Why a HIPAA BAA Is Not Enough for Canadian Dental Practices
Oct 04, 2026Your dental practice finds an AI tool that promises to make charting easier. The demonstration looks excellent. You ask the vendor about patient privacy, and the response arrives promptly: “We are HIPAA compliant, and we can provide a BAA.”
That is a useful starting point for a conversation. It is not the end of one for a Canadian dental practice.
Does a HIPAA BAA Protect a Canadian Dental Practice?
A HIPAA business associate agreement (BAA) is a contract built around obligations under US health privacy rules. It may contain valuable safeguards, but signing one does not, by itself, establish that an AI vendor’s service or its contract meets the privacy requirements applicable to a dental practice in Canada. Those requirements depend on the province, the organization, and the information and activities involved. [1][2][3]
The solution is not necessarily to reject US software. It is to establish, in writing, whether the vendor can support your actual Canadian obligations and the specific way your team intends to use the tool.
What a HIPAA BAA Covers, and What It Does Not
Under HIPAA, covered entities and their business associates use written agreements to specify permitted uses and disclosures of protected health information and related responsibilities. The US Department of Health and Human Services describes required contractual provisions for those relationships. [1]
A Canadian dental practice does not become HIPAA-regulated merely because a US vendor offers it a BAA. Conversely, an organization with independent US operations or activities may have additional obligations that require separate assessment. The label on the agreement cannot answer which laws apply. [1]
Canadian Privacy Laws Still Apply to Your Dental Practice
Canada does not have one identical privacy rule for every dental practice. Provincial health-information legislation, provincial private-sector privacy legislation, federal law where applicable, and professional standards can affect the answer. Canadian privacy regulators explicitly caution that generative AI obligations vary with the organization and its activities. [2]
For an Ontario example, the Information and Privacy Commissioner explains that health information custodians retain responsibilities when agents handle personal health information, and that electronic service providers have additional obligations depending on their role. Written agreements should clearly allocate responsibilities. [3][4]
For organizations subject to PIPEDA, the Office of the Privacy Commissioner of Canada advises assessing cross-border processing risks, securing comparable protection through contractual or other means, limiting the processor’s purposes, and being transparent about foreign processing. These are PIPEDA-specific principles, not a blanket claim that PIPEDA governs every dental clinic. [5]

What to Ask Your AI Vendor for Instead of a Standard BAA
Ask the vendor for a Canadian privacy and data-processing addendum, or an equivalent negotiated agreement, that addresses the applicable law and your actual workflow. There is no single universally prescribed document called a “Canadian IMA” that automatically makes every vendor compliant. The substance of the obligations matters more than the document title.
- Applicable law and roles: Identify the practice’s jurisdiction and the vendor’s role, including whether it acts as an agent, service provider, processor, or another type of party.
- Permitted uses: Specify what patient information may be processed, for what purposes, and prohibit unrelated uses unless separately authorized.
- AI model use: State clearly whether prompts, recordings, transcripts, images, and outputs may be used to train or improve models, and what controls or exclusions apply.
- Subprocessors and locations: Disclose where data is processed, stored, backed up, and accessed, including subcontractors and relevant changes.
- Security: Describe access controls, encryption, logging, incident management, staff access, and independent assurance that can actually be reviewed.
- Incidents: Require prompt notice, meaningful cooperation, investigation information, and support for the practice’s own reporting obligations.
- Retention and exit: Define deletion, return, backups, retention periods, and evidence of secure disposal when service ends.
- Oversight: Provide reasonable information, assurance, and escalation routes so the practice can evaluate and monitor the vendor.
These are recommended due-diligence and contracting subjects, not a claim that every clause is expressly mandated in identical wording by every Canadian statute. The final agreement should be reviewed against the laws and professional requirements relevant to your province. [2][3][5]
Your AI Scribe Comes With a HIPAA Agreement. Now What?
Imagine a practice considering an AI scribe that records a patient visit and drafts a clinical note. The vendor offers a standard HIPAA BAA. Before using it, the practice needs answers about recording and consent, where audio and transcripts travel, whether the vendor or its subcontractors can reuse the data, how long files are retained, and who can correct or delete information. The clinical team also needs a process for checking the output before it becomes part of the record. [2]
The safest immediate policy is simple: do not enter identifiable patient information into an unapproved AI tool. Review the product, the specific use case, the applicable privacy rules, and the agreement first. Then train the team on the approved workflow.
5 Questions to Send Your Dental AI Vendor Before You Sign
- Can you provide a Canadian privacy/data-processing addendum addressing the privacy law applicable to our province and our proposed use?
- Will any patient data, recordings, prompts, or outputs be used to train or improve AI models?
- Where will data be stored, processed, accessed, and backed up, and which subcontractors are involved?
- What are your incident notification, deletion, retention, and security assurance commitments?
- Will you review these terms with our privacy officer before we use the product with patient information?
If the vendor cannot answer, that is a reason to pause approval and obtain clarification. It is not, on its own, proof of a breach or of unlawful conduct.
The One Question Every Canadian Dentist Should Ask
Ask: “Can you show us how your service and agreement support the privacy obligations of our Canadian dental practice?”
Good AI adoption is not about finding a perfect badge. It is about understanding the information, assigning responsibility, formalizing protections, and checking that the safeguards continue to work. That is the kind of practical governance that helps teams use new technology with confidence.
Frequently asked questions
Is a HIPAA BAA useless in Canada?
No. It can provide useful contractual safeguards, but it is not a substitute for reviewing Canadian requirements.
Does every Canadian dental practice need an agreement called an IMA?
No universal document title applies across Canada. The needed terms and legal duties depend on jurisdiction and vendor role.
Can Canadian dentists use US-hosted AI software?
Potentially. Cross-border hosting is not automatically prohibited in every jurisdiction, but applicable legal requirements, transparency, risk, and contractual safeguards must be assessed.
Is a vendor’s “HIPAA compliant” claim enough?
No. Ask for the actual contract, technical safeguards, processing details, and evidence supporting the claim.
Can staff use the tool with patient data while contracts are being reviewed?
Do not authorize identifiable patient information until the practice has completed its review and approved the specific use.
Want your team to use AI more safely? Explore Myla training programs for practical privacy, cybersecurity, and AI education.
Sources and References
- US Department of Health and Human Services, Business Associates
- Federal and provincial privacy regulators, Principles for responsible generative AI
- Ontario IPC, Privacy and Security Considerations for Virtual Health Care Visits
- Ontario IPC, Guidance on third-party service providers
- Office of the Privacy Commissioner of Canada, PIPEDA Accountability Principle
Train Your Team to Spot AI Risks Today