BC has no statute called the Health Information Act. When people say “BC HIA,” they almost always mean the E-Health (Personal Health Information Access and Protection of Privacy) Act, often called the BC E-Health Act, which governs designated provincial health information banks such as CareConnect and PharmaNet. Most BC clinics are also covered by BC PIPA, and health authorities by BC FIPPA. ThreeShield assesses all three for health data custodians, health tech companies, and health-adjacent organizations.
BC's Personal Information Protection Act (PIPA) requires organizations to protect personal information using security safeguards appropriate to the sensitivity of the information. Healthcare data carries the highest sensitivity classification.
The E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, governs health information banks designated by ministerial order, lets patients restrict access through disclosure directives, limits disclosure outside Canada to narrow cases, and sets fines of up to $200,000.
New information systems handling health data require PIAs. Cloud migration, EHR implementations, and telehealth platforms all trigger PIA requirements under BC health privacy legislation.
Health authorities and other public bodies must notify affected people and the BC OIPC under FIPPA when a breach could reasonably be expected to cause significant harm. BC PIPA does not require private clinics to report, but the OIPC expects notification when there is a real risk of significant harm, and healthcare breaches usually meet that bar.
BC PIPA does not ban storing personal information outside Canada, but a clinic stays accountable for it wherever it goes, so US cloud providers need contractual protections. Public bodies under FIPPA need a privacy impact assessment and a risk assessment before sensitive information leaves Canada, and the E-Health Act limits disclosure of health information bank data outside Canada to narrow cases.
BC organizations with Canadian inter-provincial operations may face BC PIPA, Alberta HIA, and PIPEDA simultaneously. ThreeShield maps all three frameworks and identifies the most stringent requirements for a unified compliance approach.
Not by that name. “BC Health Information Act” and “BC HIA” almost always refer to the E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, often called the BC E-Health Act. It covers designated provincial health information banks. Private clinics are covered by BC PIPA, and health authorities by BC FIPPA.
Provincial health information banks designated by ministerial order, such as CareConnect and PharmaNet. It sets the purposes for collecting, using, and disclosing that information, lets patients restrict access with disclosure directives, limits disclosure outside Canada, and makes breaches of those rules an offence with fines of up to $200,000.
Mostly, yes. For personal information collected in the course of commercial activities, BC PIPA is 'substantially similar' to PIPEDA and exempts BC organizations from PIPEDA for BC-collected information. However, personal information crossing provincial or national borders, and employee information in federally regulated industries, remains under PIPEDA.
The biggest difference is structure: Alberta HIA applies to 'health information custodians', while BC's health privacy framework is distributed across multiple statutes. Both are provincial health privacy laws, but their custodian definitions and administrative requirements also differ. If your organization operates in both provinces, ThreeShield maps both simultaneously.
ThreeShield delivers BC PIPA-aligned security assessments for healthcare organizations and health tech companies.
Book a Scoping CallDIY · Supported · Done-for-You · All engagement models available
Whether you have a strong internal team or need everything handled end-to-end, ThreeShield meets you where you are.
For lean IT teams and cost-conscious organizations with internal security capacity
For MSPs, IT teams with some security resources, and organizations that need expert guidance but retain internal capacity
For organizations that want full compliance delivery without managing the process internally