Let AI help your clinicians. Keep every action lawful, inside the circle of care, and replay-provable.
Canadian health data is among the most tightly governed personal data anywhere. Ontario’s PHIPA, the federal PIPEDA, and the proposed AIDA each set out what may be done with personal health information, by whom, and on what lawful basis. Generative AI tools optimise for fluency — not for lawful purpose, not for the circle of care, not for an auditable access record. The KYE Canada-Health Authority Pilot™ sits between your AI and your patient data: it governs every AI-assisted action at the boundary, and emits a signed, replayable evidence record your regulator can verify offline.
A governed boundary for AI-assisted workflows over personal health information.
- Lawful-purpose resolution. Every AI-assisted action that touches personal health information must resolve to a lawful purpose under PHIPA — consent, circle-of-care implied consent, or an express statutory authorisation — before it executes. Actions with no resolved lawful purpose are refused at the boundary and logged.
- Circle-of-care boundary. Implied consent does not reach beyond the circle of care. An AI-assisted disclosure that would reach an external recipient without an explicit lawful basis is refused until that basis is recorded.
- The audit-log duty, discharged as evidence. Every AI-assisted access to personal health information emits a complete, signed access-evidence record — the PHIPA electronic audit-log duty, produced as a KYE Evidence Pack™ and Replay-Proof™ derivable from public keys alone, not a reconstructive after-the-fact log.
- Breach-notification readiness. A security-safeguards breach creating a real risk of significant harm is flagged to the accountable Health Information Custodian for the PIPEDA s.10.1 report to the OPC and, at the prescribed thresholds, the PHIPA notification to the Information and Privacy Commissioner of Ontario. KYE™ produces the evidence and raises the flag; the custodian files.
It consumes the frameworks KYE™ already maps — it does not re-map them.
The Canada jurisdiction framework spine carries the per-requirement bijection for each statute. The Canada-Health pilot binds onto that spine and consumes it: the pilot’s rules reference the spine’s framework slices rather than re-describing the law. You can read the underlying coverage on the framework pages.
- PHIPA (Ontario). Consent and lawful purpose, circle-of-care implied consent, data minimisation, the electronic audit-log duty, access and correction, and IPC breach notification for personal health information. See the PHIPA Ontario coverage.
- PIPEDA. The ten Schedule 1 fair-information principles plus the mandatory breach-of-security-safeguards report under s.10.1. See the PIPEDA coverage.
- AIDA (advisory). The high-impact-system accountability and human-oversight concepts. AIDA is tabled / lapsed and not in force, so the pilot treats it as a readiness mapping — never an in-force obligation. See the AIDA coverage.
The Canada-Health Authority Pilot™.
Canada-Health Authority Pilot™
A paid pilot for a Canadian hospital, provincial health authority, digital-health vendor, clinic network, or health insurer running AI-assisted workflows over personal health information. Scoped under NDA; synthetic / demo data only — no real patient data enters the pilot tenant.
- Lawful-purpose resolution + circle-of-care boundary on every AI-assisted action
- PHIPA electronic audit-log duty discharged as a signed Evidence Pack™
- Breach-notification readiness for PIPEDA s.10.1 and PHIPA IPC notification
- Named accountable Health Information Custodian + quarterly attestation cadence
- Synthetic / demo data only; signed post-pilot data-deletion attestation
- Manual invoice / purchase-order settlement
Contact for pricing.
Pricing is disclosed under NDA to qualified applicants only — never on a public surface. The pilot is invoiced under a manual invoice / purchase-order arrangement and activates on a signed PO or paid invoice.
Custodians, privacy officers, security leads, and counsel.
- Health Information Custodian. You are personally accountable for what is done with personal health information. KYE™ computes whether each AI-assisted action has a lawful purpose and gives you the signed access register on demand.
- Privacy officer / DPO. You answer to the OPC and the Ontario IPC. KYE™ gives you breach-notification readiness and a replayable evidence trail in one format.
- Security lead / CISO. You need to know AI cannot disclose patient data outside the circle of care. KYE™ refuses the action at the boundary, not after.
- Counsel. You assess regulatory exposure for AI adoption. KYE™ makes provenance provable — KYE™ governs actions and authorities, not clinical outcomes, diagnoses, or results.