Cyber insurance for Canadian healthcare practices comes with stricter underwriting, higher premiums, and often higher deductibles than a typical small business policy, because clinics sit at the intersection of three risk factors insurers price aggressively: highly valuable patient data, an attacker population that specifically targets healthcare, and a regulatory environment where a breach usually triggers notification duties under a provincial health privacy statute in addition to PIPEDA. If you run a dental office, a physiotherapy practice, a medical lab, or any small allied-health business that stores patient health information, understanding why insurers treat you differently — and what they'll ask for before offering competitive terms — puts you in a much stronger position when you sit down with a broker.
This guide walks through why healthcare is priced as a higher-risk category, how the patchwork of provincial health privacy laws layers on top of federal PIPEDA and Quebec's Law 25, the specific underwriting requirements healthcare applicants typically face, what a genuinely good healthcare cyber policy should cover, and realistic Canadian premium ranges by practice size. We've also included illustrative composite case studies based on the kinds of incidents Canadian clinics have experienced, a checklist to work through before you apply, and a comparison table of the major provincial health privacy regimes.
Who wrote this guide, and what IT Cares does and doesn't do
This article was written and reviewed by IT Cares certified technicians. IT Cares is an IT support and managed services company — we are not an insurance broker, and nothing here is insurance, legal, or privacy advice. What we do see regularly is the technical side of this problem: healthcare clients trying to get cyber insurance and discovering, often later than they'd like, that their EMR access controls, backup setup, or lack of MFA is the reason their premium quote came back higher than expected or their application stalled. This guide focuses on that technical and regulatory-context side, so you can walk into a conversation with a licensed insurance broker already understanding the landscape.
Why Healthcare Is a Higher-Risk Category for Insurers
Insurers don't single out healthcare arbitrarily. When an underwriter classifies a clinic differently from, say, a retail store or an accounting firm, they're pricing four factors that show up consistently in claims data across the industry.
1. Patient health records carry a much higher black-market value
A stolen credit card number is worth pennies to a few dollars on underground markets once card networks flag and cancel it, often within hours or days of a breach becoming known. A complete patient health record — name, date of birth, health insurance or provincial health number, diagnosis history, medication list, and sometimes billing and banking details — is far harder to "cancel." You can't reissue someone's medical history the way a bank reissues a card number, which means a stolen health record retains its resale value for identity theft, insurance fraud, and targeted phishing for years rather than days. Security researchers and insurers alike have long treated full medical records as commanding a significant premium over financial-only data on underground marketplaces, precisely because of that durability.
2. Ransomware groups specifically target healthcare
Healthcare providers are attractive ransomware targets for an uncomfortable but straightforward reason: clinics that can't access patient records can't safely treat patients, which creates enormous pressure to pay a ransom quickly rather than rebuild from backups over days or weeks. Attackers know this, and healthcare has consistently ranked among the most targeted sectors in ransomware activity trackers for several years running, spanning everything from small dental practices to hospital networks. A single-location clinic is not "too small to be a target" in the way many owners assume — automated scanning tools that look for exposed remote access or unpatched systems don't distinguish between a five-employee physiotherapy office and a large hospital; they simply flag whatever is vulnerable.
3. Higher regulatory exposure than most other sectors
A retail business that suffers a data breach generally has to consider PIPEDA and, if it operates in Quebec, Law 25. A healthcare practice usually has to consider those same federal and provincial general privacy frameworks and a separate, health-specific provincial statute that governs personal health information specifically, often with its own regulator, its own notification triggers, and in some cases its own penalty structure. That regulatory layering means a healthcare breach frequently costs more to respond to — more legal review, more notification complexity, more potential for a regulatory investigation — which insurers build directly into healthcare pricing.
4. Sensitive data means higher-stakes notification and reputational fallout
Patients are, understandably, far more sensitive about a breach involving their medical history, mental health records, or reproductive health information than they are about a breach involving a retail loyalty account. That sensitivity translates into a higher expectation of thorough, careful notification, a greater likelihood of media attention for larger incidents, and a higher bar for the kind of response a practice needs to mount to preserve patient trust — all of which factor into how insurers price the notification and crisis-management components of a healthcare cyber policy.
📊 IT Cares field note: We regularly see small healthcare practices assume that because they're a five- or ten-person office, they're "not the kind of target" ransomware groups care about. In practice, the size of the target rarely matters to the automated tools attackers use to find vulnerable systems — what matters is whether a scanner finds an exposed remote desktop connection, an outdated VPN appliance, or a set of credentials for sale from an unrelated breach. Being small doesn't reduce your exposure the way many owners expect; it mostly reduces your budget for responding to it.
Want your practice's security posture reviewed before you apply?
IT Cares can assess your EMR access controls, backups, and MFA setup against what healthcare insurers typically ask for — so you're not caught off guard mid-application.
The Provincial Health Privacy Patchwork: PHIPA, Quebec's Health Rules, HIA, and Beyond
One of the most common points of confusion we hear from healthcare clients is assuming that PIPEDA, or in Quebec Law 25, is the only privacy law they need to think about. In most provinces that have their own substantially similar health-specific legislation, the reality is that a dedicated provincial health privacy statute governs how "health information custodians" — a term that generally includes clinics, hospitals, pharmacies, and many individual practitioners — must handle personal health information, often instead of or alongside the general federal or provincial framework. This matters directly for cyber insurance because your policy's regulatory defence and notification coverage needs to actually match the notification regime that applies to you.
Ontario: the Personal Health Information Protection Act (PHIPA)
Ontario's PHIPA is administered by the Information and Privacy Commissioner of Ontario (IPC) and applies specifically to health information custodians handling personal health information in the province. PHIPA sets out its own breach notification obligations, which generally require notifying affected individuals at the first reasonable opportunity after a privacy breach involving their personal health information, and in many circumstances also require notifying the IPC itself, particularly for breaches meeting certain severity or scale thresholds. PHIPA also carries its own offence provisions with meaningful penalties for organizations and individuals who wilfully violate the Act's requirements.
Quebec: Law 25's health-specific provisions and the Act respecting health and social services information
In Quebec, healthcare practices need to think about both Law 25 — the province's overhauled private-sector privacy law, enforced by the Commission d'accès à l'information (CAI) — and Quebec's specific framework for health and social services information, which imposes additional obligations around consent, retention, and security for health and social services information specifically. Quebec's approach layers general privacy obligations (Law 25) with health-sector-specific rules, meaning a Quebec clinic's compliance and breach-notification posture typically needs to satisfy both frameworks simultaneously rather than treating Law 25 alone as sufficient for a health information incident.
Alberta: the Health Information Act (HIA)
Alberta's Health Information Act (HIA) is overseen by the Office of the Information and Privacy Commissioner of Alberta (OIPC) and applies to "custodians" of health information in the province, a category that includes regulated health professionals, clinics, and other health service providers. The HIA includes mandatory breach notification requirements to both affected individuals and the OIPC where a breach creates a real risk of significant harm, along with its own compliance and enforcement mechanisms distinct from Alberta's general private-sector privacy legislation.
Other provinces: confirm your specific statute
British Columbia, Manitoba, Saskatchewan, Nova Scotia, and other provinces and territories each have their own approach to health information privacy, ranging from dedicated health-specific statutes similar to Ontario's and Alberta's, to reliance on general provincial privacy law plus PIPEDA for private-sector custodians. Because this landscape genuinely varies by province and can change, and because your specific classification (health information custodian, regulated health professional, private clinic, etc.) affects which rules bind you, we strongly recommend confirming your exact obligations with your provincial privacy regulator or a lawyer familiar with health privacy in your jurisdiction rather than assuming any general guide, including this one, covers every province-specific nuance.
| Province / Framework | Regulator | Breach notification trigger | Notable penalty exposure |
|---|---|---|---|
| Ontario — PHIPA | Information and Privacy Commissioner of Ontario (IPC) | Notify affected individuals at first reasonable opportunity; notify IPC for breaches meeting statutory thresholds | Offence provisions with fines for wilful violations, applicable to organizations and individuals |
| Quebec — Law 25 + health/social services info framework | Commission d'accès à l'information (CAI) | Notify CAI and affected persons where a breach presents a risk of serious injury; additional health-sector-specific rules apply | Law 25 introduced substantially increased administrative and penal fines versus Quebec's prior privacy regime |
| Alberta — Health Information Act (HIA) | Office of the Information and Privacy Commissioner of Alberta (OIPC) | Notify affected individuals and the OIPC where a breach creates a real risk of significant harm | Offence and enforcement provisions distinct from Alberta's general private-sector privacy law |
| Other provinces / territories | Varies — provincial privacy commissioner or health-specific regulator | Varies; may rely on general provincial law and/or PIPEDA for private-sector custodians | Confirm directly with your provincial regulator or legal counsel |
For your cyber insurance application and coverage review, the practical takeaway is this: the regulatory defence and notification cost coverage in your policy needs to be sized to the actual regime that applies to your practice, not to a generic assumption that PIPEDA notification costs are all you'll face. A clinic in Ontario notifying under PHIPA, a clinic in Quebec navigating both Law 25 and health-sector rules, and a clinic in Alberta under the HIA can all face meaningfully different notification processes and costs for what looks like a similar underlying breach.
Standard SMB Cyber Insurance vs. Healthcare-Specific Underwriting
If you've ever seen a friend running a small retail or consulting business get a cyber insurance quote, you may notice their application looked considerably shorter and their premium considerably lower than what a healthcare practice of similar size faces. The table below outlines the practical differences we consistently see between a standard SMB cyber policy and healthcare-specific underwriting.
| Underwriting factor | Typical standard SMB policy | Typical healthcare-specific underwriting |
|---|---|---|
| MFA requirement | Often recommended, sometimes optional for smaller applicants | Frequently mandatory across email, remote access, and the EMR/EHR system before coverage is offered |
| Encryption of sensitive data | Encouraged, not always verified in detail | Often requires written confirmation that PHI is encrypted both at rest and in transit |
| Vendor security review | Rarely a formal application requirement | Increasingly requires EMR/EHR vendor security attestations or a SOC 2 report |
| Staff training documentation | General cybersecurity awareness sometimes asked about | Privacy training specific to the applicable health privacy statute, plus general security awareness |
| Breach notification protocol | General incident response plan often sufficient | Protocol specifically aligned to the provincial health regulator's notification requirements |
| Retention / deductible | Often lower for comparable revenue size | Often higher, reflecting elevated claim frequency and severity in the sector |
| Sub-limits on notification and regulatory costs | Sometimes bundled into a single aggregate limit | Often broken out with specific, sometimes lower, sub-limits given the higher likely cost per incident |
None of this means healthcare practices are being treated unfairly — it reflects genuinely different claims experience. It does mean that a healthcare applicant walking into the process expecting a standard SMB application is often surprised by how much more documentation and how many more security controls are expected before an insurer will offer competitive terms.
What Insurers Actually Require: A Closer Look
Multi-factor authentication, without exceptions
MFA has become close to a universal baseline requirement for healthcare cyber insurance, and its absence is one of the fastest ways to see an application declined outright or offered only at a substantially higher premium. Insurers want MFA specifically on email (a common entry point for business email compromise and phishing that leads to ransomware), any remote access tool used to connect to the practice's network, and the EMR/EHR system itself, since that's where the actual patient data lives.
Encryption of PHI at rest and in transit
Insurers increasingly ask applicants to confirm, sometimes in writing, that patient health information is encrypted both while stored (at rest) on servers, workstations, and backup media, and while being transmitted (in transit) between systems, such as when data moves between your EMR and a lab, a billing service, or a cloud backup provider. Most modern EMR/EHR platforms handle this by default, but confirming it explicitly, and getting that confirmation from your vendor in writing, is now a routine part of a strong application.
EMR/EHR vendor security attestations
Because most small healthcare practices don't build or host their own patient records system, insurers have started looking past the practice itself to ask about the vendor's own security posture. A SOC 2 report, a security whitepaper, or a written attestation describing the vendor's encryption, access controls, and breach history is increasingly requested as part of a healthcare cyber application, and having this documentation ready ahead of time can meaningfully speed up underwriting.
Documented staff privacy training
Insurers want evidence that staff have been trained not just on general cybersecurity hygiene (recognizing phishing, using strong passwords) but specifically on the privacy obligations tied to your applicable provincial health statute — who can access which records, how to handle a suspected breach, and what "minimum necessary" access looks like in daily practice. A dated training log or completion certificates for staff go a long way here.
Breach notification protocols specific to health regulators
A generic "we'll call a lawyer if something happens" plan is no longer sufficient for most healthcare applications. Insurers want to see that your practice has at least a basic written plan referencing your specific provincial health privacy regulator — the IPC in Ontario, the CAI in Quebec, the OIPC in Alberta, or your relevant province's equivalent — along with realistic notification timelines and a named point of contact responsible for coordinating a response.
Higher retentions and narrower sub-limits
Even with strong security controls in place, healthcare applicants should expect to see higher deductibles (retentions) than a comparable non-healthcare business, and sometimes narrower sub-limits on specific coverages like regulatory defence or notification costs, reflecting the insurer's higher expected claim severity in the sector. This is worth planning for financially rather than treating as a surprise at claim time.
A common mistake: applying before the basics are in place
We regularly see practices start the insurance application process before confirming MFA is actually enabled everywhere, before checking whether backups are genuinely isolated from the main network, or before requesting security documentation from their EMR vendor. This almost always slows the process down and can result in a materially worse quote, or a declined application, that could have been avoided with two or three weeks of preparation beforehand. Treat the checklist further down this article as a pre-application task list, not a post-application afterthought.
What a Good Healthcare Cyber Policy Should Cover
Not every cyber policy marketed to small businesses is genuinely built for the realities of a healthcare practice. When reviewing a policy with your broker, these are the components worth scrutinizing specifically because of how healthcare incidents tend to unfold.
Regulatory defence costs
Coverage for legal costs associated with responding to an investigation or inquiry from your provincial health privacy regulator — the IPC, the CAI, the OIPC, or your province's equivalent — separate from, and in addition to, any coverage for a federal PIPEDA-related inquiry. Given the layered regulatory exposure discussed earlier in this guide, confirm this coverage explicitly names or clearly includes provincial health regulators rather than only referencing general privacy law.
Patient notification costs, sized realistically
Notification costs for a healthcare breach tend to run higher than a general consumer breach because health-specific rules can require more detailed notices, and because clinics often need dedicated staff time or a call centre to field patient questions about sensitive medical information. Make sure the notification cost sub-limit in your policy reflects a realistic scenario for your actual patient volume, not a generic figure that might undershoot what a mid-sized clinic notifying several thousand patients would actually need.
Business interruption for an EMR outage
If your EMR or scheduling system goes down because of ransomware or another covered cyber event, a clinic can lose the ability to safely see patients, verify medication histories, or process billing, all of which translates into real lost income and extra expense. A healthcare-appropriate policy should include business interruption coverage with a waiting period and payout cap that actually matches how quickly downtime becomes costly for your specific practice, rather than a generic small-business template built around less operationally sensitive downtime.
Ransom negotiation and payment support
Given how frequently healthcare is targeted by ransomware specifically, confirm whether your policy includes access to a professional ransom negotiation service (typically through an insurer-designated panel vendor) and coverage for the ransom payment itself if negotiation and payment become the least-bad option. Understand any exclusions or conditions tied to this coverage, including sanctions screening requirements that can affect whether a payment can legally be made at all.
Data restoration and forensic investigation costs
Coverage for the cost of a professional forensic investigation to determine what happened, what data was accessed, and whether notification obligations were triggered, along with the cost of restoring or rebuilding systems and data after an incident, both of which can be substantial for a clinic without extensive in-house IT resources.
Third-party liability for vendor-caused incidents
Because most small practices rely on a third-party EMR/EHR vendor, billing processor, or cloud backup provider, confirm whether your policy responds if the breach originates on the vendor's side rather than your own network, since patients and regulators generally won't distinguish between "our system" and "our vendor's system" when it's your practice's patient data that was exposed.
How a Healthcare Practice Should Prepare to Apply for Cyber Insurance
The following steps mirror what we walk healthcare clients through before they sit down with an insurance broker. None of this is insurance advice — it's the technical groundwork that makes the insurance conversation faster, cheaper, and more likely to result in a policy that actually fits your practice.
Inventory every system that touches patient health information
List your EMR/EHR platform, billing software, imaging systems, booking portal, email, backup systems, and any third-party vendor with access to PHI, so you know exactly what an insurer will be underwriting.
Turn on multi-factor authentication everywhere
Enable MFA on your EMR/EHR, email, remote access tools, and admin accounts. Most healthcare cyber insurers now treat MFA as a baseline requirement, not an optional upgrade, and will decline or heavily surcharge applicants without it.
Confirm PHI encryption at rest and in transit
Verify with your EMR/EHR vendor and IT provider that patient data is encrypted both while stored and while transmitted, and get that confirmation in writing for your application.
Gather EMR/EHR vendor security attestations
Request your EMR/EHR vendor's SOC 2 report, security whitepaper, or written attestation covering their own safeguards, since insurers increasingly ask about vendor-side security, not just your own.
Document staff privacy and security training
Keep records showing staff have completed privacy training relevant to your province's health privacy statute and basic cybersecurity awareness training, since insurers ask for this as part of the application.
Write down your breach notification and business continuity plan
Have a plain written plan for who you would call, how you would notify your provincial health privacy regulator and affected patients, and how the clinic would keep operating if the EMR were unavailable for several days.
Why preparation changes the outcome, not just the price
Practices that walk into an application with these six steps already done don't just tend to get a better premium — they tend to get broader coverage with fewer exclusions, because the insurer has less uncertainty to price around. An underwriter facing an application with clear answers and supporting documentation can offer terms with more confidence than one facing vague or incomplete answers, where the safest response from the insurer's side is to narrow coverage, raise the deductible, or decline altogether.
Checklist: Before You Apply for Healthcare Cyber Insurance
Work through this list with your IT provider before you request quotes. Most Canadian healthcare-focused underwriters will ask about several of these items directly on the application form.
- ☐ Multi-factor authentication enabled on email for every staff member with an account
- ☐ Multi-factor authentication enabled on the EMR/EHR system itself, not just the network login
- ☐ Multi-factor authentication enabled on any remote access tool (VPN, remote desktop, remote support software)
- ☐ Written confirmation from your EMR/EHR vendor that patient data is encrypted at rest
- ☐ Written confirmation that patient data is encrypted in transit between systems
- ☐ Backups isolated from the main network (not simply an additional folder on the same server) and tested for restoration
- ☐ A current inventory of every system and vendor with access to patient health information
- ☐ EMR/EHR vendor's SOC 2 report or written security attestation on file
- ☐ Staff privacy training records specific to your province's health privacy statute
- ☐ General staff cybersecurity awareness training records (phishing recognition, password hygiene)
- ☐ A written breach notification protocol naming your provincial health regulator and realistic timelines
- ☐ A basic business continuity plan for an EMR outage lasting more than a few hours
- ☐ Confirmation of who at your practice is responsible for coordinating an incident response
Realistic Canadian Case Studies: Three Composite Scenarios
The following scenarios are fictional composites built from patterns common to Canadian healthcare cyber incidents. They're meant to illustrate how coverage and out-of-pocket exposure typically play out, not to describe any specific real practice or claim.
Case study 1: A Toronto dental clinic and a phishing-driven ransomware event
The practice: A two-dentist clinic in Toronto with roughly 3,800 active patient files, six staff, and a cloud-hosted EMR/EHR platform. The clinic carried a healthcare cyber policy with a $1 million CAD aggregate limit, a $2,500 CAD retention, and an annual premium of roughly $2,100 CAD.
What happened: A front-desk staff member clicked a phishing link disguised as a courier delivery notice, which led to credential theft and, within 48 hours, ransomware deployed against the clinic's local server hosting scanned intake forms and billing records (the core EMR data itself remained safe in the vendor's cloud environment, which was separately secured). The clinic was unable to access historical scanned documents for five business days.
What the policy covered: Forensic investigation (~$14,000 CAD), a portion of business interruption for the five-day disruption, and notification costs for the roughly 900 patients whose scanned intake forms were confirmed accessed, including a notification mailing and a dedicated phone line for patient questions (combined notification and crisis communication costs of roughly $19,000 CAD).
Out of pocket: The $2,500 retention, plus roughly $6,000 CAD in costs above the business interruption sub-limit related to temporary paper-based workflows during the outage, and the clinic's own staff time coordinating the response, which the owner estimated at over 40 hours across the two dentists and office manager.
Case study 2: A Montreal physiotherapy practice and a Law 25 notification process
The practice: A three-location physiotherapy practice in the greater Montreal area, roughly 5,200 active patient files, 14 staff across locations, carrying a $2 million CAD aggregate cyber policy with a $5,000 CAD retention and an annual premium of approximately $3,600 CAD.
What happened: An unpatched remote access tool used for after-hours administrative work was compromised, giving an attacker access to a shared drive containing patient assessment notes, insurance claim forms, and some payment information for roughly 2,100 patients across the three clinics.
What the policy covered: Forensic investigation, legal costs for navigating both Law 25 and Quebec's health and social services information framework simultaneously (roughly $22,000 CAD combined), notification to the CAI and affected patients, and credit monitoring offered to the subset of patients whose payment information was involved (combined notification and monitoring costs of approximately $31,000 CAD).
Out of pocket: The $5,000 retention, plus costs above the regulatory defence sub-limit of roughly $4,500 CAD, and a noticeable dip in new patient bookings in the month following local news coverage of the incident, which the practice estimated cost several times more in lost revenue than the direct claim costs — a reminder that reputational impact often outweighs the direct financial line items covered by a policy.
Case study 3: A Calgary medical lab and a business email compromise
The practice: An independent diagnostic lab in Calgary processing referrals for several family physician clinics, roughly 9,000 patient records annually, 22 staff, carrying a $3 million CAD aggregate policy with an $8,000 CAD retention and an annual premium of roughly $5,400 CAD, reflecting the lab's higher patient volume and broader referral network.
What happened: A business email compromise attack impersonated the lab's billing manager and attempted to redirect a payment from a referring clinic; the attempt was caught before funds moved, but the investigation revealed the attacker had been inside the lab's email environment for roughly three weeks, during which some patient result notifications may have been visible.
What the policy covered: Forensic investigation to determine the scope of email access (~$18,000 CAD), legal review under the HIA to determine notification obligations, notification to the OIPC and the roughly 1,400 patients whose result notifications were assessed as potentially exposed, and system hardening recommendations implemented as part of the claim response.
Out of pocket: The $8,000 retention, and the lab's decision to invest an additional $12,000 CAD beyond what the policy covered in upgraded email security and staff training, treated internally as a proactive cost rather than a claim expense, to reduce the likelihood of a repeat incident.
What Healthcare Cyber Insurance Costs in Canada: Realistic Budget Ranges
Premiums vary by insurer, patient volume, claims history, location, and — as this whole guide has emphasized — how strong your security controls already are. The ranges below reflect what small to mid-sized Canadian healthcare practices commonly see, presented as a starting point for budgeting conversations rather than a quote.
| Practice size / patient volume | Typical annual premium (CAD) | Typical retention / deductible (CAD) |
|---|---|---|
| Solo practitioner, under 2,000 active patients (e.g. single dentist, single physiotherapist) | $900 – $2,200 | $1,000 – $2,500 |
| Small clinic, 2,000 – 5,000 patients (e.g. multi-practitioner dental or physio office) | $1,800 – $4,000 | $2,500 – $5,000 |
| Mid-sized practice / multi-location, 5,000 – 10,000 patients | $3,200 – $6,500 | $5,000 – $10,000 |
| Diagnostic lab or larger allied-health network, 10,000+ patients | $5,000 – $12,000+ | $8,000 – $20,000+ |
Practices with strong existing security controls — MFA everywhere, encrypted and tested backups, documented staff training, and a written incident response plan — routinely land at the lower end of these ranges or negotiate meaningfully better terms, while practices with significant gaps can see premiums well above the upper end, additional exclusions, or declined applications until the gaps are addressed. These figures are illustrative composites for budgeting purposes, not quotes; your actual premium depends on your specific insurer, claims history, and risk profile, and should come from a licensed broker.
Canadian Resources Worth Knowing About
A few federal and provincial resources are worth bookmarking as you work through this process, beyond the provincial health regulators already discussed above.
- Business Development Bank of Canada (BDC) — bdc.ca publishes general guidance and financing options for Canadian small businesses investing in cybersecurity improvements, which can be relevant if closing security gaps ahead of an insurance application requires capital investment.
- Innovation, Science and Economic Development Canada (ISED) — ised-isde.canada.ca maintains resources on Canada's federal digital and cybersecurity policy landscape relevant to businesses of all sizes, including healthcare providers.
- Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca is the federal regulator for PIPEDA and a useful starting point for understanding how federal privacy law interacts with provincial health privacy statutes.
- Information and Privacy Commissioner of Ontario (IPC) — the provincial regulator for PHIPA, with guidance specific to health information custodians in Ontario.
- Commission d'accès à l'information du Québec (CAI) — the provincial regulator for Law 25 and Quebec's health and social services information framework.
- Office of the Information and Privacy Commissioner of Alberta (OIPC) — the provincial regulator for the Health Information Act (HIA) in Alberta.
None of these bodies sell or recommend insurance policies — that decision should always go through a licensed insurance broker familiar with healthcare cyber risk in your province. What these resources are genuinely useful for is confirming your exact regulatory obligations, which in turn helps you and your broker make sure your policy's regulatory defence and notification coverage actually matches what you're required to do.
If you'd rather have a professional evaluate where your practice's technical safeguards stand before you start requesting quotes, our security audit service reviews exactly the kind of controls insurers ask about — access management, encryption, backup resilience, and network exposure — and our cybersecurity services can help close specific gaps once they're identified. There's no requirement to navigate this alone or to guess at what "good enough" looks like before an insurer tells you otherwise.
Frequently Asked Questions
Get Your Practice's Security Posture Ready for Underwriting
IT Cares can review your EMR access controls, backups, and network security against what Canadian healthcare cyber insurers typically require — so your application starts from strength, not scramble. Not insurance advice; we handle the IT side.
Comments (3)
We got our renewal quote back and the premium jumped almost 40% because we didn't have MFA on our EMR yet. Wish I'd read something like this before the renewal conversation instead of during it. Fixing it now.
Didn't know PHIPA and PIPEDA could both apply depending on the situation. Our broker mentioned it once but this breaks it down way more clearly. Sharing with our office manager.
The case study about the lab and business email compromise hit close to home, we had something similar happen to a referring clinic we work with. Getting our email security reviewed after reading this.
Leave a Comment