Health tech penetration testing Canada
Health privacy in Canada is provincial, so the law that governs your product depends on where your customers are rather than where you are. That single fact decides your scope, your data handling during testing, and which of your customers can even sign the authorisation.
No Canadian health privacy statute requires a penetration test by name. They require safeguards proportionate to the sensitivity of the information, and health information is the most sensitive category the law recognises, so the proportionate answer is usually testing. The requirement you will be held to arrives through a hospital or regional health authority procurement document, and those are far more specific than the statutes.
$15,000 to $45,000 Annual testing, Canadian health tech, CAD
Provincial Health privacy law, not federal
Synthetic data The cheapest way to remove most of the problem
Which law governs you depends on your customers
| Where your customer is | Statute | What it changes |
|---|---|---|
| Ontario | PHIPA | You are an agent of the health information custodian. A written agreement must set out permitted use and safeguards, and breaches are notifiable to the individual and to the Information and Privacy Commissioner of Ontario |
| Alberta | Health Information Act | Custodian and affiliate structure, with mandatory breach notification |
| Quebec | Law 25, plus the health and social services information regime | An assessment before personal information is communicated outside Quebec, and a written agreement covering the transfer |
| Saskatchewan, Manitoba, New Brunswick, Nova Scotia, Newfoundland and Labrador | Provincial health information acts | Similar custodian and agent structures, with local notification thresholds |
| British Columbia | PIPA (BC), plus public-body rules for health authorities | No single health statute. The constraint usually arrives through the health authority contract |
| Private customers with no provincial health statute | PIPEDA | Safeguards proportionate to sensitivity, and federal breach reporting where there is a real risk of significant harm |
Under the agent relationship your customer remains accountable for information you hold. That is why their procurement team asks harder questions than a commercial buyer, and why they want evidence rather than assurance. Where information crosses a provincial or national boundary during testing, the rules are on data residency during a penetration test.
Test against synthetic data and most of this disappears
Nearly every complication above is triggered by real personal health information being present during the engagement. A staging environment seeded with synthetic records removes the transfer assessment, most of the residency question, and the awkward conversation about what the tester copied out. It costs you a data-seeding script. The trade is that findings apply to staging, so the environment has to match production in authentication, authorisation and configuration. Ask for it during scoping.
What matters most in a health product
- Access between care contexts. Whether a clinician at one clinic can reach a patient record at another, and whether a user with a narrowed role can widen it. This is the health-specific form of broken authorisation and it is the finding that ends a hospital deal.
- Audit logging that actually holds. Health regimes expect a record of who accessed what. A test should confirm the log cannot be evaded or altered, not just that it exists. The log is the control your customer relies on to meet its own obligation.
- Consent and lockbox handling. Where a patient has restricted access, testing should confirm the restriction is enforced on the server rather than in the interface.
- Integration surfaces. HL7, FHIR and flat-file interfaces are often older, less authenticated and outside the main application's authorisation model. They are frequently excluded from scope by accident. See API penetration testing.
- Bulk export and reporting. The feature that legitimately returns thousands of records is the one an attacker wants, and the least tested.
- Mobile clients, where the backend is the real target. See mobile penetration testing.
What it costs
| Engagement | Range |
|---|---|
| Web application, authenticated, multiple clinical roles | $14,000 to $32,000 |
| Integration and API surfaces | $9,000 to $22,000 |
| Cloud account review and testing | $9,000 to $22,000 |
| External network | $6,000 to $15,000 |
| Retest and closure evidence | Included, or $1,500 to $6,000 |
| Typical annual total | $15,000 to $45,000 |
The counter-case, which applies to a lot of health startups
If you hold no personal health information yet, a full testing program is premature. One authenticated application test of the authorisation model plus continuous external scanning is the honest purchase, perhaps $16,000 CAD rather than $45,000. Health tech founders over-buy testing earlier than almost any other vertical. Buy the engagement your first hospital procurement will ask about, and add the rest when the pilot converts.
What hospital procurement asks for
More than a commercial buyer, and in a fixed shape: a recent independent test by a named firm, an attestation letter rather than the report, evidence that high and critical findings were remediated and independently verified, your incident response plan, and often a data residency commitment. Several send a security questionnaire that asks the frequency question directly. Answer it honestly: the questionnaire becomes a contractual representation.
The document to send is on report against attestation letter. The closure evidence is on retest and remediation verification. If your customer is a public hospital or a regional health authority, the procurement rules on public sector penetration testing in Ontario apply on top of the health statute.
Scope it for the province you sell into
Tell us where your customers are and what their procurement asked for, and the same scope goes to Canadian firms.
Get matchedCommon questions
Does PHIPA require a penetration test?
No. PHIPA requires a health information custodian to take reasonable steps to protect personal health information against theft, loss and unauthorised use or disclosure. It never names a penetration test. Because health information is highly sensitive, testing is a common way to show the steps were reasonable, and the specific demand usually arrives through a hospital procurement document rather than the statute.
Are we an agent under PHIPA if we host our customer's patient data?
Generally yes, and it matters. The custodian remains accountable for what you do with the information, a written agreement must set out your permitted uses and safeguards, and their obligations flow to you through it. It is also why their security review is more demanding than a commercial buyer's, and why evidence beats assurance in every answer you give.
Can we test against real patient data?
You can, with the custodian's authorisation and tight rules on what the tester may copy out, but you usually should not. A staging environment with synthetic records removes the transfer assessment, most of the residency question and the risk of a tester holding real health information. The condition is that staging genuinely matches production in authentication, authorisation and configuration, otherwise the findings describe the wrong system.
What does health tech penetration testing cost in Canada?
Between $15,000 and $45,000 CAD a year for a typical company, with a single authenticated application test of a product with several clinical roles at $14,000 to $32,000 CAD. Integration surfaces such as HL7 and FHIR are usually a separate engagement and are the ones most often left out of scope by accident.
Does a test failing mean we have to report a breach?
No. A test conducted under signed authorisation is authorised access, not unauthorised use, so it is not itself a breach. It becomes a notification question only if real personal health information is actually exposed or exfiltrated during the engagement, which is exactly what the rules of engagement should prevent by limiting what the tester copies out.