PIPEDA and dental software: what Canadian practices should ask any vendor
A dental practice stays accountable for patient information it gives a software vendor. Here are 12 questions to ask, and what Canadian law expects.
By the Tusko team
Published
On this page
A practice that puts patient information into software has not handed over responsibility for it. Under Canadian privacy law, the practice stays accountable.
That makes choosing software partly a privacy decision.
The practice needs to know where the information goes, who can see it, and what happens if something goes wrong.
This guide explains which law applies, and gives 12 questions to put to any vendor. It is general information, and no substitute for legal advice.
Twelve questions for any vendor, in five groups
A checklist of the 12 questions to put to a software vendor, in five groups. Where the information is: the country and data centres, the other companies that handle it, and access from outside Canada. Who can see it: vendor staff, your own team, and a record of who opened what. How it is protected: encryption and sign-in. When something goes wrong: breach notice and past breaches. When you leave: export and deletion.
Where the information is
- The country and the data centres, backups included
- The other companies that handle it
- Whether it can be reached from outside Canada
Who can see it
- Which vendor staff can open your records, and when
- What each of your own team members can see
- A record of who opened what
How it is protected
- Encryption in transit and at rest
- How users sign in
When something goes wrong
- How soon you hear about a breach, and what you are told
- Past breaches, and what changed afterwards
When you leave
- An export of all your data, in a format you can use
- When it is deleted, and how you will know
Which law applies to your practice
Canada has a federal private-sector privacy law and several provincial ones.
The federal law is PIPEDA. The Office of the Privacy Commissioner explains who it covers.
It applies to private-sector organizations that collect, use or disclose personal information in the course of a commercial activity.
Three provinces have their own private-sector laws that are deemed substantially similar: Alberta, British Columbia and Quebec.
An organization under one of those laws is generally exempt from PIPEDA for what happens within that province.
Four more provinces have substantially similar laws for personal health information: Ontario, New Brunswick, Nova Scotia, and Newfoundland and Labrador.
So the first question is where you practise. Your provincial regulator or privacy commissioner can tell you which law governs your patient records.
The laws differ in detail and agree on the outline. The questions below fit any of them.
The principle that matters most with a vendor
PIPEDA is built on ten fair information principles. Accountability is the first.
| Principle | What it asks of a practice |
|---|---|
| Accountability | Someone is responsible, by name |
| Identifying purposes | Say why information is collected |
| Consent | Have the patient’s agreement |
| Limiting collection | Collect only what is needed |
| Limiting use, disclosure and retention | Use it for that purpose, and keep it only as long as needed |
| Accuracy | Keep it correct |
| Safeguards | Protect it |
| Openness | Be open about your practices |
| Individual access | Let people see their own information |
| Challenging compliance | Give people a way to complain |
Accountability follows the information when it moves. The commissioner’s guidelines on processing across borders put it this way.
“The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.”
Office of the Privacy Commissioner of Canada
A software vendor is such a third party. The practice’s job is to make sure the protection is comparable, and to be able to show how.
Name one person at the practice
The first principle asks for someone who is responsible. In a small practice that can be the owner or the office manager.
That person keeps the vendors’ answers, knows who to call after a breach, and handles patients’ requests to see their records.
Put the name in your privacy policy. A patient with a question should not have to guess who to ask.
Twelve questions for any vendor
Ask for the answers in writing. A vendor that handles patient information properly will have them ready.
Where the information is
- In which country, and which data centres, is our data stored? Include backups.
- Which other companies handle it? Hosting, email, text messaging, analytics and support tools all count.
- Can it be reached from outside Canada? By the vendor’s own staff or contractors, for example.
Who can see it
- Which of your staff can open our patient records, and when? Support access should be limited and logged.
- Can we set what each of our own team members can see? A front desk login and a dentist’s need not be the same.
- Is there a record of who opened what? And can we see it.
How it is protected
- Is it encrypted in transit and at rest?
- How do users sign in? Ask about password rules and a second sign-in factor.
When something goes wrong
- How soon will you tell us about a breach, and what will you tell us? Get a number of hours or days.
- Have you had a breach affecting customers, and what changed afterwards?
When we leave
- Can we export all our data, in a format we can use?
- When do you delete it, and how will we know?
Add one more for any product that uses your data to improve itself. Ask whether patient information is used for anything beyond running the service for you.
How to read the answers
A clear answer names a country, a company or a number of days.
Be wary of an answer that only says the vendor takes privacy seriously. Ask again in plainer words.
Keep the replies. They are part of the record that shows you checked.
What the law expects after a breach
Question nine matters because the clock is the practice’s, too.
The commissioner’s guidance on breach reporting sets out three duties for organizations under PIPEDA.
- Report to the commissioner any breach that poses “a real risk of significant harm to individuals”
- Notify the people affected
- Keep records of all breaches
Notification has to be given “as soon as feasible” once the organization has decided the risk is real. Breach records must be kept for two years.
Whether a risk is real depends on two things: how sensitive the information is, and how likely it is to be misused. Health information is at the sensitive end.
A practice can only do this if its vendor tells it promptly. Put the vendor’s notice period in the agreement.
Provincial laws have their own breach rules. Check the one that applies to you.
Storing data outside Canada
PIPEDA does not forbid it.
The commissioner’s guidelines say the Act does not prohibit transferring personal information to another jurisdiction for processing.
Two conditions come with that. Protection has to be comparable, and the organization has to be open about it.
Openness includes telling people their information may be sent elsewhere, and that courts and authorities there may be able to reach it.
Canadian data residency for dental practices, explained covers this in full, including the stricter rules that apply to public bodies.
Put it in the agreement
Answers in an email are useful. Terms in a signed agreement can be relied on.
- The practice owns its data
- The vendor uses it only to provide the service
- Where it is stored, and notice before that changes
- The safeguards the vendor maintains
- Breach notice, with a time limit
- Export on request, and deletion when you leave
- The same terms passed on to anyone the vendor uses
Ask who the vendor’s privacy contact is, by name. A named person is a sign the rest has been thought through.
Keep your own record
A practice that can show its homework is in a far better position if a patient or a regulator asks.
Keep one page for each system that holds patient information.
That includes practice management software, imaging, an intraoral scanner’s cloud and any lab’s doctor portal.
On each page, note where the data is stored, the vendor’s answers, the agreement’s date and who at the practice is responsible.
Review the pages once a year. Vendors change hosts and add tools, and last year’s answer may not hold.
Remember the files that sit outside any system. Scans emailed to a lab, and photos on a phone, are patient information too.
Ask us the same questions
We make Tusko, so these questions apply to us. Our security page sets out how patient information is handled. Bring all twelve to a demo.
See how Tusko works for practices. For the federal dental plan’s effect on lab cases, read CDCP and lab fees.
Does PIPEDA apply to a dental practice in BC?
The federal privacy commissioner says Alberta, British Columbia and Quebec have private-sector laws deemed substantially similar to PIPEDA, and organizations under them are generally exempt from PIPEDA for what happens within the province. A BC practice should look to BC’s Personal Information Protection Act first.
Does patient information have to stay in Canada?
The federal commissioner’s guidance says PIPEDA does not prohibit transferring personal information to another jurisdiction for processing. It expects comparable protection by contract, and openness with patients about it.
Who is responsible if a software vendor has a breach?
The practice remains accountable for information it gave the vendor to process. That is why the agreement should say how quickly the vendor will tell you, and what it will tell you.
Is a signed agreement enough?
It is the start. Ask for the answers to the questions in this guide in writing, keep them on file, and ask again when the vendor changes how it works.
Sources
- Office of the Privacy Commissioner of Canada: PIPEDA requirements in brief
- Office of the Privacy Commissioner of Canada: Guidelines for processing personal data across borders
- Office of the Privacy Commissioner of Canada: What you need to know about mandatory reporting of breaches of security safeguards
Related guides
Under the Canadian Dental Care Plan, lab fees are reimbursed when they are reasonable and customary. Here is what that means for practices and labs.
Choosing a dental lab in Metro Vancouver comes down to driver routes, licensing and how the lab communicates. Here is what to check before you send a case.
A crown under the Canadian Dental Care Plan needs approval before treatment starts. Here is what the request needs, and how to keep the lab case moving.