
What data sovereignty and data residency mean for Canadian healthcare teams that fax and sign documents, how PHIPA fits in, and what to check before you choose a provider.
Fax is still how a large share of Canadian health information moves. Referrals, lab results, prescriptions, and records requests arrive by fax every day in clinics, pharmacies, and hospitals. Many of those documents also need a signature before they go back, so the same records often pass through an e-signature tool as well. When fax and signing move to the cloud, a question follows quickly from privacy officers and procurement teams: where does this data live, and who controls it?
That question is what people mean by data sovereignty. This guide explains the term in plain language, how it relates to data residency and PHIPA, and what to check before you pick a fax or e-signature provider for health information.
Data sovereignty is the idea that data is subject to the laws and control of the place where it is collected, stored, or processed. In practice, Canadian organizations use the term to ask two things about any service that holds their data:
Data residency answers the first question. It is the part you can name in a contract: a city, a data center region, a backup location. Data sovereignty takes in both questions, which is why it shows up in security questionnaires next to residency, encryption, and access controls.
For healthcare, the topic is not abstract. Health information is among the most sensitive data an organization holds, and in Ontario, PHIPA sets specific rules for how it is collected, used, disclosed, and protected, including when an outside provider handles it.
The two terms are often used as if they mean the same thing. They overlap, but they answer different questions, and a provider can be strong on one while saying little about the other.
Data residency is about location. It tells you the country, city, or data center region where your files are stored, and ideally where the backups are kept too. It is concrete and easy to verify: a good provider lets you choose the region, shows it in your account settings, and writes it into the contract.
Data sovereignty is about control. It covers residency, but it also asks who operates the service, which company signs your agreement, and what that company commits to in writing about how your data is handled.
For a Canadian healthcare team, that leads to a practical rule: start with residency, because it is the part you can confirm, then look at what surrounds it. Four details are easy to miss:
None of this replaces legal advice. It does give your privacy officer and IT team a shared vocabulary for comparing providers, and a short list of questions to put in writing.
Ontario's Personal Health Information Protection Act (PHIPA) sets the rules for personal health information in the province. It is built around the health information custodian: the hospital, clinic, pharmacy, lab, or practitioner that is responsible for the information. PHIPA requires custodians to take reasonable steps to protect personal health information in their custody or control against theft, loss, and unauthorized use or disclosure, and to protect records against unauthorized copying, modification, or disposal.
Custodians rarely do everything themselves. PHIPA also defines an agent: a person or organization that, with the custodian's authorization, acts for or on behalf of the custodian in respect of personal health information, for the custodian's purposes and not its own. PHIPA also sets rules for electronic service providers that supply the technology custodians use to handle health information. A cloud provider that handles faxes on a custodian's behalf works inside this framework, which is why the agreement you sign with the provider matters as much as the technology.
Fax adds a few specific risks, because documents arrive outside your EHR:
PHIPA does not require personal health information to be stored in Canada. It focuses on safeguards and accountability. Many organizations add their own requirements on top, such as keeping health records and backups in Canadian data centers, and write them into their policies and vendor contracts. If you need the full comparison with US rules, see PHIPA vs HIPAA. For questions about your own obligations, the Information and Privacy Commissioner of Ontario publishes guidance for custodians.
Use these eight questions in your vendor review. Ask for the answers in writing, and keep them with the contract.
A provider that answers all eight clearly, and puts the answers in its agreement, gives your privacy officer what they need to sign off.
Fax.Plus Enterprise answers each question on the checklist, and puts the answers in writing. It starts at $79.99 per month billed annually ($99.99 billed monthly), with 4,000 pages a month and unlimited members, and every price is published.
If your team handles health information in Ontario and needs it stored in Canada, talk to the Fax.Plus team about an Enterprise plan with Canadian data residency for Fax.Plus and Sign.Plus.
Data residency is where your data is physically stored, such as a data center region in Toronto or Montreal. Data sovereignty is the wider question of whose rules and control the data falls under, which also depends on who operates the service and what they commit to in your agreement.
No. PHIPA does not require personal health information to be stored in Canada. It requires health information custodians to take reasonable steps to protect it, including when an agent handles it on their behalf. Many Ontario organizations also require Canadian storage in their own policies and vendor contracts. For advice on your specific obligations, check the guidance from the Information and Privacy Commissioner of Ontario or your legal counsel.
Yes. On Enterprise, you can store your sent and received fax files in Toronto or Montreal, and choose the location of backups separately. Admins set the region from the account settings and can move stored faxes later if requirements change.
Fax.Plus supports PHIPA compliant faxing on the Enterprise plan, with Advanced Security Controls and a signed PHIPA Service Provider Agreement. See PHIPA compliant fax for details.
Yes. Admins can set a retention period of zero days so faxes are permanently deleted after transmission, or turn off fax storage and archive faxes in their own systems through the Fax.Plus API.
