📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

BC Health Information Act · BC HIA

What is the BC Health Information Act (BC HIA)?

When people say the “BC Health Information Act” or “BC HIA,” they almost always mean the E-Health (Personal Health Information Access and Protection of Privacy) Act, often called the BC E-Health Act. It is BC's closest match to Alberta's Health Information Act, but it only governs designated provincial health information banks. Most BC health practices are also covered by BC PIPA, and public bodies by FIPPA.

Map your BC health-information controls See the three statutes

BC E-Health Act (SBC 2008 c. 38) · BC PIPA · BC FIPPA · all enforced by the BC OIPC

Definition

“BC HIA” and “BC Health Information Act” are the names people use for the BC equivalent of Alberta's Health Information Act. No BC statute has that exact name. The statute they mean is the E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, often called the BC E-Health Act, and it is the framework Lavawall® lists as BC HIA. Because that Act is narrow, BC health information is really protected by three statutes that work together.

For private healthcare practices in BC (independent dental, medical, naturopathic, chiropractic, optometric, pharmacy, physiotherapy, and similar offices), the operative law is BC PIPA (the Personal Information Protection Act). PIPA governs personal information including health information held in private-sector hands.

For BC public bodies (health authorities, public hospitals, the Ministry of Health, public-sector medical research institutes), the operative law is the Freedom of Information and Protection of Privacy Act (FIPPA). FIPPA has its own rules for consent, access, security, privacy management programs, breach notification, and disclosure outside Canada.

For specifically designated provincial Health Information Banks (CareConnect, PharmaNet, the Provincial Laboratory Information Solution, the Client Registry / Enterprise Master Patient Index, the Provider Registry), the operative law is the BC E-Health (Personal Health Information Access and Protection of Privacy) Act. This is the statute people mean by “BC HIA,” and the closest BC match to Alberta's HIA, though it is much narrower in scope.

Core components

BC PIPA (Personal Information Protection Act)

Private-sector privacy law for BC. Governs all personal information including health information held by private practices. Most BC dental, medical, naturopathic, optometric, chiropractic, and pharmacy practices sit here.

FIPPA (Freedom of Information and Protection of Privacy Act)

Public-sector privacy law for BC. Governs health authorities, public hospitals, and the Ministry of Health. Requires a privacy management program and breach notification, and a privacy impact assessment before sensitive information is stored outside Canada.

BC E-Health Act (“BC HIA”)

The E-Health (Personal Health Information Access and Protection of Privacy) Act. Governs designated provincial Health Information Banks (HIBs) such as CareConnect, PharmaNet, and the Provincial Laboratory Information Solution. The closest match to Alberta HIA, though narrower in scope.

OIPC oversight

The Office of the Information and Privacy Commissioner for BC enforces all three statutes.

Breach notification

Mandatory for public bodies under FIPPA since 1 February 2023. BC PIPA does not require reporting to the OIPC, but the OIPC recommends notifying people at real risk of significant harm.

Why it matters

Procurement questionnaires, MSP proposals, and clinic operators use “BC HIA” all the time. Knowing it means the E-Health Act, and that BC PIPA and FIPPA carry most of the load, is what keeps the compliance work accurate.

For BC MSPs serving healthcare, the practical compliance picture is: BC PIPA for the great majority of private healthcare practice clients; FIPPA for public health authority work; and BC E-Health Act when the client interacts with provincial HIBs. Many MSPs have clients spanning more than one of these.

Cross-border data transfers are particularly sensitive in the BC health space. FIPPA required public bodies to keep personal information in Canada until the 2021 amendments replaced that rule with a privacy impact assessment and a risk assessment before sensitive information is stored outside Canada. The E-Health Act still limits disclosure of health information bank data outside Canada to narrow cases. For private practices under BC PIPA, US-hosted services raise procurement-evidence questions even where they are not strictly prohibited.

How Lavawall® helps with BC HIA and the E-Health Act

Lavawall® has a BC E-Health Act framework (the one listed as BC HIA), plus separate BC PIPA and BC FIPPA frameworks, alongside Alberta HIA, PIPEDA, Quebec Law 25, and HIPAA. Answers write to shared controls, so an MSP picks the right combination for each healthcare client and collects the evidence once.

Lavawall® is hosted in Canada (AWS Montréal by default, moving to a Canadian-owned hosting provider in Vancouver in Q4 2026), so BC health information stored on Lavawall® itself does not leave Canada. That matters for private-practice procurement (BC PIPA) and for public-body compliance (FIPPA and the BC E-Health Act).

ThreeShield Information Security Corporation, the Calgary-based audit firm that built Lavawall®, has worked with BC healthcare practices on PIPA breach-notification, security incident response, and procurement-evidence requirements. The BC control mapping reflects the actual question patterns BC healthcare procurement teams generate. For BC MSPs serving healthcare, Lavawall® produces both the technical-safeguards evidence the practice needs and the agent-relationship documentation that flows through to client procurement teams.

Start your BC health-information mapping →

Frequently asked

Does BC actually have a "Health Information Act"?
Not by that name. People who search for the BC Health Information Act or BC HIA usually mean the E-Health (Personal Health Information Access and Protection of Privacy) Act, SBC 2008 c. 38, often called the BC E-Health Act. It governs designated provincial health information banks such as CareConnect and PharmaNet. Private health practices are covered by BC PIPA, and public bodies by FIPPA.
Which BC statute applies to my dental, medical, or pharmacy practice?
A private-sector practice in BC is generally governed by BC PIPA. A practice operating under a public health authority is governed by FIPPA. A system that interacts with a designated provincial Health Information Bank (CareConnect, PharmaNet, etc.) is also subject to the BC E-Health Act for that interaction.
Does the BC regime require breach notification?
For public bodies, yes. Since 1 February 2023, FIPPA requires public bodies, including health authorities, to notify affected people and the BC OIPC without unreasonable delay when a breach could reasonably be expected to cause significant harm. BC PIPA does not require private practices to report breaches to the OIPC, though the OIPC recommends notifying people at real risk of significant harm. The E-Health Act has no separate notification duty of its own.
Is the BC regime stricter than Alberta HIA?
Not overall. The two differ rather than one being stricter or more lenient. Alberta HIA is more prescriptive about custodian-affiliate roles, Privacy Impact Assessments, and the provincial Netcare environment. BC's distributed regime is structurally more complex but substantively comparable on safeguards and breach notification.
Should BC MSPs serving healthcare also align to HIPAA?
Often, yes. When the BC practice has US clients or US-resident patients, HIPAA can become directly relevant. Even when it does not, HIPAA-aligned safeguards generally satisfy BC PIPA, FIPPA, and E-Health Act expectations, and many practices treat HIPAA as a useful superset.