Resources · For occupational therapists and privacy officers
The questions a privacy officer asks about an AI tool in home care, and what a good answer looks like
A privacy officer who reviews an AI documentation tool for a home care program will ask about a dozen questions, and almost all of them come from three places: the privacy law that governs the occupational therapist's client records, the AI scribe guidance that Canadian privacy commissioners published between September 2025 and January 2026, and the OT college's own expectations. This article lists the questions, explains where each one comes from, and describes what a complete answer from a vendor looks like. It is written for the OT or program lead who has to bring the tool through review, and for the privacy officer who has to sign it off. It is not legal advice; the sources are linked so the officer can read them directly.
Which privacy law applies to an occupational therapist's client records?
It depends on the province and on who employs the OT. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) is the baseline for private-sector organizations that handle personal information in the course of commercial activity, which includes a private OT practice. Quebec, British Columbia and Alberta have private-sector laws the federal government has declared substantially similar, so PIPEDA steps back inside those provinces. Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador have health-specific laws that are substantially similar for personal health information held by custodians (source 1). Those are Ontario's PHIPA, New Brunswick's PHIPAA, Nova Scotia's PHIA and Newfoundland and Labrador's PHIA. Alberta's Health Information Act (HIA) covers custodians in that province, and public bodies such as regional health authorities fall under each province's public-sector statute.
In practice the officer wants to establish two things: that the OT (or the OT's employer) is the custodian of the record, and that the vendor is something less than a custodian. Newfoundland and Labrador's PHIA, for example, makes a custodian of "a health care professional, when providing health care to an individual or performing a function necessarily related to the provision of health care" (source 2). That is the OT. The software company is, in that Act's terms, an information manager: a body that processes, retrieves, stores or disposes of personal health information, or provides information technology services to a custodian. The same division exists under every provincial statute, with different names, and it sets up every other question below.
Is the vendor an agent, an electronic service provider, or an information manager?
This is the officer's first structural question, because the label decides which contract is required. Ontario's IPC guidance explains that PHIPA "may also apply to developers of AI scribes depending on the nature of their role under PHIPA, for example if the developer is itself a custodian or acts as an agent or as a service provider," and that an electronic service provider is one that supplies services enabling a custodian to "collect, use, modify, disclose, retain or dispose of personal health information electronically" (source 3, p. 4). Whatever the label, the custodian stays accountable.
Alberta's OIPC is more prescriptive. If the vendor is an information manager under section 66 of the HIA, "the contract must contain the content set out in section 7.2 of the Health Information Regulation," and the vendor "cannot collect, use or disclose health information unless the custodian is permitted to do so under HIA" (source 4). Newfoundland and Labrador's PHIA requires the information manager agreement to be in writing and to "provide for the protection of the personal health information against unauthorized access, use, disclosure, disposition, loss or modification" (source 2, s. 22).
The Ontario guidance lists what the agreement should say, and it is a useful checklist in any province: a clause prohibiting the vendor from using the information for any purpose the custodian has not authorized; administrative, physical and technical safeguards, with an obligation to securely dispose of records at the custodian's request; an obligation to "proactively notify the custodian when the AI scribe is performing below pre-determined accuracy thresholds or is producing unexpected outputs"; cooperation in breach investigations; and "regular third-party assessments of its model" (source 3, pp. 21 to 22). A good vendor answer is a signed data processing or information manager agreement that already contains those clauses, rather than a promise to negotiate one later. The same guidance notes that the obligations apply "whether the service is paid or free" (p. 22), so a free trial on a personal phone is reviewed the same way as a purchased licence.
Does the client have to consent to the AI tool?
Yes, and the officer will want to see how the consent is worded and where it is recorded. The Ontario IPC's position is that "there is currently no statutory provision that explicitly permits the collection, use, or disclosure of personal health information by an AI scribe without consent," and that obtaining express consent before use and recording it in the health record "is a best practice" (source 3, p. 24). British Columbia's OIPC, writing under PIPA, asks for express rather than implicit consent, documented in writing, with the client told they can withdraw it "at any time, with no change to the level of care" (source 5). Alberta's guidance adds that where a recording device is not visible, the custodian must "obtain written consent from the individual" under section 23 of the HIA (source 4).
The colleges say the same thing from the professional side. The Alberta College of Occupational Therapists' April 2026 guideline states that "explicit informed consent is required whenever identifiable personal or health information is entered into" an AI tool (source 6). The College of Occupational Therapists of Ontario published its own question-and-answer resource on AI in practice in October 2024, covering ethics, privacy, informed consent and record keeping (source 7), and CAOT's 2024 practice document on assistive technology and AI asks therapists to "obtain informed consent, and ensure secure data handling when integrating AI and technology" (source 8).
For a home assessment the consent covers more than audio. Photographs of the home, measurements, and a 3D scan of the rooms are all personal information about the client and about anyone else who lives there. The consent script should name each of those, say who will see them, and say what happens if the client declines one part (for instance, notes and measurements but no scan). A vendor that supplies a plain-language consent paragraph the OT can adapt has done part of the officer's work.
Where is the data stored, and does it leave Canada?
Canadian privacy law mostly does not forbid storage outside the country, but it makes the custodian responsible for the consequences, so the officer needs a precise answer rather than a reassuring one. Ontario's IPC states that "although PHIPA does not prevent personal health information from being retained or stored outside Ontario or Canada, custodians are ultimately responsible for protecting the personal health information in their custody or control," and that they "need to be satisfied that the risks of processing data outside the country are appropriate considering the context" (source 3, p. 17). The federal Privacy Commissioner's long-standing guideline on transfers for processing says the transferring organization must ensure "a comparable level of protection while the information is being processed by the third party," must tell people their information may be processed abroad, and must accept that "no contract can override the criminal, national security or any other laws of the country to which the information has been transferred" (source 9).
Two provinces go further. Quebec's private-sector law, as amended by Law 25, requires a privacy impact assessment before personal information is communicated outside Quebec, and the assessment must conclude that the information would receive adequate protection (source 10). Newfoundland and Labrador's PHIA limits disclosure outside the province to listed circumstances, including the individual's consent and disclosures that support the delivery of health care (source 2, s. 47). British Columbia's OIPC asks organizations to assess "the potential risks of any cross-border disclosures" and to avoid vendors that process data in jurisdictions with inadequate privacy laws (source 5).
The complete vendor answer names the hosting region in writing, lists every sub-processor that touches identifiable data (including the speech-to-text and language-model providers, which are often separate companies), says whether support staff outside the region can access records, and says what changes if the region changes. The phrase "Canadian data centre" on a marketing page does not settle the question; the agreement should name the region.
Is client data used to train the model?
The officer will ask this in two forms: whether identifiable data is used, and whether "de-identified" data is used. The Ontario IPC notes that vendors "may request that custodians agree to disclose personal health information or de-identified data for the purpose of training and improving their AI model," that custodians "must not agree to disclose any personal health information to a third party vendor unless they have the legal authority to do so," and that sharing recordings or transcripts for that purpose requires the individual's consent first (source 3, p. 23). On de-identification the same guidance is blunt: "removing direct identifiers like name and personal health numbers is not sufficient," because clinical uniqueness in a rich dataset can raise the re-identification risk "to unacceptable thresholds," and the contract must prohibit any attempt to re-identify (p. 23). The federal Commissioner's principles for generative AI ask organizations to prefer anonymized, synthetic or de-identified data over personal information wherever feasible (source 11). British Columbia's guidance asks the same two questions and adds a third: whether de-identified information will be disclosed to third parties (source 5).
A clear vendor answer is a sentence in the agreement itself: identifiable client data is not used to train or improve any model, no de-identified derivative is created for that purpose, and the model providers in the chain are contractually bound the same way. If the vendor does train on de-identified data, the officer will want the de-identification method, the re-identification prohibition, and the fact disclosed in the custodian's public privacy statement, which the Ontario guidance requires (p. 23).
How long are recordings, photos and drafts kept, and how are they deleted?
Home assessment tools hold more kinds of data than a session scribe, so the retention answer has to be given per kind. The Ontario IPC's data minimization point is that an AI scribe "will capture every spoken word in a care visit," that "not all such information may need to be retained," and that custodians must decide whether keeping recordings and transcripts is consistent with PHIPA (source 3, p. 6). British Columbia's OIPC says voice recordings "must not be kept after transcription is complete" unless there is a clear justification (source 5). Alberta's guidance asks custodians to "detail how long the full recording will be retained by the AI scribe and why, and how the information will be securely deleted" (source 4).
Photographs, measurements and a 3D scan are different from audio. They are the evidence behind the recommendations in the report, and a funder or a college may later ask how a threshold height or a doorway width was arrived at. Those items therefore usually follow the custodian's clinical record retention schedule rather than being deleted after the report is drafted. The officer needs the vendor to state, for each data type, the default retention, whether the custodian can shorten or extend it, how deletion is confirmed, and what happens to the data when the contract ends. Audio should default to the shortest period the workflow allows.
What audit trail exists?
The officer will ask who can see a record, whether every access is logged, and whether the log can be produced. The Ontario guidance requires "monitoring, logging, and auditing measures in place to deter, detect, and prevent unauthorized use or disclosure," implemented "on an ongoing, targeted, and random basis," and expects contracts to guarantee the vendor can supply "the information that would be required in the case of a breach investigation by the IPC" (source 3, pp. 9 and 22). Alberta's guidance asks vendors to describe "how the AI scribe tool captures and retains logs of transactions" covering access, use and disclosure (source 4).
For an AI drafting tool there is a second audit trail that matters as much: the edit history. The officer, and later a college investigator, may want to know what the tool drafted and what the OT changed before signing. A vendor answer that covers both the access log (who opened which case, when, from where) and the authorship log (which sentences were generated, which were edited, who approved the final report) is complete. An answer that covers only login events leaves the second question open.
Who is accountable for the accuracy of what the tool writes?
The OT is, and the officer will want the workflow to make that unavoidable. The Ontario IPC requires custodians to have procedures so that "all records of personal health information created or altered by an AI scribe are reviewed by the custodian for accuracy before they are used for any purpose or disclosed to others," recommends that AI-generated content be flagged as unreviewed if it can reach a record before review, and asks for policies that require the custodian to "immediately cease operating AI systems if the AI system's performance falls outside an acceptable range" (source 3, p. 24). The Alberta College of Occupational Therapists puts it in professional terms: "registrants remain fully accountable for validating any AI-generated recommendations" before use, and AI-assisted content in the record "must be reviewed, corrected where necessary to ensure accuracy" (source 6).
The vendor's part of the answer is design. The tool should not be able to file, send or submit anything on its own; every draft should stay a draft until the OT signs it; and the tool should make it easy to trace a statement in the report back to its evidence (the note, the photo or the measurement it came from). The vendor should also be willing to state, in writing, what the tool does when it does not have enough information, which is that it leaves a gap for the OT rather than filling it.
Has a privacy impact assessment been done?
In Alberta this is not optional: section 64 of the HIA requires custodians to submit a PIA describing the effects of a proposed new practice involving identifying health information, and the OIPC has published a template specific to AI scribes (source 4). Ontario's IPC says custodians "should conduct a PIA before introducing an AI system, like an AI scribe," and pairs it with a threat risk assessment of the information assets involved (source 3, pp. 7 and 18). British Columbia's OIPC asks for a PIA "before adopting an AI scribe," updated when the tool's functions change (source 5). Quebec requires an assessment for any project to acquire, develop or redesign an information system that involves personal information (source 10). The Alberta College of Occupational Therapists asks registrants to "complete or update a Privacy Impact Assessment (PIA) before implementing new AI tools or systems" (source 6).
The custodian owns the PIA, but a vendor that has been through this before will hand over most of the inputs: a data flow diagram, the sub-processor list, the security summary, the retention schedule and answers to the standard questionnaire. Ask for that package on the first call. A vendor that cannot produce it has not been through a health-sector procurement yet.
What happens when something goes wrong?
The last question is about breach response, and the officer wants to see timelines and duties on both sides. Ontario's IPC expects policies that require contractors and vendors to notify the custodian of a breach or suspected breach "at the first reasonable opportunity," notification of affected individuals with their right to complain to the IPC, direct reporting to the IPC where appropriate, and annual breach statistics (source 3, p. 9). Newfoundland and Labrador's PHIA requires a custodian who reasonably believes there has been a material breach to inform the Commissioner (source 2, s. 15). Quebec requires notification of the Commission d'accès à l'information and of affected individuals when an incident presents a serious risk of injury, and a register of all incidents (source 10). British Columbia's guidance asks that vendors be "contractually obligated to report any privacy breaches" and to give timely notice of software updates that change how data is handled (source 5).
The vendor's answer is a clause with a number of hours in it, a named contact, and a commitment to preserve logs and assist the investigation. It should also cover the quieter failure: a model update that changes what the tool writes. The Ontario guidance treats a drop below agreed accuracy thresholds as something the vendor must proactively report, and the officer may reasonably ask for the same.
How OmaScan AI answers these questions. Client data is encrypted on the device, in transit and at rest, stored in a single server region named to you in writing before deployment, and never used to train AI. The privacy program is built on PIPEDA and PHIPA, and a privacy impact assessment and data processing agreement are available on request. OmaScan AI drafts; the OT reviews, edits and signs every report, and nothing is filed or sent without that sign-off, with an audit trail of who did what. The privacy policy is the authoritative statement of how personal information is handled, and the page for funders and organizations describes the procurement package. OmaScan AI is in active pilots with occupational therapists.
The questions, in one list
- Which privacy statute governs these records, and who is the custodian?
- What is the vendor under that statute (agent, electronic service provider, information manager), and is the required agreement signed?
- What consent is obtained from the client, in what words, and where is it recorded?
- In which named region is data stored, and who are the sub-processors, including the model providers?
- Is identifiable or de-identified client data used to train or improve any model, anywhere in the chain?
- What is the retention period for audio, transcripts, photos, measurements, scans and drafts, and how is deletion confirmed?
- Is every access logged, and is there an authorship log showing what the tool drafted and what the OT changed?
- Can the tool file, send or submit anything without the OT's sign-off?
- Has a PIA been completed, and what inputs does the vendor supply for it?
- What are the breach notification timelines and duties on each side?
- Does the vendor commit to report accuracy regressions and material model changes?
- Do the same terms apply to a free trial?
Common questions
Does PIPEDA apply to a sole-practitioner occupational therapist?
If the practice is private and charges for its services, it is a commercial activity, so PIPEDA applies unless the province has a substantially similar law that takes its place (Quebec, British Columbia and Alberta for private-sector information generally; Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador for personal health information held by custodians). An OT employed by a hospital or health authority is usually covered by that employer's public-sector or health statute instead. When in doubt, the provincial commissioner's office will say which law applies.
Can I use a free AI scribe on my own phone for home visits?
Only if it passes the same review as a paid tool. Ontario's IPC says custodians' obligations "continue to apply ... whether the service is paid or free," and its guidance describes a breach that began with a clinician installing an AI scribe on a personal device against the employer's policy. The consent, storage, training-use and retention questions above still need answers, and a consumer app's terms usually do not give them.
Does client data have to stay in Canada?
Under PHIPA, PIPEDA and most provincial laws, no, but the custodian remains responsible for protecting it wherever it is, must tell clients it may be processed abroad, and must accept that foreign law can reach it there. Quebec requires a privacy impact assessment before information leaves the province, and public bodies in some provinces have their own rules. The practical requirement is a named region in the agreement and a risk assessment that the officer is comfortable signing.
Who signs the information manager or data processing agreement?
The custodian does. In a private practice that is the OT or the practice owner; in a health authority or hospital it is the organization, usually through its privacy office or procurement, on behalf of the clinicians who use the tool. An OT working under contract to an organization should check whether the organization's agreement covers them or whether they need their own.
Sources
- Office of the Privacy Commissioner of Canada. PIPEDA in brief: the ten fair information principles and the provinces with substantially similar legislation. Read September 21, 2026.
- Government of Newfoundland and Labrador. Personal Health Information Act, SNL 2008 c. P-7.01, sections 2, 4, 15, 22 and 47. Read September 21, 2026.
- Information and Privacy Commissioner of Ontario. AI Scribes: Key Considerations for the Health Sector (PDF), January 28, 2026, with the companion checklist. Page numbers above refer to the PDF. Read September 21, 2026.
- Office of the Information and Privacy Commissioner of Alberta. Artificial Intelligence (AI) Scribe Privacy Impact Assessment Guidance (PDF), September 2025. Read September 21, 2026.
- Office of the Information and Privacy Commissioner for British Columbia. PIPA and AI scribes: best practices for healthcare organizations in BC. Read September 21, 2026.
- Alberta College of Occupational Therapists. Artificial Intelligence (AI) and Occupational Therapy (PDF), April 2026. Read September 21, 2026.
- College of Occupational Therapists of Ontario. Now Available: Artificial Intelligence (AI) in Occupational Therapy Practice, October 29, 2024. Read September 21, 2026.
- Canadian Association of Occupational Therapists. OT Practice Document: Assistive Technology and Artificial Intelligence (PDF), 2024. Read September 21, 2026.
- Office of the Privacy Commissioner of Canada. Guidelines for processing personal data across borders, January 27, 2009. Read September 21, 2026.
- Commission d'accès à l'information du Québec. Principaux changements apportés par la Loi 25: assessments before communicating information outside Quebec and for information system projects, incident reporting, automated decisions. Read September 21, 2026.
- Office of the Privacy Commissioner of Canada. Principles for responsible, trustworthy and privacy-protective generative AI technologies, December 7, 2023, modified May 6, 2025. Read September 21, 2026.