Quebec clinic owners, medical directors, and privacy leads

Can Quebec clinics use ChatGPT under the health and social services information act (Bill 3)?

Sources verified Sanitized Ai Team

The short answer

Not with identifiable patient information unless the Act's conditions are met. Since July 1, 2024, the Act treats everything a covered clinic holds as confidential, and handing it to an outside provider generally requires a written agreement with prescribed clauses and, if the data leaves Quebec, a prior privacy impact assessment. A personal ChatGPT account meets neither condition, so clinics should provide approved tools and stop identifiable data at the prompt.

The situation

It is 6:40 p.m. at a family medicine clinic in Laval. A physician asks the coordinator to turn a consultation note into a referral letter. The coordinator opens a personal ChatGPT account in a second tab, pastes the note, and gets a clean letter back in seconds. The note contained the patient's name, health insurance number, diagnosis and medication list.

The clinic has an EMR with access controls, a person in charge of the protection of information, and a governance policy on its website. None of those see the browser tab next to the EMR. The owner's question: under Quebec's health information law, is this allowed, and what are we expected to do?

What the rules actually say

The Act respecting health and social services information (Loi sur les renseignements de santé et de services sociaux, CQLR c R-22.1) was adopted in 2023 as Bill 3 and, according to the Commission d'accès à l'information (CAI), has been in force since July 1, 2024. The Act does not mention generative AI; its general rules apply to any tool that handles health information.

Who is covered

Section 4 and the schedules cover the Ministère, Santé Québec and institutions, bodies such as the RAMQ and, through Schedule II, private professional practices, specialized medical centres, laboratories, private seniors' residences and palliative care hospices. A professional who practises within such a body but keeps their own records is treated as a body in their own right, and a regulation adds college and university health services. A private clinic is very likely inside the Act.

Confidential by default

Under section 2, health information is information that identifies a person, even indirectly, and relates to their health or the services they received. A name or health insurance number qualifies when it appears alongside such details. Section 5 makes all information a body holds confidential: it may be used or communicated only as the Act allows or with the patient's express consent, and in a form that does not identify the person directly whenever that is possible.

Handing information to an outside provider

Section 77 allows a body to communicate information to a contractor only when necessary, under a written agreement. When the provider is not itself a covered body, the agreement must, on pain of nullity, set out protection measures, limit use to the mandate, require confidentiality undertakings, oblige the provider to report violations, allow audits, and require secure destruction at the end. Under section 78, if the information will go outside Quebec, a privacy impact assessment showing adequate protection must come first. A personal chatbot account opened by clicking through consumer terms is unlikely to satisfy either section.

Safeguards, policy, training and incidents

  • Security (s. 99): the body is responsible for the information it holds and must take reasonable security measures given its sensitivity.
  • Governance policy (s. 105): roles, security measures, an incident procedure, and training.
  • Technology (ss. 106 and 107): a privacy impact assessment before acquiring a technological product that handles the information, and a published register of those products.
  • Training: the governance regulation requires training when people start and an annual refresher that covers, among other things, safe use of the body's technological products.
  • Incidents (ss. 108 to 110): a "confidentiality incident" includes any communication the law does not authorize. The body must act to reduce risk, notify the Minister, the CAI and affected people promptly if there is a risk of serious injury, and keep an incident register.

Section 160 makes an unauthorized communication an offence, with fines of $5,000 to $100,000 for individuals and $15,000 to $150,000 in other cases. Under section 165, an organization answers for an employee's offence unless it shows due diligence. That is the practical frame for AI: can you show the precautions you took? For the wider privacy picture, see Quebec Law 25 and generative AI.

Why policies and bans fall short

A governance policy is mandatory, and it should address AI. But a policy on the website does not reach the coordinator at 6:40 p.m. with three letters left to write.

Blocking chatgpt.com has its own gaps. Staff switch to another assistant, a phone, or a home laptop, and the clinic loses what the incident provisions assume it has: knowledge that something happened. LayerX reported in 2025 that 71% of generative AI connections use personal, non-corporate accounts, traffic a clinic's approved tools never see. As we explain in why banning ChatGPT does not work, prohibition moves the activity out of sight rather than ending it.

What a practical control looks like

These steps map to obligations the clinic already carries. Confirm details with your professional order or counsel.

  1. Find out what is in use. Ask staff which AI tools they use and for what (letters, summaries, translations). Add approved tools to the section 107 register.
  2. Sanction tools deliberately. For each approved AI tool, complete the section 106 privacy impact assessment and put a section 77 agreement in place, with a section 78 assessment if data leaves Quebec. An approved AI scribe covers one workflow; our guide on AI scribes and the ChatGPT gap covers the rest.
  3. Write AI into the governance policy. State which tools are approved, which information may go into them, and that identifiable details must be removed where possible, as section 5 expects.
  4. Add AI to the annual refresher, with real examples of health information in a prompt, including indirect identifiers.
  5. Define the incident path. Treat identifiable information pasted into an unapproved tool as a potential confidentiality incident: assess it with the person in charge, record it, and escalate if there is a risk of serious injury.
  6. Keep evidence of training, approvals and caught events, so the clinic can show due diligence.

Sanitized Ai is a browser extension for Chrome, Edge and Firefox that supports steps 3 to 6. It detects health information, personal information and identifiers in prompts and file uploads to the major AI assistants, and redacts or blocks them before submission. The person sees a plain-language explanation of what was flagged and why, so the policy is taught at the moment it matters.

Once information is submitted to a public AI tool it cannot be recalled and becomes subject to the provider's terms. Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never shows prompt content: an audit-ready record that can support a showing of reasonable safeguards, though no tool guarantees a regulatory outcome. See our healthtech page.

Frequently asked questions

Does the Act apply to a private medical clinic, or only to the public network?

It reaches beyond the public network. Schedule II lists private professional practices (cabinets privés de professionnel), defined in the health governance statute as businesses where physicians, dentists or other professionals practise privately on their own account. Confirm your status with your professional order or counsel.

Is it acceptable if staff remove the patient's name before pasting a note into an AI tool?

It helps, but it may not be enough. The Act covers information that identifies a person even indirectly, so a date of birth, a rare diagnosis or a detailed history can keep a note within the Act. Removing direct identifiers where possible is a baseline expectation under section 5, not a complete answer.

A staff member already pasted a patient note into ChatGPT. Is that a confidentiality incident?

It may be. The Act defines a confidentiality incident to include any communication the law does not authorize. The clinic must take reasonable measures to reduce the risk, assess it with its person in charge of the protection of information, record it in its incident register, and notify the Minister, the Commission d'accès à l'information and affected patients if there is a risk of serious injury. Get advice from counsel on the facts.

Does Quebec's Law 25 also apply to our clinic?

Usually for different information. The Commission d'accès à l'information points health and social services organizations to this Act for health information and to the public or private sector privacy law, as amended by Law 25, for their other obligations. Employee information kept for human resources purposes is excluded from the Act's definition of health information.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading