Health Information Protection

Law 5: Understanding Your Obligations... and Those of Your Partners

Since July 1, 2024, the Act respecting health and social services information establishes a rigorous governance framework for health information management in Quebec.

Law 5 Compliance Guide

Download our comprehensive guide to understand and apply Law 5 within your organization.

What You Need to Know

This new legislation establishes a rigorous governance framework for the management of health information in Quebec. Inspired by Law 25, it adopts many of the same principles—this time applying them specifically to the health and social services sector.

Whether you are a public institution, a non-profit organization, a subcontractor, or a partner, you are likely affected.

Law 5 introduces specific rules governing the collection, use, retention, and sharing of health information.

It clarifies responsibilities for all parties, including partners and service providers.

It strengthens individual protections while enabling better access to information for authorized professionals.

In short: compliance no longer stops at your organization—it extends across your entire ecosystem.

Are You Affected?

The law applies to "health and social services sector bodies," including:

Public Institutions

CIUSSS, CISSS, hospitals, CLSCs, CHSLDs, and other public healthcare facilities

Private Practices

Healthcare professionals in private practice and their teams

Specialized Centers

Laboratories, specialized medical centers, fertility clinics

Emergency & Support Services

Ambulance services, private seniors' residences, palliative care homes, funeral service providers

Non-Medical Employers

Even if your organization is not a health sector body, you may be indirectly affected:

Assistance Programs

Internal Employee Assistance Programs (EAPs)

Risk: Collection and processing of sensitive data

On-Site Services

On-site medical clinics or nursing services

Risk: Shared responsibility for health data

Partnerships

Partnerships with providers subject to Law 5

Risk: Contractual compliance obligations

Key Obligations to Remember

Governance

Appoint a Health Information Protection Officer (HIPO / RPRS) with a formal written mandate.

Data Inventory

Map all health information held: type, purpose, location, and access method.

Policies

Draft and publish rules governing collection, access, retention, transmission, and destruction.

Access Logs

Maintain automated logs of all access to and transmission of health data.

Consent

Obtain consent that is clearly free, informed, and specific—and retain proof.

PIA (EFVP)

Conduct Privacy Impact Assessments before any high-risk technological project.

Incidents

Notify the CAI and affected individuals within 72 hours when an incident presents a serious risk of harm.

Training

Provide annual staff awareness training, with proof of participation.

Vendor Contracts

Include mandatory clauses covering security, subcontracting, and audit rights.

Sanctions

In addition to the fines and penalties imposed under Law 25, additional fines of up to $150,000 per incident may apply in cases of non-compliance with Law 5.

What Does This Mean for Your Organization?

Health Sector Organizations

Compliance with Law 5 is now just as critical as compliance with Law 25.

SMEs and Non-Profits

Review your contractual relationships—you may be required to certify Law 5 compliance when receiving health data from medical partners.

HR or OHS Service Providers

Your contracts and security measures must align with Law 5 requirements if you serve clinics or healthcare organizations.

Need Help?

Exact RH already supports many organizations—clinics, non-profits, and SMEs—in the practical application of Law 5:

  • Compliance diagnostics
  • Policy drafting and consent templates
  • Targeted training for staff and managers
  • PIA (EFVP) support and security testing
  • Support in assessing incident risk levels
  • Assistance with communications with the CAI

Frequently Asked Questions (FAQ)

What is Law 5 in Quebec?

Law 5 (Act respecting health and social services information) establishes a rigorous governance framework for health information management in Quebec. In force since July 1, 2024, it adopts principles similar to Law 25 but applies them specifically to the health and social services sector.

Who is subject to Law 5?

Law 5 applies to health and social services sector bodies including public institutions (CIUSSS, CISSS, hospitals), private healthcare practices, specialized medical centers, laboratories, ambulance services, private seniors' residences, and funeral service providers.

What are the main changes introduced by Law 5?

Key obligations include appointing a Health Information Protection Officer (RPRS), maintaining a data inventory, implementing written policies, keeping access logs, obtaining clear consent, conducting Privacy Impact Assessments (PIAs), notifying incidents within 72 hours, and including mandatory clauses in vendor contracts.

What penalties are provided under Law 5?

In addition to Law 25 fines and penalties, Law 5 provides for additional fines of up to $150,000 per incident in cases of non-compliance with health information protection requirements.

Are non-medical organizations (SMEs and non-profits) affected?

Yes, non-medical organizations may be indirectly affected if they have Employee Assistance Programs (EAPs), on-site medical clinics, or partnerships with healthcare providers subject to Law 5. They may need to certify Law 5 compliance when receiving health data.

Do I need specific consent for health data?

Yes, Law 5 requires consent that is clearly free, informed, and specific. Organizations must retain proof of consent for health information collection, use, and sharing.

What is an access log?

An access log is an automated record of all access to and transmission of health data. Law 5 requires organizations to maintain these logs to track who accessed what information and when.

How should a health data privacy incident be managed?

When an incident presents a serious risk of harm, organizations must notify the CAI and affected individuals within 72 hours. This includes data breaches, unauthorized access, and loss of health information.

What is the relationship between Law 25 and Law 5?

Law 5 is inspired by Law 25 and adopts many of the same principles, but applies them specifically to the health and social services sector. Compliance with Law 5 is just as critical as compliance with Law 25 for healthcare organizations.

How can Exact RH support my organization?

Exact RH provides compliance diagnostics, policy drafting and consent templates, targeted training for staff and managers, PIA support and security testing, incident risk level assessment, and assistance with CAI communications.

Let's Talk About Your Law 5 Compliance

Contact us for a free assessment. We'll help you turn Law 5 compliance into a trust-building advantage for your organization—and for your patients, employees, and partners.

Free Consultation: 1-866-950-3357