Meet us at eHealth Canada 2026See the full Tessera platform live, and ask about a scoped pilotBook a demo
For IT and privacy leaders

Canadian health data residency and PHIPA for clinical platforms

Where clinical data lives, and which privacy regimes apply, is a procurement question before it is a technical one. Here is how Tessera is built for Canadian residency and provincial privacy law.

Residency: the data stays in Canada

For Canadian health programmes, data residency is often the first gate a platform has to clear. Tessera is hosted in Azure Canada Central (Toronto) and Azure Canada East (Quebec City). Clinical data stays in Canada, with no cross-border transfers.

That matters because residency is not only a privacy preference; for many public-sector programmes it is a procurement requirement. Building on Canadian regions from the start means the question is answered before the conversation begins.

Provincial privacy law, not just federal

Canadian health privacy is layered. The federal regime, PIPEDA, sits alongside provincial health-information law: PHIPA in Ontario, PIPA in British Columbia, and HIA in Alberta. A platform that operates across provinces has to satisfy each of them, not just the federal baseline.

Tessera is built for that reality. The same platform can serve programmes in different provinces while meeting the applicable provincial regime, rather than assuming one province's rules cover the rest.

Audit and provenance

Privacy law expects you to know who accessed what, and when. Tessera maintains complete audit trails through FHIR Provenance, with seven-year retention. Every access and every change to clinical data is recorded and queryable, which is what a privacy officer needs to answer an access review or investigate an incident.

This is the same governed-lineage discipline that underpins the Tessera data contract: nothing is overwritten silently, and the chain of custody is intact.

Stewardship and de-identification

Clinical data rarely stays in one place. It feeds research registries, provincial data repositories, and partner systems. Tessera is built to support that downstream stewardship: records carry downstream identifiers and consent flags, so de-identification and separation are straightforward rather than a bespoke project each time.

The platform also supports full de-identification and synthetic data generation that mimics production data for testing, so teams can build and validate without exposing real patient information.

Questions to ask any clinical platform

Residency and privacy posture are easy to assert and harder to evidence. When you are assessing any clinical platform for Canadian use, a short set of questions surfaces the substance:

  • In which regions does clinical data physically reside, and are there any conditions under which it leaves Canada?
  • Which provincial privacy regimes does the platform support, and can it serve programmes in more than one province at once?
  • Is there a complete, queryable audit trail of who accessed what and when, and for how long is it retained?
  • Can data be de-identified and shared downstream with consent tracked, without a bespoke project each time?

The point is not that one answer is universally right; it is that residency and privacy should be demonstrable, not assumed.

Interoperability as part of the compliance posture

Standards are part of how Tessera stays aligned with where Canadian health data is going. The platform is FHIR R4 native and supports SMART on FHIR v2, and it is aligned with Canada Health Infoway's Pan-Canadian Interoperability Roadmap and CA Core+ (2027).

Being Canadian-built and Canadian-resident is not a slogan here; it is the architecture. Residency, provincial privacy law, audit, and interoperability are designed in, not retrofitted. Read the integration and compliance view written for IT and informatics leaders.

Keep reading

Meet us at eHealth Canada 2026

See the full platform, then start with a scoped pilot

Book a personalised demo. We'll show you the platform live and scope a low-risk pilot, one registry, one pathway, or one surveillance stream, to prove the model in your environment.

Low-risk entry point. We'll work with your EMR/EHR, your data residency, and your team.