CPSA AI Policy Template: What Alberta Clinics Need Under the HIA (2026)
Alberta is the one Canadian province where the privacy regulator has said, in writing, that a clinic must file a privacy impact assessment before turning on an AI scribe. That single fact changes what an Alberta clinic AI policy has to do. It is not enough to tell staff to be careful; the policy has to sit on top of a completed PIA and describe controls the regulator expects to see. This guide covers what the College of Physicians and Surgeons of Alberta (CPSA) and the Office of the Information and Privacy Commissioner (OIPC) each expect, and what the policy needs to contain.
What CPSA expects
CPSA's updated Advice to the Profession, 'Artificial Intelligence in Clinical Practice', covers ambient scribes, documentation tools, intake and triage, and clinical decision support. Its premise is that AI changes nothing about a regulated member's responsibilities: privacy, safe care, accurate records, and accountability for clinical decisions all remain with the physician.
- Complete or update a privacy impact assessment before introducing an AI tool into clinical practice.
- Inform patients and obtain consent before recording or transcribing a clinical encounter with an AI scribe, explain the purpose and the privacy and accuracy risks, and document that discussion.
- Document how and when AI is used in the patient record, especially where it informed a diagnosis, treatment, or a clinical note.
- Review AI-generated content before it enters the record. Regulated members remain fully accountable for all record content and clinical decisions.
What the OIPC requires under the Health Information Act
On September 3, 2025 the OIPC issued its 'Artificial Intelligence (AI) Scribe Privacy Impact Assessment Guidance'. It states that custodians are required under section 64 of the Health Information Act (HIA) to submit a PIA to the Commissioner before using an AI scribe, and it sets out what that PIA must address. The guidance is the checklist a clinic's policy has to satisfy:
- A project description and data flow diagram showing where health information goes, including any processing outside Alberta or Canada.
- Contracts under which the vendor acts as the custodian's information manager under section 66, collecting, using, retaining, and destroying health information only as the HIA allows, with the custodian retaining control.
- A clear prohibition on the vendor using patient information to improve or train its models unless legally authorized.
- The limitation principle (section 58): collect and use only what the purpose requires.
- The duty of accuracy (section 61): a review step so that AI-generated notes are correct before they are relied on.
- Security safeguards (section 60) and breach reporting (section 60.1), including how the clinic would learn of and report a vendor-side breach.
- Patients' rights of access and correction (sections 7 and 13), which extend to AI-generated content in their record.
The OIPC has also published guidance for small custodians on the use of AI generally, which applies the same principles to tools other than scribes. The College of Family Physicians of Alberta maintains AI scribe guidelines for its members that align with both regulators.
The sections an Alberta clinic AI policy needs
- Scope: physicians, nurses, allied staff, administrative staff, students, and locums; every AI tool including features inside the EMR.
- PIA gate: no AI tool touches health information until a PIA covering it has been completed and, for AI scribes, submitted to the OIPC. The policy names who owns the PIA.
- Approved tools: the specific tools cleared under a PIA, and a rule that nothing else may process patient information. Consumer chatbots on personal accounts are named as prohibited.
- Consent and notice: the script staff use before an AI scribe records, how a patient's refusal is handled, and how the consent discussion is documented.
- Documentation of AI use: how the record shows that AI contributed to a note, a summary, or a decision.
- Physician review: every AI-generated note is read and corrected before signing; decision support informs, never decides.
- Vendor process: information manager agreement in place, no training on patient data, data location known, breach notification terms, retention and destruction terms.
- Incident reporting: what staff do when health information reaches an unapproved tool, including self-reporting without penalty, and how breaches are assessed for reporting to the OIPC.
- Review date: the policy names an owner and an annual review, and is re-checked whenever the PIA is amended.
The fast path
Our generator produces a complete clinic AI policy with Canadian privacy clauses, healthcare-specific data rules, and Canadian spelling when you select Canada as your jurisdiction, plus a vendor assessment checklist and a staff acknowledgment form in the full pack. It gives you the policy layer; the PIA itself is a separate document your privacy officer prepares using the OIPC's template. Preview the entire policy free before paying. It is a self-help template, not legal advice.
Generate your AI policy in 3 minutes
Customized to your industry, jurisdictions, and tools. Free preview, $ 49 one-time to download, delivered instantly.
Generate an Alberta clinic AI policy