For organizations handling the health data of Québec residents, that data is classified as sensitive personal information under Law 25, triggering stricter obligations across the board. Québec is the beachhead: Ontario's PHIPA and other provincial health-privacy regimes carry parallel duties, and medical AI placed on the EU market adds a high-risk layer under the AI Act. Diagnostic AI, clinical decision support, and patient-facing systems each carry specific requirements that Veille monitors continuously.
Key obligations
Veille encodes Québec's Law 25, Ontario's PHIPA, and the EU AI Act for health AI. Some health-specific privacy regimes, such as Alberta's HIA, are on the roadmap, not yet encoded. If your health operations sit outside our encoded frameworks, talk to us first so we scope it honestly.
Health data is "sensitive" under Law 25 regardless of whether it directly identifies the patient. Inferred health characteristics, biometric data used to assess health status, and data from wearable devices all carry the stricter obligations. Treat all healthcare AI data as sensitive unless you have a legal opinion confirming otherwise.
Use cases
| System | Frameworks | Key obligations |
|---|---|---|
| Clinical decision support | Law 25EU AI Act | PIA, human oversight mechanism, transparency for decisions affecting individual care |
| Patient triage and prioritization | Law 25 | Automated decision transparency, human review pathway for priority-affecting outputs |
| Administrative AI (billing, coding) | Law 25 | PIA for health data processing, owner designation, documentation obligations |
| Predictive models (readmission, risk) | Law 25EU AI Act | Sensitive data full compliance stack, EU scope if European patient data is involved |
First step
Most healthcare organizations have more AI systems processing sensitive data than their privacy teams are aware of. Book a 30-minute call, and we'll start with an inventory.
Book a call →