📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

What is the BC E-Health Act

What is BC E-Health (Personal Health Information Access and Protection of Privacy) Act?

The BC E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, is the British Columbia statute that governs designated provincial Health Information Banks (HIBs), including CareConnect, PharmaNet, the Provincial Laboratory Information Solution, the Client Registry / Enterprise Master Patient Index, and the Provider Registry.

Map your BC E-Health controls See the core components

SBC 2008 c. 38 · Health Information Banks · disclosure directives · enforced by the BC OIPC

Definition

The BC E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, is the British Columbia statute that governs designated provincial Health Information Banks (HIBs), including CareConnect, PharmaNet, the Provincial Laboratory Information Solution, the Client Registry / Enterprise Master Patient Index, and the Provider Registry.

The BC E-Health Act was enacted in 2008 (SBC 2008 c. 38) and brought into force on 10 April 2009. It is the BC statute closest to Alberta's Health Information Act, which is why people often search for it as the “BC Health Information Act” or “BC HIA.” Unlike Alberta's Act, the BC statute governs only specifically designated provincial Health Information Banks (HIBs), not all health information held by all healthcare providers in the province.

A Health Information Bank is a database designated by ministerial order under section 3 of the Act. The designation order must specify the purposes for which the information in that HIB may be collected, used, and disclosed. Examples of currently designated HIBs include CareConnect, PharmaNet, the Provincial Laboratory Information Solution, the Client Registry / Enterprise Master Patient Index, and the Provider Registry.

For private healthcare practices in BC (independent dental, medical, naturopathic, chiropractic, optometric, pharmacy, and similar offices), the operative privacy law is BC PIPA, not this E-Health Act. For public bodies (health authorities, hospitals, the Ministry of Health), the operative law is the Freedom of Information and Protection of Privacy Act (FIPPA). The E-Health Act layers on top of FIPPA whenever those public bodies are working with personal health information from a designated HIB.

The Office of the Information and Privacy Commissioner for BC (OIPC) is the enforcement body for the E-Health Act, alongside its enforcement of PIPA and FIPPA.

Core components

Health Information Bank (HIB)

A health database designated by Order in Council under the Act. Each designation specifies the HIB's permitted purposes (treatment, billing, public health, planning, research, etc.).

Data steward / data stewardship committee

Each HIB has a chief data steward and may have a data stewardship committee that authorizes planning or research disclosures from the HIB.

Disclosure directive

A patient instruction attached to a HIB record limiting whether and to whom that information may be disclosed. Disclosure directives must be activated in the specific HIB to which they relate, on terms set by the designation Order.

Permitted purposes

Limited statutory list including identifying patients, providing or facilitating health services, identifying providers, chronic disease management, billing, and public health planning and research.

Data residency provisions

Personal health information from a HIB may be disclosed outside Canada only in narrow cases, such as health research with the person's express written consent (sections 14 and 18).

OIPC oversight and offences

The Office of the Information and Privacy Commissioner for BC handles investigations, audits, and complaints. Breaching a disclosure directive or the Act's disclosure limits is an offence with fines of up to $200,000 (section 24).

Interaction with FIPPA

The Act explicitly adapts FIPPA provisions for the health context. References to "public body" in incorporated FIPPA provisions are read as "health care body" for E-Health Act purposes.

Why it matters

The BC E-Health Act matters most directly to BC public-sector health bodies (health authorities, hospitals, the Ministry of Health) and to MSPs and SaaS vendors that interact with designated provincial HIBs. Most private BC healthcare practices do not have direct E-Health Act obligations; they sit under BC PIPA for their day-to-day records.

For MSPs serving BC health-authority clients or vendors plugged into CareConnect, PharmaNet, or any other designated HIB, E-Health Act compliance becomes a real procurement gate. Procurement teams ask about data residency, audit logging, disclosure-directive support in any system that touches HIB data, and the security-breach reporting expectations the OIPC has set.

For Calgary or US-based MSPs serving BC healthcare clients, the data-residency posture is operationally important. The E-Health Act's narrow limits on disclosure outside Canada, FIPPA's privacy impact assessment for sensitive information stored outside Canada, and BC PIPA cross-border questions together make Canadian-resident hosting the easy answer in procurement.

How Lavawall® helps with the BC E-Health Act

Lavawall® has a BC E-Health Act framework (listed as BC HIA in older material), alongside separate BC PIPA and BC FIPPA frameworks. Answers write to shared controls, so MSPs serving BC health authorities, hospitals, or HIB-connected vendors collect evidence once and use it across all three.

Lavawall® is hosted in Canada (AWS Montréal by default, moving to a Canadian-owned hosting provider in Vancouver in Q4 2026), so BC health information stored on Lavawall® itself stays in Canada. Native CAD billing eliminates the foreign-currency vendor relationship.

ThreeShield Information Security Corporation, the Calgary-based audit firm that built Lavawall®, supports BC clients on health-information security work, including the procurement-evidence requirements that flow from BC E-Health Act-connected systems. The control mapping reflects what BC OIPC investigations and procurement teams actually examine. For BC MSPs serving healthcare, Lavawall® produces the safeguards evidence, breach-detection, audit logging, and data-residency documentation that BC health-information procurement teams expect, including for FIPPA's mandatory breach notification for public bodies, in force since 1 February 2023.

Start your BC E-Health control mapping →

Frequently asked

Is the BC E-Health Act the same as the "BC Health Information Act" or "BC HIA"?
Yes, in practice. BC has no statute called the Health Information Act. People who search for the BC Health Information Act or BC HIA usually mean the E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, often called the BC E-Health Act. Private practices are covered by BC PIPA and public bodies by FIPPA.
What are the penalties under the BC E-Health Act?
Fines of up to $200,000. Section 24 makes it an offence to breach a disclosure directive or the Act's limits on collection, use, and disclosure, and officers who authorize the breach can be charged too.
Does the BC E-Health Act require breach notification?
Not directly. The Act has no explicit breach notification duty of its own. The health care bodies that run health information banks are public bodies, so FIPPA's mandatory breach notification (in force since 1 February 2023) applies to them.
Is the BC E-Health Act the same as Alberta's Health Information Act?
No. Alberta HIA is a broad provincial statute covering all custodians of health information in Alberta. The BC E-Health Act is much narrower; it governs only specifically designated provincial Health Information Banks. BC private healthcare practices are governed by BC PIPA for their general health records, not by this statute.
Does the BC E-Health Act apply to my dental practice?
Generally no. A private dental practice in BC is governed by BC PIPA for personal information including health information. The E-Health Act applies to designated Health Information Banks (CareConnect, PharmaNet, etc.), and practices that interact with those HIBs do so under the rules the HIB designation Order specifies.
Has the BC E-Health Act been declared substantially similar to PIPEDA?
No. Unlike BC PIPA (which has been declared substantially similar to PIPEDA), the BC E-Health Act has not received that designation. PIPEDA can still apply to federally regulated health-related work in BC.
What is a Health Information Bank?
A database that the Minister of Health has designated as an HIB by ministerial order under section 3 of the Act. The designation Order specifies the HIB's purpose, which determines what collection, use, and disclosure is permitted. Currently designated HIBs include CareConnect, PharmaNet, the Provincial Laboratory Information Solution, the Client Registry / Enterprise Master Patient Index, and the Provider Registry.
What is a disclosure directive?
A patient-driven instruction that limits whether and to whom personal health information from a HIB may be disclosed. The directive must be activated in the specific HIB to which it relates, in the manner the HIB's designation Order specifies.
Who enforces the BC E-Health Act?
The Office of the Information and Privacy Commissioner for British Columbia (OIPC), the same body that enforces BC PIPA and FIPPA.