Skip to content
STRUCTURA HEALTH
FILE · GOVERNMENT & PUBLIC SECTOR

Government & Public Sector

The accountability layer for Ontario Health Teams and the public sector

Structura is built for Canadian health-privacy law, with Canadian data residency on our roadmap. The public-sector track maps a clinic network's obligations across PHIPA-HINP, Quebec Law 25, PIPEDA, ITSG-33 Protected B, and SOC 2 — with the evidence artefacts procurement asks for.

Data sovereignty

Canadian data residency — a roadmap commitment, stated up front

No statute mandates Canadian residency for every private-clinic record, but PHIPA's “reasonable safeguards” expectation, Law 25's transfer-assessment rules, and Alberta's HIA restriction on out-of-Canada storage all point the same way. For government and Protected B workloads, Canadian residency is mandatory, and it is not yet current infrastructure for Structura — we are transparent that this is a roadmap milestone for the public-sector track, not a capability available today. Role-based access and a full audit trail are already in place.

The Toronto skyline and CN Tower at dusk
Exhibit — the public sectorProcurement-grade evidence, Canadian jurisdiction
Framework Mapping

One platform, mapped to the frameworks procurement checks

How Structura's public-sector track relates to each obligation. Structura supports these frameworks — it does not certify or guarantee compliance with them; authorisation decisions remain with the buyer and the regulator.

FrameworkWhat it requiresHow Structura supports it
PHIPA — HINP (Ontario)As a Health Information Network Provider, complete a PIA/TVRA and provide it to client custodians, sign a written HINP agreement with each HIC, keep access logs available, and notify on any unauthorised access (no harm threshold).Designed around the HINP obligations — HINP agreement template and PIA/TVRA inputs included.
Quebec Law 25Mandatory Privacy Impact Assessments (including any transfer outside Quebec), prompt breach notice to the CAI and affected individuals (the statute says “with diligence” — 72 hours is the common operating target), and a maintained incident register. Penal ceilings up to CAD $25M or 4% of global revenue.Law 25 workflows, CAI-format PIA templates, breach-notice tracker, and incident register on the roadmap.
PIPEDA (federal)Governs cross-provincial and cross-border flows of personal information; PHIPA is deemed substantially similar for within-province PHI.Cross-border transfer assessments tracked as a compliance control.
ITSG-33 — Protected B / M / MFor federal systems handling Protected B information: FIDO2 MFA, mutual TLS, central logging, a formal Threat & Risk Assessment, and a Security Assessment & Authorization (SA&A) package for the department / CCCS.Public-sector track target. SA&A evidence pack and residency attestation in scope (residency itself is on our roadmap, not yet current infrastructure); full authorization is buyer-led.
SOC 2 Type IIThe assurance credential serious enterprise and public-sector buyers expect before onboarding a vendor that holds compliance data.On the roadmap — a milestone, not a current certification.

Sources: Ontario IPC PHIPA & HINP guidance; O.Reg 329/04; Commission d'accès à l'information du Québec (Law 25); Office of the Privacy Commissioner (PIPEDA); CCCS ITSG-33. SOC 2 Type II is a roadmap milestone, not a current certification.

The Public-Sector Track

The evidence artefacts a public-sector buyer asks for

Beyond the core platform, the public-sector track packages the documents and exports that move a procurement forward.

Canadian data sovereignty — on our roadmap

Canadian residency is mandatory for Protected B workloads, and it is not yet current Structura infrastructure. We state that up front because procurement will ask.

SA&A evidence pack

A structured Security Assessment & Authorization evidence package aligned to ITSG-33 Protected B / M / M, assembled to support a department's or CCCS authorisation process.

PIA-ready export

Export a Privacy Impact Assessment package in IPC (Ontario) and CAI (Quebec) formats, drawn from the controls and evidence already maintained in the platform.

HINP agreement template

A written Health Information Network Provider agreement template to sign with each client custodian, reflecting PHIPA's HINP obligations.

WCAG 2.1 AA VPAT

A Voluntary Product Accessibility Template in preparation for the public-sector track — the accessibility evidence federal and ACA procurement expects.

Per-OHT bulk pricing

Volume pricing for Ontario Health Teams and multi-site networks, with a single agreement able to onboard 20–80 clinics under shared governance.

The Ontario Health Teams wedge

One agreement can onboard an entire clinic network

Ontario Health Teams are integrated clinic networks operating under shared PHIPA governance. A single HINP agreement can onboard 20–80 clinics at once — so the public-sector track includes an OHT onboarding package: the HINP agreement template, bulk per-OHT pricing, a network admin view, and an IPC annual-statistics export for the whole team.

20–80

clinics onboarded under a single HINP agreement across an OHT.

Canadian

data residency on our roadmap — mandatory for Protected B workloads, and not yet current infrastructure.

1 export

IPC annual breach-statistics report assembled across the whole network.

Procurement

A named contact once scoped

Tell us the team, the jurisdiction, and the frameworks in scope, and we'll assign a contact for SA&A evidence, residency attestation, VPAT, and per-OHT pricing.

Contact the public-sector team

Public-sector registrations in progress: CanadaBuys / ProServices, Supply Ontario VOR, and the Ontario Health directory.