Fast answer
PIPA (BC's Personal Information Protection Act) doesn't ban AI — it requires that personal information be processed with consent, for stated purposes, with reasonable safeguards, and with accountability for where it goes. Consumer AI tools fail those tests; AI running inside the clinic's own governed Microsoft 365/Azure tenant, with access controls and audit logging, can pass them. Automate admin first (scheduling, documents, referral handling), clinical content only with explicit design and professional advice.
The line staff are already crossing
The riskiest AI in most clinics isn't a system anyone bought — it's a browser tab. Summarizing a referral letter in a free chatbot sends patient information to a third party with no agreement, no Canadian residency guarantee, and no audit trail. Under PIPA, the clinic remains accountable for that disclosure regardless of which staff member did it.
The first step is a sanctioned alternative, not a memo. Prohibition without provision fails every time; staff use these tools because the workload is real. Give them an approved, governed way to do the same task and the shadow usage stops.
What PIPA actually requires of AI processing
- Purpose and consent: personal information can be used for the purposes it was collected for — using clinical data to run the clinic's own operations generally fits; feeding it to external tools for other purposes doesn't.
- Safeguards: reasonable security for the sensitivity of the data — for health information, that means encryption, access controls, and knowing exactly which systems touch it.
- Accountability: the clinic must be able to answer 'where did this data go and who accessed it' — which rules out any tool without logging and a data processing agreement.
- Residency awareness: health-sector expectations in BC favour Canadian data residency — a design constraint we build in from the start.
None of these are exotic requirements. They're the same discipline as clinic backups and network segmentation — which is why AI governance fits naturally inside managed clinic IT rather than a separate vendor's silo.
What clinics can automate today, compliantly
- Intake and forms: patient intake documents processed and staged into the EMR for staff verification — no more retyping, human confirms before commit.
- Referral handling: inbound referrals classified, key fields extracted, and routed — with the original always attached and a human approving.
- Admin communications: recall letters, appointment follow-ups, and routine correspondence drafted for review, never auto-sent.
- Operational reporting: no-show patterns, scheduling utilization, and billing summaries assembled automatically from your own systems' data.
Notice the pattern: every workflow keeps a human between the AI and the patient record's final state. That's both the PIPA-safe design and, frankly, the good-medicine design.
Where to be cautious
Clinical decision support, diagnostic suggestions, and AI scribes that draft chart notes sit in a different risk category — involving College of Physicians and Surgeons of BC guidance, professional judgment questions, and often explicit patient consent conversations. Some clinics adopt these successfully; none should adopt them casually. Start with the admin automations, build the governance muscle, and approach clinical AI as a deliberate second phase with proper advice.
If your clinic wants the practical starting map, our fixed-fee AI readiness assessment for clinics includes the PIPA design review — and pairs naturally with the clinic IT services we already deliver.