day

Common questions

Does PIPEDA cover health information collected by a private clinic?

Generally yes — PIPEDA applies to personal information collected in the course of commercial activity, and health information is personal information like any other under the federal statute. In practice most provinces have layered a dedicated health-information statute on top; Alberta’s is the Health Information Act, and it works differently from PIPEDA rather than simply restating it.

Can an AI scribe vendor use patient conversations to improve its own model?

Not under Alberta’s Health Information Act without independent authority for that use. The OIPC has named this exact contract provision as a pitfall custodians commonly miss, and its guidance is that HIA “would likely not permit” a vendor to train on health information supplied to it by a custodian.

Does deleting the recording after transcription solve the privacy question?

No — retention practices matter, but they are only one requirement among several. The harder questions are whether the custodian has authority to collect only what is essential under the limitation principle, whether the vendor contract actually names the right statute, and what happens to any copy the vendor holds once the relationship ends.

Running an AI tool against real client data

Accuracy, safeguards and vendor accountability don't stop mattering once a tool is live.