
Alberta Health Information Act: Custodian Obligations in Practice
HIA asks for something no other Canadian privacy law does — the highest level of anonymity possible — and requires you to file privacy impact assessments before you go live.
GuardsArm Team
Security Experts

Alberta's Health Information Act imposes two obligations that catch out organisations arriving from a HIPAA or PIPEDA background. One is a data-minimisation duty phrased more strictly than anywhere else in Canadian privacy law. The other is that certain changes require a privacy impact assessment to be submitted to the Commissioner before you implement them — not filed afterwards.
Who is a custodian, and who is an affiliate
HIA applies to custodians — a defined list that includes regional health authorities, physicians, pharmacists, nursing homes and other named health service providers. Anyone working for or on behalf of a custodian is an affiliate, and affiliates carry personal duties under the Act rather than sheltering behind the organisation.
That distinction matters. An employee who looks up a neighbour's record is not merely breaking an internal policy; they are exposed personally. It also means your contractors and locums need to understand their own position, not just sign an organisational agreement.
The Act covers health information in two forms: diagnostic, treatment and care information, and registration information. Registration information — demographics, billing, eligibility — is frequently forgotten in scoping because it does not feel clinical.
The duty that has no equivalent elsewhere
HIA requires custodians to collect, use and disclose the least amount of health information necessary, at the highest level of anonymity possible in the circumstances.
In practice this reshapes design decisions:
| Decision | What HIA pushes you toward |
|---|---|
| A reporting dashboard | Aggregate or de-identified figures, not record-level extracts |
| A research request | De-identified unless identity is genuinely required |
| A vendor integration | The minimum field set, not the whole record for convenience |
| A staff role | Scoped access, not blanket access "in case" |
An access model that would pass a HIPAA minimum-necessary review can still fail here, because HIA asks not just for less data but for less identifiable data.
Privacy impact assessments are a gate, not a formality
Custodians must prepare a PIA describing how a proposed new practice, information system or administrative change affects the privacy of health information, and submit it to the Office of the Information and Privacy Commissioner for review before implementing it.
Build PIA submission into your project intake, with the review period treated as real calendar time. Teams that discover the requirement at go-live either slip the date or proceed without acceptance, and the second option creates an exposure that lasts as long as the system does.
Breach notification
Where a loss, unauthorised access or unauthorised disclosure creates a risk of harm, custodians must notify the Commissioner, the Minister and the affected individual. The three-way notification is distinctive — a custodian used to PIPEDA will not expect the Minister to be on the list.
Practical consequences for your incident plan:
- Your notification templates need three recipients, not one
- Affiliates must know to escalate internally and immediately, since the clock starts on organisational awareness
- Your logging has to be good enough to establish what was accessed, by whom. Access to a record leaves a trace only if the system was configured to keep one — see logging strategy
Netcare access adds provincial audit visibility on top of your own, so inappropriate access can surface from outside your organisation before you find it yourself.
Disclosures that need their own analysis
Care-related disclosure between custodians is the straightforward case. Everything else needs a specific footing, and these are the requests that arrive without warning:
| Request | What to check first |
|---|---|
| Research | Ethics approval and the research provisions; de-identify unless identity is essential |
| Family member asking about a patient | Authority to act, or a permitted disclosure — not politeness |
| Insurer or employer | Express authorisation from the individual, scoped to what was authorised |
| Law enforcement | The specific provision relied on, recorded at the time |
| Another custodian outside Alberta | The disclosure rule plus the safeguards that follow the data |
The common failure is a verbal request handled helpfully at a front desk, with no record of what was disclosed or under what authority. Build a disclosure log and require a provision to be named in it — that single discipline prevents most of the findings in this category.
Where to start
Pull your last three system changes and ask whether a PIA was prepared and submitted. If the answer is no for any of them, that is both your most likely finding and the easiest thing to correct going forward.
GuardsArm supports Alberta custodians with PIAs, access reviews and breach readiness. See Alberta HIA compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


