The short version. A private home care agency in Alberta is governed by Alberta's own privacy law, PIPA, not the federal PIPEDA, and in most cases it is not a custodian under the Health Information Act. Because Carelyst stores all persistent data in Canadian data centres in Toronto, an Alberta agency using Carelyst avoids the written notices PIPA requires whenever personal information is handled by a service provider outside Canada. This page explains those rules in plain English, with the sections of the law named so your own advisor can check every claim.
Our general privacy practices are on the Privacy Policy and the PIPEDA & PIPA BC page. This page is not legal advice; it is a plain-language map of where the obligations sit.
PIPA (Personal Information Protection Act, SA 2003) is Alberta's private-sector privacy law. Alberta is one of the few provinces whose law has been declared substantially similar to PIPEDA, so for commercial activity inside Alberta, organizations follow PIPA rather than the federal Act. PIPEDA still applies to data that crosses provincial or national borders and to federally regulated employers.
The Health Information Act (HIA) governs health information held by custodians: hospitals, continuing care home operators, provincial health agencies such as AHS, pharmacies, and individually regulated professionals designated by regulation. A private-pay home care agency staffed by health care aides and LPNs is not on any of those lists, so it is normally not a custodian, and its client records fall under PIPA.
Two important nuances. If your agency delivers care under contract to AHS or another custodian, you handle that health information as the custodian's affiliate: the HIA governs it, the custodian keeps control of it, and you owe the custodian notice of any breach as soon as practicable. And if your agency employs a registered nurse, that RN is individually a custodian for records in her custody. Carelyst's per-agency isolated database and role-gated access apply the same protections either way; what changes is who answers for the data.
PIPA sections 13.1 and 6(2) create a duty most agencies only discover after choosing software. When an Alberta organization uses a service provider outside Canada to collect, use, store or disclose personal information, it must notify the individuals concerned, in writing or orally, before or at the time of collection or transfer, name a contact person who can answer questions about it, and maintain written policies listing the countries involved and the purposes authorized. "Service provider" is defined broadly enough to include a foreign-hosted software platform and the foreign sub-processors of a Canadian one.
Carelyst keeps all persistent data, including backups, in Canadian data centres in Toronto, in a dedicated database per agency. An Alberta agency running on Carelyst does not trigger the section 13.1 notice duty for its care records, because the service provider is not outside Canada. Agencies on foreign-hosted platforms carry that duty for every client and employee whose information the platform touches.
For agencies working under a custodian contract, the HIA Regulation adds a related rule: before health information is stored or used outside Alberta, the custodian must have a written agreement covering control, risk, safeguards, monitoring and remedies. Carelyst provides the safeguards documentation an agency needs to support that agreement.
Alberta introduced mandatory private-sector breach reporting on May 1, 2010, more than eight years before the federal rules took effect in November 2018. Under PIPA section 34.1, an organization must report a breach to the Information and Privacy Commissioner without unreasonable delay where a reasonable person would consider there is a real risk of significant harm, and the Commissioner can then require notification of the individuals affected. Failing to report is an offence with fines up to $10,000 for an individual and $100,000 for an organization.
Where Carelyst fits: if a breach ever creates a real risk of significant harm, we commit to notifying affected agency owners within 72 hours of confirming it, with the details an OIPC report requires. The Commissioner's guidance confirms an organization may authorize a third party, such as its software provider, in writing to report on its behalf; we support agencies either way. Agencies doing AHS-contracted work also owe the custodian breach notice under HIA section 60.1, where penalties reach $200,000 for individuals and $1,000,000 for organizations, which is a strong reason to know exactly where your visit records live.
Unlike PIPEDA, PIPA covers the employee information of provincially regulated employers. Your caregivers' certifications, schedules, performance notes, and the GPS coordinates captured when they clock in and out are "personal employee information": you may collect and use it without consent for managing employment, but current employees must receive reasonable advance notice of what is collected and why. Carelyst helps in two ways: location is captured only at the clock-in and clock-out moments, never as continuous tracking, so the notice you give caregivers is short and honest; and every correction to a punch records who changed it, when, and the stated reason, so the record you show an employee is one you can stand behind.
Alberta's Employment Standards Code is specific in a way paper timesheets struggle with. A few of the rules that matter daily to a home care agency, with the sections named:
One caution your payroll provider should hear: any source claiming home care workers are exempt from overtime as "domestic workers" is wrong for agencies. That exemption applies only where the employer ordinarily lives in the home; an agency is not resident in its client's home, so agency caregivers fall under the caregiver division above.
Alberta's Client Directed Home Care Invoicing program requires documentation of each service including the client's name, the date, the caregiver's name, the time care began and ended or the total time provided, and a summary of the care, completed at the time care is provided, with claims subject to compliance review and recovery of payment where a service is not properly documented. The requirement is technology-neutral, paper qualifies, but a record written at the door is precisely what a verified clock-in and clock-out produce without anyone remembering to write it.
A closing note. Privacy and employment law are technical and they change; the PIPA review process is active as of 2026 and no amending bill has been introduced yet. This page describes the law as we verified it from the current consolidations and names the sections so your own advisor can confirm each point. If your compliance review needs specific data-processing answers, write to legal@carelyst.ca or ask through the contact page, and a person will answer.