veille Built for, Healthcare (Québec + EU)
Vertical

Healthcare AI processes the most sensitive data. The regulatory obligations match.

For organizations handling the health data of Québec residents, that data is classified as sensitive personal information under Law 25, triggering stricter obligations across the board. Québec is the beachhead: Ontario's PHIPA and other provincial health-privacy regimes carry parallel duties, and medical AI placed on the EU market adds a high-risk layer under the AI Act. Diagnostic AI, clinical decision support, and patient-facing systems each carry specific requirements that Veille monitors continuously.

Data classificationSensitive under Law 25
Primary frameworksLaw 25, EU AI Act (medical)
PIA requiredBefore every AI deployment on health data

Key obligations

What healthcare AI compliance requires.

Scope

Veille encodes Québec's Law 25, Ontario's PHIPA, and the EU AI Act for health AI. Some health-specific privacy regimes, such as Alberta's HIA, are on the roadmap, not yet encoded. If your health operations sit outside our encoded frameworks, talk to us first so we scope it honestly.

Law 25, Art. 3.3 and 17 Stricter PIA requirements for sensitive data
Health data is explicitly classified as sensitive under Law 25. AI systems processing health information require a Privacy Impact Assessment before deployment, completed, not retroactive. Explicit consent documentation and a designated privacy officer are also mandatory.
Law 25, Art. 12.1 Automated decisions affecting patient care
AI systems that make or influence clinical decisions (triage prioritization, referral recommendations, medication flagging) may constitute automated decisions under Law 25 if there is no meaningful human deliberation before the output is acted on. Transparency notices and human review pathways are required.
EU AI Act, Annex III Medical device AI: potential high-risk classification
AI systems intended to be used as medical devices, or embedded in medical devices, may fall under Annex III for organizations serving the European market. Software that provides diagnostic or therapeutic recommendations is potentially in scope. High-risk (Annex III) provisions apply 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI.
Law 25, Art. 25 De-identification of health data for AI training
Health data used to train or evaluate AI models must be de-identified in compliance with CAI standards. Organizations must document that de-identification was performed and that the process meets the regulatory threshold before any model training proceeds.
Important

Health data is "sensitive" under Law 25 regardless of whether it directly identifies the patient. Inferred health characteristics, biometric data used to assess health status, and data from wearable devices all carry the stricter obligations. Treat all healthcare AI data as sensitive unless you have a legal opinion confirming otherwise.

Use cases

Healthcare AI systems that Veille monitors.

SystemFrameworksKey obligations
Clinical decision support Law 25EU AI Act PIA, human oversight mechanism, transparency for decisions affecting individual care
Patient triage and prioritization Law 25 Automated decision transparency, human review pathway for priority-affecting outputs
Administrative AI (billing, coding) Law 25 PIA for health data processing, owner designation, documentation obligations
Predictive models (readmission, risk) Law 25EU AI Act Sensitive data full compliance stack, EU scope if European patient data is involved

First step

Health AI compliance starts with knowing what you have.

Most healthcare organizations have more AI systems processing sensitive data than their privacy teams are aware of. Book a 30-minute call, and we'll start with an inventory.

Book a call