PHIPA-Compliant AI Scribes, Explained
What PHIPA actually requires, why most AI scribes on the market can't clear that bar, and what to check before you let one near a patient chart.
Ambient AI scribes have gone from novelty to near-standard in Canadian clinics in under two years — and for good reason. Physicians using them report getting real evening and weekend time back. But "AI scribe" has become a category name for a wide range of products with very different data-handling practices, and most of the marketing doesn't mention the one thing that actually matters for a Canadian clinic: what happens to the recording after the appointment ends.
What PHIPA actually says
Ontario's Personal Health Information Protection Act (and its provincial equivalents — HIA in Alberta, PIPA in BC and Saskatchewan) don't ban AI. They require that any custodian of personal health information — which includes a clinic using a third-party tool to process patient conversations — maintain reasonable safeguards over that information's collection, use, disclosure, and retention.
In practice, that means a clinic adopting an AI scribe needs to be able to answer:
- Where is the recording processed and stored, physically and jurisdictionally?
- Who besides the clinic can access it — including the vendor's own staff and infrastructure providers?
- Is it retained after the note is generated, and if so, for how long and why?
- Is any of it used to improve or train a model that other clinics' data flows through?
A tool can be clinically excellent at generating a SOAP note and still fail every one of these questions. Those are two separate axes of quality, and most buying decisions only evaluate the first one.
Why US-hosted scribes are a harder sell than they look
Many popular ambient scribe products run on general-purpose cloud infrastructure based in the United States. That introduces the same jurisdictional issue Canadian legal and health privacy frameworks were partly designed around: data physically sitting on servers that a foreign government has a legal mechanism to compel access to, independent of Canadian law or the patient's consent. For a solo practitioner this can feel like an abstract risk. For a clinic handling mental health records, reproductive health information, or anything else where a breach would be genuinely harmful to a patient, it isn't abstract at all.
What to actually check before adopting one
If you're evaluating an AI scribe for your practice, the clinically-focused demo will always look good — that's not where the real difference is. Ask instead:
- Data residency — is processing and storage 100% within Canada, on infrastructure without a US corporate parent?
- Private vs. shared infrastructure — is your clinic's data flowing through a multi-tenant endpoint alongside hundreds of other practices, or through infrastructure your clinic effectively controls?
- Audit trail — can you export a log showing exactly when a recording was accessed, by what, and for what purpose?
- Training policy — is patient data used, in any form, to train or fine-tune a model? Get this in writing, not in a sales call.
- Retention — is audio deleted after transcription, or retained? If retained, where, and under what safeguard?
The alternative: infrastructure your clinic actually controls
WizardX runs AI transcription, secure voice recording, and private document intelligence on private GPU infrastructure inside Canadian data centres — not a shared cloud endpoint, and not anything with US jurisdiction exposure. Every access is logged and exportable. Nothing is used to train any model, for any customer, ever.
The clinical value of an AI scribe — less charting after hours, faster intake, better continuity — doesn't require accepting a data-handling model you can't fully explain to a patient if they asked. Increasingly, that's the actual bar clinics should be evaluating against, not just note quality.