Back to Blog
Compliance
4 min read

Alberta Health Information Act: Custodian Obligations in Practice

HIA asks for something no other Canadian privacy law does — the highest level of anonymity possible — and requires you to file privacy impact assessments before you go live.

GuardsArm Team

Security Experts

September 25, 2026

Alberta Health Information Act compliance

Alberta's Health Information Act imposes two obligations that catch out organisations arriving from a HIPAA or PIPEDA background. One is a data-minimisation duty phrased more strictly than anywhere else in Canadian privacy law. The other is that certain changes require a privacy impact assessment to be submitted to the Commissioner before you implement them — not filed afterwards.

Highest anonymity possible
A stricter test than HIPAA minimum necessary
PIAs go in before go-live
Submitted to the Commissioner, not filed internally
Affiliates are personally liable
Duties attach to individuals, not only the organisation

Who is a custodian, and who is an affiliate

HIA applies to custodians — a defined list that includes regional health authorities, physicians, pharmacists, nursing homes and other named health service providers. Anyone working for or on behalf of a custodian is an affiliate, and affiliates carry personal duties under the Act rather than sheltering behind the organisation.

That distinction matters. An employee who looks up a neighbour's record is not merely breaking an internal policy; they are exposed personally. It also means your contractors and locums need to understand their own position, not just sign an organisational agreement.

The Act covers health information in two forms: diagnostic, treatment and care information, and registration information. Registration information — demographics, billing, eligibility — is frequently forgotten in scoping because it does not feel clinical.


The duty that has no equivalent elsewhere

HIA requires custodians to collect, use and disclose the least amount of health information necessary, at the highest level of anonymity possible in the circumstances.

Least amount, highest anonymity
The wording asks two separate questions of every collection, use and disclosure: is this the smallest amount of health information that will do, and is this the least identifiable form it could take? Passing the first and failing the second is the common outcome.

In practice this reshapes design decisions:

DecisionWhat HIA pushes you toward
A reporting dashboardAggregate or de-identified figures, not record-level extracts
A research requestDe-identified unless identity is genuinely required
A vendor integrationThe minimum field set, not the whole record for convenience
A staff roleScoped access, not blanket access "in case"

An access model that would pass a HIPAA minimum-necessary review can still fail here, because HIA asks not just for less data but for less identifiable data.


Privacy impact assessments are a gate, not a formality

Custodians must prepare a PIA describing how a proposed new practice, information system or administrative change affects the privacy of health information, and submit it to the Office of the Information and Privacy Commissioner for review before implementing it.

Where the PIA sits in a projectWhere the PIA sits in a project1Proposed changeTriggerA new system, a new practice, or an administrative change affecting health information.2Prepare the PIABefore build completesDescribe the information flows, the risks and the mitigations.3Submit to the OIPCBefore implementationThe Commissioner reviews; this is calendar time your project plan must carry.4ImplementAfter acceptanceGoing live ahead of review leaves an exposure lasting the life of the system.
Discovering this at go-live means slipping the date or proceeding uncovered.

Build PIA submission into your project intake, with the review period treated as real calendar time. Teams that discover the requirement at go-live either slip the date or proceed without acceptance, and the second option creates an exposure that lasts as long as the system does.


Breach notification

Where a loss, unauthorised access or unauthorised disclosure creates a risk of harm, custodians must notify the Commissioner, the Minister and the affected individual. The three-way notification is distinctive — a custodian used to PIPEDA will not expect the Minister to be on the list.

Practical consequences for your incident plan:

  • Your notification templates need three recipients, not one
  • Affiliates must know to escalate internally and immediately, since the clock starts on organisational awareness
  • Your logging has to be good enough to establish what was accessed, by whom. Access to a record leaves a trace only if the system was configured to keep one — see logging strategy

Netcare access adds provincial audit visibility on top of your own, so inappropriate access can surface from outside your organisation before you find it yourself.


Disclosures that need their own analysis

Care-related disclosure between custodians is the straightforward case. Everything else needs a specific footing, and these are the requests that arrive without warning:

RequestWhat to check first
ResearchEthics approval and the research provisions; de-identify unless identity is essential
Family member asking about a patientAuthority to act, or a permitted disclosure — not politeness
Insurer or employerExpress authorisation from the individual, scoped to what was authorised
Law enforcementThe specific provision relied on, recorded at the time
Another custodian outside AlbertaThe disclosure rule plus the safeguards that follow the data

The common failure is a verbal request handled helpfully at a front desk, with no record of what was disclosed or under what authority. Build a disclosure log and require a provision to be named in it — that single discipline prevents most of the findings in this category.


Where to start

Pull your last three system changes and ask whether a PIA was prepared and submitted. If the answer is no for any of them, that is both your most likely finding and the easiest thing to correct going forward.

GuardsArm supports Alberta custodians with PIAs, access reviews and breach readiness. See Alberta HIA compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.