Skip to Content
ANALYSISMEMBER

PIAs, shared custody, AI highlight changes to Alberta's Health Information Act

Amendments to Alberta's 2026 Health Information Act, now in force, introduce new obligations and compliance pathways for custodians and vendors.

Published
Subscribe to IAPP newsletters

Contributors:

Scott Sibbald

CIPM

Consultant

Range Road Consulting

Recent amendments to Alberta's Health Information Act came into force in June 2026, bringing new compliance pathways and obligations around privacy impact assessments, shared health information, de-identification, artificial intelligence and more.

Contained within a November 2025 omnibus bill that generated headlines in Alberta for other reasons, public reaction to the bill's privacy components was muted. 

There are nevertheless significant amendments deserving attention.

Privacy impact assessments

The HIA has contained a PIA requirement since 2001, providing both "custodians" to which the act applies and the Office of the Information and Privacy Commissioner of Alberta with experience completing and reviewing tens of thousands of PIAs over that time. For any new or changed administrative practice or information system involving the collection, use or disclosure of individually identifying health information, a custodian must complete a PIA and submit it to the OIPC for review and comment before implementing the practice or system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            

One of the challenges, however, with this legislative control has been that information security policies and safeguards are more often implemented by an "information manager" or health information services provider, not the custodian. 

To resolve this, "information managers," as defined under the HIA — such as an AI scribe tool, electronic medical record system or virtual care vendors — can now submit their information security policies to the OIPC for review and comment. 

The HIA requires an information manager's security policy to address the privacy, security and confidentiality risks, explain the functions and capabilities of the information system, and describe the system's privacy, security and confidentiality safeguards.

Contributors:

Scott Sibbald

CIPM

Consultant

Range Road Consulting

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership