fbpx

Physiotherapy & Alberta’s HIA

Illustration showing circle of care centered aroundan x-ray image celebrating the addition of physiotherapists to the HIA

What Alberta Physiotherapists Need to Know About Their New Privacy Responsibilities

On June 22, 2026, regulated physiotherapists in Alberta became designated health information custodians under the Health Information Act (HIA). This change marks a significant shift in how physiotherapy clinics manage patient information, privacy compliance, and data security. 

In the webinar recording below, Brightsquid’s privacy experts walk through what these changes mean in practice, how clinics can build an effective privacy program, and the steps physiotherapists should take to meet their obligations under the HIA. Watch the full webinar recording (approximately 60 minutes):

Why This Privacy Webinar Matters For Physios in AB

For many physiotherapy clinics, privacy compliance has historically been governed primarily by Alberta’s Personal Information Protection Act (PIPA). The transition to custodian status under the HIA changes that framework. Physiotherapists who collect, use, disclose, store, and dispose of health information while providing care now have responsibilities similar to those of other healthcare custodians within Alberta’s healthcare system.

The change is designed to support more effective sharing of patient information within the healthcare “circle of care” while ensuring strong safeguards for patient privacy. It also helps facilitate participation in systems such as Alberta Netcare.

For clinic owners and lead practitioners, the transition is not simply a regulatory update. It requires the implementation of a structured privacy management program that demonstrates accountability and ongoing compliance.

Understanding Your Role as a Custodian

A key theme throughout the webinar is that privacy compliance begins with understanding the responsibilities attached to the custodian role. As a custodian, a physiotherapist or physiotherapy organization becomes accountable for protecting patient health information throughout its entire lifecycle.

Key responsibilities include:

  • Establishing and maintaining HIA-compliant privacy policies and procedures
  • Creating a privacy management program
  • Designating a Privacy Officer
  • Training and overseeing staff and affiliates
  • Managing vendor relationships through appropriate agreements
  • Completing Privacy Impact Assessments (PIAs)
  • Responding appropriately to privacy incidents and breaches

The webinar also explains how custodians, affiliates, and information managers each play different roles in protecting health information and why clear accountability is essential.

Privacy Impact Assessments: More Than a Regulatory Requirement

One of the most important topics covered is the Privacy Impact Assessment (PIA).

Many clinic operators view a PIA as a document required by regulators. In reality, a well-developed PIA is much more than a compliance exercise. It serves as a practical business tool that helps organizations identify privacy risks, implement safeguards, assign responsibilities, and prepare for potential incidents before they occur.

The webinar explains that a PIA demonstrates that an organization has:

  • Evaluated privacy risks across its operations
  • Implemented reasonable mitigation measures
  • Considered how patient information is managed throughout the clinic
  • Established appropriate privacy controls and accountability structures 

Importantly, all custodian-led physiotherapy organizations must submit a PIA to Alberta’s Office of the Information and Privacy Commissioner (OIPC).

Building a Strong Privacy Foundation

Compliance is not achieved through paperwork alone.

The webinar outlines the practical safeguards clinics should implement to protect protected health information (PHI), including administrative, technical, and physical controls.

Examples discussed include:

  • Strong password policies
  • Multi-factor authentication
  • Secure remote access
  • Controlled access to health information
  • Secure communication channels
  • Information Manager Agreements with service providers
  • Ongoing monitoring and auditing activities

A recurring theme is that privacy compliance is an ongoing process rather than a one-time project. Regular reviews, staff training, policy updates, and risk assessments are necessary to maintain compliance as clinics evolve. 

Privacy Compliance Versus Security

One of the more valuable discussions in the session explores the distinction between privacy compliance and cybersecurity.

While encryption, access controls, and other security measures are important, security alone does not guarantee compliance. True privacy compliance also requires policies, procedures, legal authority, appropriate disclosure practices, and accountability frameworks.

For healthcare organizations, protecting patient information means addressing both technical risks and governance responsibilities. A secure system without appropriate privacy controls still leaves an organization exposed.

Understanding and Preventing Privacy Breaches

The webinar also provides practical examples of how breaches occur in healthcare settings.

Many incidents stem from simple human error rather than sophisticated cyberattacks. Common examples include:

  • Sending emails to the wrong recipients
  • Incorrect use of CC instead of BCC
  • Misdirected faxes
  • Improper disposal of records
  • Failure to disable credentials after staff departures
  • Unauthorized access to patient records 

The presenters emphasize the importance of training, clear policies, credential management, and incident response planning to reduce risk and ensure compliance when incidents occur.

Practical Next Steps for Physiotherapy Clinics

If your clinic is preparing for HIA compliance, consider the following priorities:

  1. Designate a Privacy Officer.
  2. Review and update privacy policies and procedures.
  3. Identify all vendors that access or manage patient information.
  4. Put appropriate Information Manager Agreements and confidentiality agreements in place.
  5. Assess current security safeguards and access controls.
  6. Provide privacy and security training to all affiliates.
  7. Develop a breach response process.
  8. Complete and submit a Privacy Impact Assessment.

Additional Resources

Physiotherapists seeking additional guidance can access resources through:

Leave a Reply

Your email address will not be published. Required fields are marked *