Cross-Border PHI in 2026: Why US-Hosted EMR Add-Ons Trigger Law 25 and CLOUD Act Exposure for Ontario Clinics

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. I have been helping Canadian clinics and SMBs build PHIPA-defensible IT since 2012, across Toronto, Hamilton, and Metro Vancouver.

When an Ontario clinic signs an AI scribe or analytics add-on whose tenant sits in us-east-1, three regimes engage at once. PHIPA, wherever patient records are handled outside the practice. Quebec Law 25, where any patient is a Quebec resident. And the US CLOUD Act, over the very same records.

None of that goes away because the vendor encrypts at rest or holds a SOC 2 report. The practice is the Health Information Custodian and stays accountable for every downstream copy.

Below is what each regime requires, which of the three PHIPA hooks catches a cloud vendor, and the 6-step protocol I run on every cross-border procurement. It is the companion to the PHIPA-compliant AI playbook for Ontario clinics.

Key Takeaways.

  • The operative CLOUD Act text is 18 U.S.C. s.2713. It reaches records “located within or outside of the United States” whenever the provider is subject to US process.
  • PHIPA has no single cross-border rule. It has three hooks, and picking the wrong one is the commonest error I see: s.17 for agents, s.10(4) with O. Reg. 329/04 s.6(1) for non-agent providers, s.50 for disclosure outside Ontario.
  • Quebec Law 25 wants an assessment before the transfer, permits it where protection is adequate, and demands a written agreement. The s.90.12 ceiling is CA$10,000,000 or 2% of worldwide turnover, whichever is greater.
  • Canadian data residency is not a statutory requirement under PIPEDA or Law 25. It is a control you choose because it makes the accountability duty cheap to evidence.

Book a Free Clinic IT Consultation

The CLOUD Act in plain English (and why US tenant != Canadian residency)

Two details matter at procurement, and neither is in the vendor security one-pager. First, the operative provision is s.2713 of Title 18, added by Public Law 115-141, division V, on March 23, 2018. The bill numbered H.R. 4943 never passed alone, so citing it cites a bill rather than the enacted law.

Second, the trigger is jurisdiction over the provider, not the location of the disk. A scribe vendor incorporated in Delaware that hosts a Toronto practice in Canada Central is still a US provider under s.2713.

My read for an Ontario clinic is narrow and useful. Tenant region cuts routine exposure: it stops accidental cross-border replication and keeps support access inside Canada. It does not close the foreign-process question, and an assessment claiming otherwise is the error our engineers found most often in clinic files.

Not sure whether your scribe vendor’s parent is US-incorporated? Book a free vendor-residency review →

Quebec Law 25 cross-border transfer requirements

Read the rest of Law 25 s.17, because the later paragraphs are where Ontario clinics get caught. The information may be communicated if the assessment establishes adequate protection. That communication then needs a written agreement reflecting the assessment and any agreed mitigations.

The final paragraph extends the same duty to entrusting an outside party with keeping the information on your behalf. Handing consult audio to a hosted transcription model is exactly that. It does not ban the transfer, and reading s.17 as a residency mandate is the misreading I correct most often.

The penalty ceiling is real. Article 90.12 caps the monetary administrative penalty for a legal person at CA$10,000,000 or 2% of worldwide turnover, whichever is greater, and s.90.1 lists s.17 among the provisions that attract one.

Quebec reach is easier to trigger than clinic operators assume. One patient with a Gatineau or Montreal address puts that record inside Law 25. In our experience most border clinics run the assessment once for the whole panel, because screening addresses costs more than the assessment does.

PHIPA s.50 and the IPC’s expectations for off-shore PHI

PHIPA s.50 is the right rule for a genuine disclosure. It is often the wrong rule for a cloud vendor, and sorting that out is the first thing I check on a clinic file.

PHIPA s.2 defines an agent as a person acting for the custodian, in respect of personal health information, for the custodian’s purposes rather than the agent’s own. Where a vendor fits, s.17 governs. The custodian stays responsible and may permit the agent to act only where the custodian could act itself.

The breach clock is the other place clinic policy goes wrong. PHIPA s.12(2)(a) requires notice to the affected individual at the first reasonable opportunity, and the Act fixes no day count anywhere. The 60-day figure circulating in Ontario clinic templates is the HIPAA number, imported from a statute that does not bind a Canadian custodian.

Commissioner notification runs on a separate track. PHIPA s.12(3) plus O. Reg. 329/04 s.6.3 set seven triggers: theft, deliberate unauthorised use, further downstream use, a pattern of similar losses, and any loss the custodian judges significant. And s.10.1, the electronic audit log duty, still awaits proclamation, so audit logging is a s.12(1) reasonable-steps argument.

So a US-incorporated vendor with a SOC 2 report and a HIPAA business associate agreement is not sufficient documentation. The custodian still needs the Canadian analysis: which hook applies, the vendor named, categories enumerated, safeguards mapped. HIPAA binds covered entities inside the US framework and answers none of it.

Customer Lockbox is the control that makes Microsoft support access auditable rather than invisible. Our Purview eDiscovery and legal hold walkthrough for Ontario clinics covers the licence tier it needs.

Decision matrix: vendor comparison by tenant region and cross-border posture

I have written the matrix by vendor class rather than by brand, deliberately. Product-level residency claims rot inside a quarter, and the Vendor of Record list is now the authoritative source that blog tables like this one were trying to approximate.

Vendor class. Tenant region. Law 25 s.17 assessment needed? CLOUD Act exposed? Mitigations.
Canadian, on the Vendor of Record list. Canadian by program requirement. Yes, but short, and it clears. Low, no US parent. Agent determination, then s.6(1) clauses.
Canadian, not on the list. Usually Canadian, confirm in writing. Yes. Low, unless a US sub-processor is in the path. Sub-processor map first, residency lock-in second.
Foreign parent, not US. Canadian on request, rarely by default. Yes, with a full adequacy analysis. Depends on the sub-processor chain. Written region commitment, audit rights.
Microsoft 365 Copilot, Canadian-region tenant. Canada, under Advanced Data Residency. Yes, and it turns on key custody. Yes, Microsoft is US-incorporated. Hold 100% seat coverage, add clinic-held keys.
US-incorporated, US tenant only. US default, Canadian region rare. Yes, and it may not clear. Yes, full exposure. Negotiate a Canadian region, or document refusal.
Consumer chatbot, free or personal tier. US only. Not applicable, do not proceed. Yes, with no contractual hooks. Never for PHI, use a contracted tier.

The PIA template for cross-border SaaS in a Canadian clinic

The assessment is the artefact that shows a regulator you did the work. I keep mine under eight pages, named, dated, and signed by the privacy officer or principal physician. In our fourteen years supporting Ontario clinics, this is the document the IPC investigation team asks for first.

  1. Name the information categories. Consult audio, transcript, structured note, billing code, demographics. Flag mental health, sexual health, addiction, and minors separately.
  2. Name the purpose per flow. “The scribe drafts a SOAP note from consult audio” qualifies. “Workflow automation” does not.
  3. Decide agent or service provider. Everything downstream depends on it. Agent means s.17. Not an agent means s.10(4) with s.6(1). Onward disclosure means s.50.
  4. Map the vendor stack. Contracting entity, country of incorporation, tenant region, and every sub-processor with its storage location. Model hosting and transcription are separate rows.
  5. Run the adequacy analysis. Per destination: the governing regime and its enforcement, foreign process exposure such as s.2713 and FISA 702, and the safeguards actually on offer.
  6. Document the controls. Contract terms and technical measures, plus operational items such as audit-log access and data return on exit.
  7. Score the residual risk. One to five. Three or higher needs a written justification and a compensating control.
  8. Set consent posture and review cadence. Twelve months, or six if the score was three or higher.

Want the FC assessment template for a clinic procurement you have open? Book a 30-minute scoping call →

Mitigations: encryption keys held in Canada, contractual SCCs, and what residency lock-in requires

Layer 1: residency lock-in. Put the tenant-region commitment in the master services agreement, not the marketing site. Name the Canadian region. Bar migration without prior notice and your written opt-in. Set a repatriation window on termination.

Residency decisions are cheapest before workloads move. The guide to cloud migration challenges covers region lock, processor documentation, and the Canada East trade-off.

Layer 2: customer-managed keys held in Canada. Key custody changes the arithmetic. If the vendor holds the keys, US process served on it produces plaintext. If the clinic holds them in a Canadian key management service, the vendor produces ciphertext, because its s.2713 duty is to produce what it has.

The IPC of Ontario has not endorsed customer-managed keys as the only acceptable architecture, and I would not claim it has. The effect on s.2713 disclosure risk is still material.

Layer 3: PHIPA-equivalent contract terms. Standard contractual clauses are a European construct that travels well as a template. The Ontario version is a processing addendum carrying the s.6(1) restrictions plus PHIPA-equivalent security duties, breach notification, audit rights and survival past termination. Ask for it in writing before the pilot.

The 6-step vendor vetting protocol

This is what Fusion Computing runs on every cross-border procurement a clinic asks us to review. It costs roughly eight hours of our time for a typical scribe or analytics vendor, plus legal review of the addendum. We measured that across a year of clinic procurements before publishing it.

  1. Get incorporation and tenant region in writing. Legal entity name, country of incorporation, headquarters address, exact tenant region. From the vendor, in email or on paper. One hour.
  2. Map sub-processors and storage locations. This is where US model hosting inside a Canadian-branded product surfaces. One to two hours.
  3. Complete the eight-step assessment above for this specific vendor. Two to three hours.
  4. Negotiate the residency and key-management addendum. Lock the region in the agreement, confirm whether customer-managed keys are possible, document every refusal. One to two hours.
  5. Update the patient-facing notice. Name the vendor or category and the residency posture in the privacy policy and consent form. One hour.
  6. Set the cadence and run the 90-day audit. Calendar a twelve-month re-review, then confirm at 90 days that residency and key custody have not drifted.

Pair this with the OHIP billing data security checklist for the PHIPA billing-data version, or send us the vendor name and we will run steps one and two for you.

The first time I watched a clinic owner discover their AI scribe transcripts were being indexed in us-east-1 was a Tuesday morning in February 2026. The sales deck claimed Canadian residency for the audio file, which was true, and said nothing about the transcript index.

We caught it at step two and the vendor moved the index to a Canadian region inside 30 days. Without the sub-processor map, that clinic signs and stays exposed.

Mike Pearlstein, CEO, Fusion Computing. Anonymized clinic engagement, Q1 2026.

CLOUD Act bilateral agreement status by country. Per the US Department of Justice, the United Kingdom signed in October 2019 and Australia in December 2021. Canada has been in announced negotiations since March 2022 with no agreement in force. European Union negotiations resumed in March 2023. CLOUD Act agreements: who has one. Source: US Department of Justice. United Kingdom. Signed October 2019. Australia. Signed December 2021. Canada. Negotiations only, March 2022. European Union. Talks resumed, March 2023.

Do/Don’t

Do. This is the short version I give clinic owners, and it is what holds up when the IPC asks a custodian to explain a cross-border arrangement. It comes out of the procurement reviews we run for our clients across Ontario.

  1. Decide the PHIPA hook first. Agent under s.17, service provider under s.10(4) with O. Reg. 329/04 s.6(1), or disclosure under s.50. The rest of the file depends on it.
  2. Treat incorporation, not tenant region, as the CLOUD Act signal. Region helps and is worth buying. It does not close the question.
  3. Finish the assessment before the contract is signed. A post-hoc one reads as a retrofit.
  4. Name the vendor in the patient-facing notice. Named-vendor disclosure carries more weight than a generic sharing clause.

Don’t.

  1. Do not treat “HIPAA-compliant” as an answer. HIPAA does not bind an Ontario custodian.
  2. Do not publish a 60-day PHIPA breach deadline. The Act says first reasonable opportunity. Sixty days is the HIPAA figure.
  3. Do not skip the sub-processor map. The transcript-index trap above is what it exists for.
  4. Do not assume Law 25 is somebody else’s problem. One Quebec-resident patient is enough.

Further reading and primary sources

HOW THIS GUIDANCE WAS ASSEMBLED.

This draws on FC’s anonymized client data from 2025 and 2026 Ontario clinic engagements, and on an FC internal benchmark covering breach SOP rollout and scribe deployment for our clinic clients.

Over that sits first-person field observation from my own practice supporting regulated Canadian healthcare SMBs. Every statutory citation above was read against the primary instrument, not a secondary summary.

Frequently asked questions

Does PHIPA require personal health information to stay in Canada?

No. PHIPA contains no data-residency rule, and neither does PIPEDA. The OPC states that PIPEDA does not prohibit transferring personal information to another jurisdiction for processing. Schedule 1 Principle 4.1.3 requires contractual or other means providing a comparable level of protection. Residency is a control you choose because it makes that accountability duty far cheaper to evidence.

Which PHIPA section applies to a cloud AI scribe vendor?

It depends on the role. If the vendor acts for the custodian’s purposes it is an agent under s.2, so s.17 governs. If it supplies electronic means without being an agent, s.10(4) applies and O. Reg. 329/04 s.6(1) puts three duties on it directly. Section 50 covers disclosure to a person outside Ontario. Decide this before signing.

Does Quebec Law 25 apply to a clinic in Ottawa or Hamilton?

It can. Law 25 attaches to the personal information of Quebec residents, not to the geography of the holder. One patient with a Gatineau address brings that record inside s.17 when it moves to a US-incorporated vendor. Most border clinics run the assessment once for the whole panel, because screening addresses costs more.

Is a SOC 2 Type II report enough for a PHIPA cross-border file?

No. SOC 2 is a controls audit and says nothing about foreign legal process. The file needs the hook identified, the vendor named, data categories enumerated, the destination legal regime assessed, and safeguards mapped. SOC 2 is an input to step five above, not the artefact.

What about Microsoft 365 Copilot on a Canadian-region tenant?

Microsoft is US-incorporated, so 18 U.S.C. s.2713 reaches it whatever the tenant region. Canadian residency under the Advanced Data Residency add-on narrows the surface and carries weight in the PHIPA file. Watch the licensing rule: it needs 100% coverage of eligible paid seats, and below that Microsoft says data may be relocated with no warning at all.

If we hold the encryption keys in Canada, does the CLOUD Act stop applying?

It still applies to the provider, and the practical exposure changes anyway. Section 2713 obliges a provider to produce what is in its possession, custody, or control. Where the keys live in the clinic’s own Canadian key management service, what the provider holds is ciphertext. This stays the most underused mitigation in Canadian healthcare procurement.

Does PHIPA give us 60 days to notify after a breach?

No. PHIPA s.12(2)(a) requires notice to the individual at the first reasonable opportunity, and the Act sets no day count. Sixty days is the HIPAA figure and does not bind an Ontario custodian. Telling the Commissioner is separate: s.12(3) with O. Reg. 329/04 s.6.3 (2004) lists seven triggers, including theft, deliberate unauthorised use, and any loss the custodian judges significant.

Where does this fit in the broader healthcare AI rollout?

The cross-border analysis is one input into the assessment step, and it belongs before the pilot. The artefact lives with the assessment file and gets re-opened on any vendor acquisition. See the PHIPA-compliant AI playbook for Ontario clinics for the sequence and the AI scribe vendor comparison for product detail.

Schedule Your Free Clinic IT Consultation

Related Resources

Bottom line

Cross-border personal health information is a three-regime problem with one answer. Identify the PHIPA hook, document the analysis, and build the residency, key-custody, and contract stack. Read incorporation rather than tenant region as the CLOUD Act signal. Canadian residency is a control worth buying, not a rule you are obeying, and saying so is the stronger position.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611