BC HIA · BC E-HEALTH ACT · BC PIPA

BC Health Information Act (BC HIA)
The BC E-Health Act and BC Healthcare Privacy

BC has no statute called the Health Information Act. When people say “BC HIA,” they almost always mean the E-Health (Personal Health Information Access and Protection of Privacy) Act, often called the BC E-Health Act, which governs designated provincial health information banks such as CareConnect and PharmaNet. Most BC clinics are also covered by BC PIPA, and health authorities by BC FIPPA. ThreeShield assesses all three for health data custodians, health tech companies, and health-adjacent organizations.

BC Privacy Requirements for Healthcare Organizations

BC PIPA Security Safeguards

BC's Personal Information Protection Act (PIPA) requires organizations to protect personal information using security safeguards appropriate to the sensitivity of the information. Healthcare data carries the highest sensitivity classification.

The BC E-Health Act (“BC HIA”)

The E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, governs health information banks designated by ministerial order, lets patients restrict access through disclosure directives, limits disclosure outside Canada to narrow cases, and sets fines of up to $200,000.

Privacy Impact Assessments

New information systems handling health data require PIAs. Cloud migration, EHR implementations, and telehealth platforms all trigger PIA requirements under BC health privacy legislation.

Breach Notification

Health authorities and other public bodies must notify affected people and the BC OIPC under FIPPA when a breach could reasonably be expected to cause significant harm. BC PIPA does not require private clinics to report, but the OIPC expects notification when there is a real risk of significant harm, and healthcare breaches usually meet that bar.

Cross-Border Data Transfers

BC PIPA does not ban storing personal information outside Canada, but a clinic stays accountable for it wherever it goes, so US cloud providers need contractual protections. Public bodies under FIPPA need a privacy impact assessment and a risk assessment before sensitive information leaves Canada, and the E-Health Act limits disclosure of health information bank data outside Canada to narrow cases.

Comparison: BC PIPA vs. Alberta HIA vs. PIPEDA

BC organizations with Canadian inter-provincial operations may face BC PIPA, Alberta HIA, and PIPEDA simultaneously. ThreeShield maps all three frameworks and identifies the most stringent requirements for a unified compliance approach.

BC Clinics & Physicians BC Pharmacy Groups BC Health Tech Companies BC Mental Health Services BC Dental Practices BC Health Research Organizations

Frequently Asked Questions

Not by that name. “BC Health Information Act” and “BC HIA” almost always refer to the E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, often called the BC E-Health Act. It covers designated provincial health information banks. Private clinics are covered by BC PIPA, and health authorities by BC FIPPA.

Provincial health information banks designated by ministerial order, such as CareConnect and PharmaNet. It sets the purposes for collecting, using, and disclosing that information, lets patients restrict access with disclosure directives, limits disclosure outside Canada, and makes breaches of those rules an offence with fines of up to $200,000.

Mostly, yes. For personal information collected in the course of commercial activities, BC PIPA is 'substantially similar' to PIPEDA and exempts BC organizations from PIPEDA for BC-collected information. However, personal information crossing provincial or national borders, and employee information in federally regulated industries, remains under PIPEDA.

The biggest difference is structure: Alberta HIA applies to 'health information custodians', while BC's health privacy framework is distributed across multiple statutes. Both are provincial health privacy laws, but their custodian definitions and administrative requirements also differ. If your organization operates in both provinces, ThreeShield maps both simultaneously.

Get a BC Privacy & Health Security Assessment

ThreeShield delivers BC PIPA-aligned security assessments for healthcare organizations and health tech companies.

Book a Scoping Call

DIY · Supported · Done-for-You · All engagement models available

Three Ways to Engage, from DIY to Done-for-You

Whether you have a strong internal team or need everything handled end-to-end, ThreeShield meets you where you are.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal security capacity

  • Lavawall® platform access with GRC module
  • Automated evidence collection against BC PIPA
  • Live compliance score dashboard
  • Policy and procedure template library
  • Self-guided remediation workflows
  • AI-generated compliance status reports
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

For MSPs, IT teams with some security resources, and organizations that need expert guidance but retain internal capacity

  • Everything in DIY tier
  • CISSP/CISA-guided gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development support
  • Quarterly compliance review calls
  • Tier 3 escalation for complex issues
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

For organizations that want full compliance delivery without managing the process internally

  • Everything in Supported tier
  • ThreeShield manages the full compliance program
  • CISSP/CISA-executed formal assessment or audit
  • Findings methodology (typically 200+ findings)
  • Complete policy and procedure creation
  • Audit-ready evidence packages
  • Annual reassessment included
Book Done-for-You Assessment