Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

US Healthcare Privacy

HIPAA Compliance for Canadian Companies

If you store, process or support U.S. patient information, HIPAA expectations follow the data. We help Canadian vendors and providers meet the Privacy, Security and Breach Notification Rules — and prove it to US customers.

The Basics

What HIPAA is and who it applies to

The Health Insurance Portability and Accountability Act (HIPAA) is the US federal law that governs protected health information (PHI). Its three operative rules — the Privacy Rule, the Security Rule and the Breach Notification Rule — set out how PHI may be used and disclosed, how electronic PHI must be safeguarded, and what happens when it is exposed. The rules are enforced by the US Department of Health and Human Services’ Office for Civil Rights (OCR).

HIPAA applies to covered entities — health plans, healthcare clearinghouses and providers that transmit health information electronically — and to their business associates: any vendor that creates, receives, maintains or transmits PHI on their behalf. A Canadian software company, hosting provider, analytics firm or support desk that touches US patient data is a business associate, is expected to sign a Business Associate Agreement (BAA), and is directly liable under the Security Rule.

That is why HIPAA matters in Canada even though it is not Canadian law: it arrives in the contract. We cover the fundamentals inWhat is HIPAA? and the scope question inDoes HIPAA apply to my business?If you also handle Canadian health data, see how it fits alongsidePHIPA andPIPEDA.

Privacy Rule

Sets the permitted uses and disclosures of protected health information (PHI), the “minimum necessary” standard, and patients’ rights over their records.

Security Rule

Requires administrative, physical and technical safeguards for electronic PHI — starting with a documented, organization-wide security risk analysis.

Breach Notification Rule

Defines what counts as a breach of unsecured PHI and who must be told, how quickly, and by whom — including the business associate’s duty to its customer.

Key Requirements

What HIPAA compliance requires

Physician working at a computer in a clinic — electronic protected health information safeguarded under the HIPAA Security Rule
  1. Documented security risk analysis

    An accurate, organization-wide assessment of the risks to electronic PHI is a required Security Rule safeguard — and the first document the Office for Civil Rights asks for after an incident.

  2. Administrative, physical and technical safeguards

    Policies, workforce training, access controls, audit logging, encryption decisions, device and facility controls, and contingency planning, each mapped to the systems that actually hold PHI.

  3. Business Associate Agreements

    A signed BAA with every covered entity you serve and every subcontractor that touches PHI on your behalf — with obligations your team can genuinely meet.

  4. Permitted uses and minimum necessary

    Use and disclose PHI only as the Privacy Rule and your BAA allow, and limit each use to the minimum information needed for the task.

  5. Breach detection and notification

    Detect, assess and report breaches of unsecured PHI to the covered entity inside the window your BAA sets, so it can meet its own notification deadlines to patients and regulators.

  6. Workforce training and sanctions

    Train everyone with PHI access on their obligations, keep the records, and apply a documented sanctions policy when the rules are broken.

Our Services

Our HIPAA compliance services

Everything a Canadian team needs to satisfy a US healthcare customer, delivered by people who work in both regimes every day.

HIPAA Gap Analysis

A detailed comparison of your current PIPEDA or PHIPA posture against HIPAA’s three rules, so you know exactly what is missing before a US customer asks.

Security Risk Analysis

The Security Rule’s required risk analysis, documented in the form OCR and enterprise procurement teams expect, with a prioritized remediation plan.

Policy Development

HIPAA-aligned policies and procedures written for your Canadian operating context — not a US template with the letterhead swapped.

BAA & Vendor Readiness

Review of the Business Associate Agreements you sign and the subcontractor agreements you need, plus the evidence to satisfy vendor security questionnaires.

Staff Training

Role-based HIPAA training for engineering, support and operations teams so US privacy expectations are understood, not just acknowledged.

Ongoing Compliance Support

A Virtual Privacy Officer or vCISO to maintain the program, re-run the risk analysis as systems change, and answer customer audits.

Most engagements start with aThreat and Risk Assessmentor aPrivacy Impact Assessment, continue withpolicy development andcustom training, and are maintained by aVirtual Privacy Officer.

Why It Matters

Why HIPAA compliance matters for Canadian businesses

The US market is a significant opportunity for Canadian health-tech, and HIPAA readiness is the price of admission. Treated proactively, it becomes a selling point rather than a blocker.

Unlock US Healthcare Deals

US providers, payers and their procurement teams will not onboard a vendor without HIPAA evidence — a signed BAA, a current risk analysis and working safeguards.

Avoid Enforcement

OCR investigates complaints and breaches. Civil penalties can reach into the millions per calendar year per violation category, adjusted annually for inflation, plus multi-year corrective action plans.

Protect Patients and Reputation

Demonstrate that sensitive health data is protected across the border, and keep a breach from becoming the story your customers remember.

How We Work

From data map to evidence package in four steps

  1. Scope

    Map where US patient data enters, lives and leaves your systems, which contracts govern it, and which rules therefore apply to you.

  2. Assess

    Run the security risk analysis and the gap analysis against the Privacy, Security and Breach Notification Rules.

  3. Remediate

    Close the gaps in priority order — policies, safeguards, training, agreements — with your team doing the work and ours guiding it.

  4. Prove

    Assemble the evidence package customers and auditors ask for, and keep it current as your product and vendors change.

FAQ

HIPAA compliance questions, answered

Short answers to what Canadian teams ask us most. Something missing? Book a call and ask directly.

HIPAA is US law, so it does not apply to you directly as a Canadian business. It reaches you through your customers: if you create, receive, maintain or transmit protected health information for a US covered entity, you are a business associate, you will be asked to sign a Business Associate Agreement, and you become directly liable under the Security Rule. In practice, the moment US patient data is in scope, HIPAA is too.

A BAA is the contract a covered entity must have with any vendor that handles PHI on its behalf. It sets out permitted uses, required safeguards, breach-reporting timelines and what happens to the data when the relationship ends. If you serve US healthcare customers you will need one with each of them — and you need your own BAAs with any subcontractor, such as a cloud host or support vendor, that touches the same data.

Yes. A documented, organization-wide risk analysis of the threats to electronic PHI is a required safeguard under the Security Rule, not an optional best practice. It has to be accurate, cover all systems that hold ePHI, and be updated as your environment changes. Missing or incomplete risk analyses are among the most common findings in OCR enforcement.

No. Neither HHS nor the Office for Civil Rights certifies organizations as HIPAA compliant, and any product promising one is selling something else. What US customers accept instead is evidence: a current risk analysis, documented policies and safeguards, training records, signed BAAs, and often an independent report such as a SOC 2 with HIPAA-mapped controls.

They aim at the same thing — protecting personal health information — but from different directions. PIPEDA and PHIPA are principle-based and apply because of where you operate; HIPAA is rule-based and arrives through contract. Many controls overlap, so a strong Canadian privacy program is a head start, but HIPAA adds specific requirements such as the formal risk analysis, the BAA chain and defined breach-notification mechanics.

Your BAA will set the clock. You must contain the incident, assess whether unsecured PHI was compromised, and notify the covered entity within the contractual window so it can meet its own obligations to patients, HHS and, for larger breaches, the media. If the data also belongs to Canadians, PIPEDA or provincial breach rules may apply at the same time — which is why a rehearsed response plan matters.

It depends on your starting point. An organization that already runs a documented privacy and security program can usually close HIPAA-specific gaps in a matter of weeks; one starting from scratch should plan for a few months of policy, safeguard and training work. Scoping the data flows first is what keeps the timeline honest.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

What do you need a quote for? (select all that apply)

We only use your details to respond to this request.