Ask a Canadian dental practice about marketing compliance and you will get an answer about wording. Testimonials, superlatives, what the website may claim. Almost nobody talks about the layer underneath, where patient data moves out of the practice management system and into a CRM, an email platform, an analytics tool and, quite often, an advertising platform in another country.
That layer is governed by privacy law rather than by your college, it is assessed almost nowhere, and it is where a practice is most likely to be doing something it has never consciously decided to do.
It is a separate body of law from Canadian dental advertising compliance, and satisfying your college says nothing about whether you have satisfied this.
Which law governs patient information in a dental practice?
In Ontario, personal health information held by a health information custodian is governed by the Personal Health Information Protection Act, 2004, usually called PHIPA. Health care practitioners and those operating a group practice fall within the custodian definition.
Other provinces have their own regimes, and federally PIPEDA applies to commercial activity where a provincial law has not been declared substantially similar. The practical point for a practice owner is simpler than the jurisdictional map: patient information is treated as sensitive, and using it for something other than care requires you to have thought about consent.
Is a patient list personal health information?
A list of people who are patients of a dental practice reveals, by its existence, that each person on it received dental care from you. That is the character of the information, regardless of whether a clinical detail is attached.
This is why the instinct that “it is only names and email addresses” does not hold. The sensitivity is not only in the fields. It is in what membership of the list discloses.
What consent is needed to market to patients?
Under PHIPA, implied consent generally covers using information to provide health care. Marketing is not the provision of health care.
Published guidance for regulated health professionals states that “express consent from the client must be obtained for all marketing and market research activities”, and that “express consent is required for certain fundraising and marketing activities”. That is a materially higher bar than most practices operate on.
CASL governs whether you may send the message. Privacy law governs whether you may use the information to send it. Satisfying one does not satisfy the other, and a campaign can be clean under CASL and still be a problem under PHIPA. The anti-spam side is covered separately.
Can a dental practice upload a patient list to Facebook or Google?
This is the question practices most want answered and it is the one where honesty is more useful than confidence. We could not find published Canadian regulator guidance addressing patient list uploads by a health care provider to an advertising platform, so this article does not tell you the answer. What it can do is set out the questions that determine it, which are the questions to put to your privacy advisor or your regulator.
- Is the upload a use, or a disclosure? Sending information outside the custodian’s control to a third party looks more like disclosure than internal use, and disclosure attracts a different analysis.
- Does hashing change the analysis? Platforms describe matched audiences as privacy-preserving because identifiers are hashed. Hashing is not anonymisation when the purpose of the process is to match a specific individual.
- Is the purpose marketing? If yes, the express consent standard above is engaged before you reach any platform question.
- Did the patient know? Consent under PHIPA has to be knowledgeable. It is difficult to argue a patient knowingly consented to something no document mentions.
Our position, and we would rather say it plainly: we do not upload patient lists to advertising platforms for dental clients. Not because we have a ruling that says it is prohibited, but because the analysis above has no comfortable answer, the information is sensitive, and the upside does not justify the exposure to the licensee.
Are tracking pixels allowed on a dental booking page?
Again, no Canadian regulator guidance specific to healthcare booking pages was located, so treat what follows as risk analysis rather than a rule.
The concern is straightforward. A pixel on a page whose URL or content identifies a treatment can transmit, alongside a device identifier, the fact that a particular person viewed a page about a particular procedure. On a general information page that is unremarkable. On a booking confirmation, or a page named after a specific treatment, the transmission starts to carry a health inference.
Reasonable precautions that cost nothing:
- Keep treatment names out of URLs used in booking and confirmation flows.
- Do not pass form field contents into analytics or conversion events.
- Fire conversion events on a generic thank-you page rather than one identifying the procedure.
- Know exactly which third-party scripts run on your site. Most practices cannot list them.
What about storing patient data outside Canada?
Most marketing tooling a dental practice uses stores data in the United States. The requirement to be aware of, in general terms, is accountability: information transferred to a third party for processing remains your responsibility, and patients are entitled to know how their information is handled. Specific cross-border requirements vary by province and we did not verify them for this article, so confirm your own province’s position rather than relying on a general statement.
Most of the exposure sits in tooling rather than in policy, so the fix belongs in how your CRM and conversion stack is put together in the first place.
What should a practice actually do about this?
- Inventory the stack. Every tool that touches patient information: practice management system, CRM, email platform, call tracking, chat widget, analytics, ad platforms. Most practices have never written this list down, and writing it down is most of the work.
- Separate care communications from marketing communications at the system level, not just by intent.
- Get express consent for marketing, recorded, at the point of collection, in language a patient would understand.
- Update the privacy notice to describe what actually happens, including third parties and cross-border storage.
- Ask before you upload. Any transfer of patient information to a platform is worth a specific conversation with a privacy advisor, in advance.
This article names the questions and does not invent the answers. Where Canadian regulator guidance exists it is quoted; where it does not, that is said. The advertising rules that sit alongside this are set out in Canadian dental advertising compliance, and the broader habit of importing American practice into a Canadian regulatory environment creates exposure well beyond the data layer.
If you take one thing from this, make it the inventory. Most practice owners can name their practice management system and very few can name every tool that touches a patient record. You cannot make a judgement about exposure you have not listed, and the listing is an afternoon. Everything else, including whether you need help with any of it, follows from that one page.
This article describes advertising and privacy rules as they applied on the review date shown. Regulations change and vary by province. This is general information, not legal advice. Confirm anything you intend to rely on with your own regulatory college.