Every US-based dental AI competitor carries a HIPAA badge. HIPAA does not apply in Canada. Canadian dental practices are governed by PHIPA (Ontario), PIPA (BC), and HIA (Alberta). Aida is built for PHIPA-aware implementation: privacy-aware data-flow planning, scoped encryption review, interaction logging, retention planning, and a vendor agreement review path for each practice. Processing location, access, retention, and vendor terms are documented and reviewed before launch.
How we decide whether the service fits
We look at patient-call data flow, access control, retention, and vendor terms, then decide whether Aida is the right fix. The goal is a clear result, not another tool added before the problem is understood.
We first check patient-call data flow, access control, retention, and vendor terms. Then we decide whether Aida solves the problem.
Aida fits when the call workflow, storage path, access model, and fallback responsibilities can be reviewed before launch.
It does not fit when a practice wants a generic HIPAA claim without reviewing the applicable data flow.
Your practice keeps privacy accountability, patient-record decisions, staff review, and approval of the live call workflow.
PHIPA is Ontario's Personal Health Information Protection Act. It requires dental practices to protect patient data at every point of contact, including when a patient calls to book an appointment. Any third-party service that handles patient calls needs appropriate safeguards, agreements, and review.
PHIPA applies to every Ontario dentist and any staff member or third-party service that handles personal health information on their behalf. When a patient calls your practice to book an appointment or ask about coverage, that interaction creates personal health information: the caller's name, contact details, reason for calling, and any health details they share.
An after-hours answering service that records those calls, transcribes them, or books or prepares appointment requests is handling personal health information under PHIPA. That service needs appropriate security controls, a documented data flow, and a data processing agreement with your practice before it can be used responsibly.
Most dental answering services do not document this clearly for Canadian practices. US-based AI receptionists are usually built around HIPAA, not PHIPA. A HIPAA Business Associate Agreement should not be treated as a substitute for Canadian privacy review. This is not a minor technicality: it is a meaningful compliance gap that exposes your practice to regulatory risk.
HIPAA is a US law. It does not apply to Canadian dental practices. Vendors that advertise HIPAA compliance are not automatically PHIPA-aware. The two laws share similar goals but differ in jurisdiction, processing-location review, and breach notification timelines.
| Topic | HIPAA (US) | PHIPA (Ontario) |
|---|---|---|
| Jurisdiction | United States only | Ontario (PIPA in BC, HIA in Alberta) |
| Applies to dental practices | Only US-based practices | All Ontario dentists and staff |
| Data-flow review requirement | No explicit residency requirement | Processing location and cross-border transfer risk should be reviewed |
| Vendor agreement required | Business Associate Agreement (BAA) | Vendor agreement covering safeguards, access, retention, and notification |
| Breach notification | 60 days to notify HHS | Without delay, as soon as reasonably possible |
| Patient access rights | Right to access, amend, restrict | Right to access and correct personal health information |
A US dental AI receptionist should not be treated as PHIPA-ready just because it carries a HIPAA badge. Privacy-aware data handling requires a documented pre-launch review of processing location, access, retention, and vendor terms.
Aida supports PHIPA-aware implementation planning. Processing location, access, retention, vendor terms, and the agreed staff-review workflow are documented before launch.
Aida is planned around minimum necessary data, access review, retention planning, and implementation review. The exact data flow is validated with the practice before launch.
Data handling is scoped before launch, including encryption scope where applicable, access control, retention, and vendor terms.
Calls can generate a timestamped transcript, structured data record, and outcome log so staff can review what happened before updating the chart.
The agreed workflow documents what information is needed for each call and how it is handled. Processing location, access, retention, and vendor terms are reviewed before launch.
Call received
Aida answers the call. The connection method and call handling are reviewed during implementation before the workflow goes live.
Data collected
The information collected is defined in the agreed workflow and reviewed with the practice before launch. Aida does not provide diagnosis or clinical triage.
Handled under practice controls
Processing location, access, retention, vendor terms, and any applicable encryption scope are documented and reviewed before launch.
Appointment booked or call flagged
Aida completes bookings only where schedule access is supported and tested. Otherwise, it prepares a staff-ready request through the agreed escalation path.
Call record available for review
Your team reviews the configured call details through the agreed staff-review workflow.
PIPEDA is Canada's federal privacy law for private sector organizations. Dental practices in provinces without substantially similar legislation should review vendor workflows against PIPEDA's fair information principles.
Accountability
Accountability responsibilities are defined in the practice agreement and implementation review.
Identifying purposes
Aida identifies why it is collecting data at the time of collection. Disclosure that the call is handled by an AI assistant is configured to your jurisdiction's requirements and your practice's policy, and Aida always discloses when a caller asks.
Consent
Aida collects data only for purposes the caller has consented to: booking an appointment or getting practice information.
Limiting collection
Aida collects only the minimum data required to complete the call. No payment details, government IDs, or unnecessary personal information.
Limiting use, disclosure, and retention
Data is used only to serve your practice and is not sold. Vendor access and retention schedules are governed by the practice agreement and implementation scope.
Safeguards
Encryption scope, practice-level isolation, access logging, retention, and incident response responsibilities are reviewed before launch.
Data flow matters because patient information can move through telephony, transcription, storage, dashboards, and practice systems. Canadian dental practices should understand where that data is processed, who can access it, how long it is retained, and what agreements govern it.
PHIPA requires dental practices to use reasonable safeguards and appropriate vendor controls when personal health information is handled outside the clinic. Cross-border processing can be possible in some circumstances, but it needs careful review instead of generic HIPAA assurances.
For dental practices, this means that using a US-based dental AI receptionist, including competitors that advertise HIPAA compliance, should be evaluated against Canadian privacy obligations before launch. The risk is not theoretical: privacy commissioners have investigated cross-border handling of personal health information.
Aida's onboarding includes a data-flow review, minimum necessary data collection, access review, encryption scope where applicable, retention planning, and vendor agreement planning. The goal is simple: make the workflow useful without creating a privacy mess for the practice.
Privacy-aware data handling, PHIPA, PIPEDA, provincial health privacy laws, data processing agreements, and breach notification. If it affects your practice's compliance posture, it is covered here.
PHIPA is the Personal Health Information Protection Act, Ontario's health privacy law. It applies to all health information custodians in Ontario, including dentists. PHIPA governs how patient data is collected, used, stored, and disclosed. Any software that handles patient calls or books or prepares appointment requests on behalf of a dental practice needs appropriate privacy controls. Dental practices in BC fall under PIPA; in Alberta under HIA. Aida is designed around privacy-aware workflows for Canadian dental practices.
HIPAA is the US Health Insurance Portability and Accountability Act. It applies to American healthcare providers and does not apply in Canada. PHIPA is Ontario's equivalent. The core requirements are similar: protect personal health information, limit access, document activity, and get appropriate agreements with service providers. The key difference is jurisdiction: HIPAA compliance alone is not enough for PHIPA-aware planning. Data flow, safeguards, and vendor agreements need review.
Processing location, access, retention, and vendor terms are documented and reviewed before launch so the practice understands the agreed data flow.
The information collected is defined in the agreed workflow and reviewed with the practice before launch. Aida does not provide diagnosis or clinical triage.
Agreement terms are reviewed as part of onboarding. The review covers PHIPA obligations, privacy-aware data handling, retention schedules, safeguards, and breach-notification responsibilities so the practice understands the vendor terms before launch.
Aida is designed for Canadian dental privacy workflows, including PIPA in BC, HIA in Alberta, and federal PIPEDA where it applies. The implementation should still be reviewed against the practice's province, data flow, and vendor agreement.
Breach handling is defined during implementation and in the practice agreement. The review covers access logging, incident response, notification responsibilities, and applicable PHIPA, PIPEDA, and provincial obligations.
It depends on the vendor's data flow, safeguards, contracts, and the practice's privacy obligations. HIPAA alone should not be treated as enough for a Canadian dental practice. Ask where data is processed, who can access it, what agreements are available, and how breach notification works.
Canadian dental practices are fielding more calls than ever as patients navigate CDCP coverage and eligibility. Aida answers after hours, handles the intake, and gives your team a documented call record to review.
Vendor agreement path reviewed. Implementation reviewed before launch.