Compliance

Built around the actual Canadian and BC rules your program operates under.

We don't bolt on generic "HIPAA-style" compliance language borrowed from the US. Here's the real framework we design against — and how we can help you meet it.

Privacy law

Provincial and federal privacy obligations

Provincial · Private sector

PIPA — Personal Information Protection Act (BC)

Governs how private-sector organizations, including most nonprofits, collect, use, store, and disclose personal information in BC — including client health information. This is the primary privacy framework most Lantern Point clients operate under.

Provincial · Public bodies

FOIPPA — Freedom of Information and Protection of Privacy Act (BC)

Applies where an organization operates as, or contracts with, a public body — relevant for programs with certain Health Authority data-sharing arrangements. We help identify whether FOIPPA obligations apply alongside PIPA for your specific contracts.

Federal · Fallback

PIPEDA

Canada's federal private-sector privacy law, relevant where provincial legislation doesn't occupy the field — for example, for organizations operating in more than one province or handling certain federally regulated data.

Regulator

Office of the Information and Privacy Commissioner for BC (OIPC)

BC's independent privacy regulator. Breach-notification expectations and privacy guidance for organizations under PIPA and FOIPPA originate here.

Licensing & care standards

Facility licensing and accreditation

Licensing

Community Care and Assisted Living Act (CCALA)

BC's licensing and registration regime for community care facilities and assisted-living residences, overseen in part by the Assisted Living Registrar. Many recovery homes and group homes operate under CCALA, which includes recordkeeping and incident-reporting expectations that directly shape how client information systems need to be designed.

Legislation

Mental Health Act (BC)

Relevant where involuntary care or designated-facility status applies — an important consideration for how certain client records and incident documentation are handled.

Voluntary accreditation

CARF & Accreditation Canada

Many treatment operators pursue voluntary accreditation through CARF or Accreditation Canada, both of which include IT and records-management criteria. We help make sure your systems and documentation are ready to satisfy accreditation review.

Our commitment

How we hold ourselves to the same standard

As a partner with access to client-adjacent systems, Lantern Point maintains its own internal privacy and security policy, a written data processing agreement for every client relationship, staff confidentiality agreements, and cyber-liability insurance appropriate to handling sensitive health-adjacent data.

  • Written data processing agreement with every client
  • Staff confidentiality agreements
  • Cyber-liability and professional liability insurance
  • Internal privacy and security policy, reviewed annually
  • Clear, contractual scope of responsibility for any client-side incident

Not sure what applies to your program?

A free Risk Check-In includes a plain-language read on which of these frameworks apply to your specific contracts and licensing status.

This page is a general orientation to the compliance landscape relevant to BC nonprofit recovery and mental health operators and is not legal advice. Always confirm specific obligations with qualified legal counsel and your funders/licensing body.