logo
Canadians' health data at risk of being handed over to U.S. authorities, experts warn

Canadians' health data at risk of being handed over to U.S. authorities, experts warn

CBC31-07-2025
Canadians' electronic health records need more protections to prevent foreign entities from accessing patient data, according to commentary in the Canadian Medical Association Journal.
"Canadian privacy law is badly outdated," said Michael Geist, law professor and Canada Research Chair in internet and e-commerce law at the University of Ottawa and co-author of the commentary. "We're now talking about decades since the last major change."
Geist says electronic medical records systems from clinics and hospitals — containing patients' personal health information — are often controlled by U.S. companies. The data is encrypted and primarily stored on cloud servers in Canada, but because those are owned by American companies, they are subject to American laws.
For example, Geist points out, the U.S. passed the Clarifying Lawful Overseas Use of Data (CLOUD) Act in 2018, which can compel companies to disclose customer information for criminal investigations, even if it's stored outside the United States. The law allows for bilateral agreements with the U.S. and other countries. Canada and the U.S. began negotiations in 2022.
The companies have "Canadian laws that may say they've got to provide appropriate protections for that data," Geist said. "But they may have U.S. law that could compel them to disclose that information."
Canada's laws, Geist says, have not yet found a way to respond to that.
How health data could be used
The CMAJ commentary says "serious privacy, security, and economic risks arise when companies in other countries hold and use Canadian data."
Among them, the authors point to the potential use of that information for law enforcement surveillance, or by private companies seeking to use the data to make money.
Health data is deeply personal, and ongoing Canada-U.S. political tensions may cause some to be even warier about where and how their information is stored and used, says Lorian Hardcastle, assistant professor in the law faculty and Cumming School of Medicine at the University of Calgary.
"There is a compelling argument to be made to say, 'Well, you know, we just need to have this information stored in Canada and not have those dealings with American companies,'" said Hardcastle.
Aside from the CLOUD Act, another concern Geist lays out is the potential for foreign companies to profit off of Canadians' health data. With the growth of AI, Geist says that data has become increasingly valuable — a tremendous pool of information that could potentially be used to generate AI algorithms. (The cloud companies say their customers own and control their own data.)
"We should be the ones to benefit from that," Geist said. "We should be the ones who are entitled to appropriate privacy protections."
Dr. Sheryl Spithoff, an assistant professor at the University of Toronto, says these risks highlight how Canada's privacy laws fall short.
"This data is patient data. It belongs to patients. That should be used for reasons that are in their interests, that bring them benefit, that don't cause harm."
Tech companies respond
The CMAJ commentary says three U.S. cloud companies dominate: Google Cloud, Microsoft Azure and Amazon Web Services.
Google told CBC News that "customer data belongs to our customers, not to Google Cloud." It says, like many tech companies, it gets requests from governments and courts to disclose customer information, usually as part of criminal investigations. The company says it follows a "transparent, fair, and thorough process" to respond. It didn't comment specifically about Canadian health data.
"Google provides a response on a case-by-case basis, taking into account different circumstances and informed by legal requirements, customer agreements, and privacy policies," it said.
"We are committed to protecting privacy while also complying with applicable laws."
Microsoft said that in the second half of 2022, of the nearly 5,000 demands for "consumer data" it received from U.S. law enforcement, 53 warrants sought content stored outside of the U.S.
"Microsoft's compliance team reviews government demands for customer data to ensure the requests are valid, rejects those that are not valid, and only provides the data specified in the legal order."
Amazon said it "does not disclose customer information in response to government demands unless we're required to do so to comply with a legally valid and binding order."
In a statement, a spokesperson for Amazon Web Services wrote "there have been no data requests to AWS that resulted in disclosure to the U.S. government of enterprise or government content data stored outside the U.S. since we started reporting the statistic."
Limits to Canada's privacy laws
Privacy experts say the failure of Canada's privacy laws to keep pace with changing technology has put the country's data sovereignty at risk.
Geist says strengthening provincial laws and the federal Personal Information Protection and Electronic Documents Act, known as PIPEDA, could help create a guardrail against potential U.S. data requests reaching into Canada.
In his commentary, Geist calls for "stronger penalties for unauthorized disclosure of personal information without consent and guidance that foreign court orders related to Canadian data are unenforceable in Canada."
Innovation, Science and Economic Development Canada says PIPEDA applies when transferring data across the border, but Geist says the law itself isn't robust enough.
Geist also calls for the country to develop Canadian cloud servers for health data, and to ensure that data is hosted on Canadian soil.
The wealth of health information generated by the health-care system should stay in Canada and benefit Canadians, Geist says. He and his co-authors see the potential for health AI algorithms to be developed in Canada by Canadian companies, with robust safeguards, to support health-care decisions "based on data representative of Canada's population."
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Ontario hospital defends use of animals in research as critics speak out
Ontario hospital defends use of animals in research as critics speak out

National Post

time24 minutes ago

  • National Post

Ontario hospital defends use of animals in research as critics speak out

A lawyer for a national animal rights organization says it was shocked to learn from 'brave whistleblowers' about the conditions animals undergoing experiments at London's St. Joseph's Hospital are experiencing. Article content 'We been working hard to find loving homes for the dogs and pigs at St. Joseph's,' said Alanna Devine, director of campaigns for Animal Justice. 'We have been in communication with the hospital asking they release the dogs and pigs for rehoming since whistleblowers reached out to us a couple of months ago. Article content Article content Article content A story published Wednesday in the National Post and other Postmedia papers, including the London Free Press, detailed how Lawson Research Institute – the research arm of St. Joseph's Health Care London – is secretly testing heart attack recovery using dogs and puppies on its sixth floor. Article content The dogs used at St. Joseph's come from U.S. breeders before being subjected to the experiments, Devine said. Article content Insiders say the dogs are in cages at St. Joseph's and are alone 23 hours a day, the story said. Article content Article content Article content Devine said she doesn't know how many dogs have died. Article content Article content 'We know a number of dogs have been killed based on information from the whistleblowers,' she said, adding there is no federal regulation of lab animals. Article content Animal Justice posted a story and photos about the research at Lawson Research Institute on its website Thursday. Article content The dogs have shown 'troubling repetitive behaviours' such as pacing, tail sucking and repeatedly dunking their faces in water, the story said. Article content Dogs are heard whimpering and screaming in pain during recovery, Animal Justice said. Article content 'Animal care staff are emotionally devastated when animals they bond with are killed,' the story said. Article content The Free Press requested an interview with Donna Ladouceur, chair of the board at St. Joseph's Health Care London. The hospital responded with a written statement from its communications department that said the story published by Postmedia 'contains several inaccuracies of fact.'

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store