
Two acronyms get thrown around in the same sentence a lot, and most clinics we talk to aren’t sure which one actually governs them. Short answer: probably both.
PIPEDA is federal. It applies to personal information handled in the course of commercial activity—which covers a private clinic’s business generally, including a patient’s contact details or billing information.
PHIA is Manitoba’s own law, and it’s specifically about personal health information—the more sensitive category, covering trustees (health custodians like clinics and physicians) directly.
Here’s the part that catches people out: several provinces—Ontario, Quebec, New Brunswick, and Newfoundland & Labrador—have their own health-privacy law recognized as “substantially similar” to PIPEDA, so PIPEDA steps aside there. Manitoba hasn’t received that exemption. Which means for a private Manitoba practice, PHIA and PIPEDA can both be in play on the same piece of information at the same time.
This isn’t fully settled even among people who do this for a living—it’s a genuinely underspecified corner of the law. It’s also exactly why we don’t market Tasrif as “PIPEDA compliant” and call it done. Both laws exist, both matter, and if you’re making a decision that turns on the answer, that’s a conversation for your own privacy counsel, not a vendor’s blog post.