Law 25

What it changes in practice

The central rule is simple: health information is not freely given to an AI. Every access needs a reason, authorization and a record.

Necessity

Only the information necessary for a specific task should be read.

Consent

AI access to a record requires clear, valid and revocable consent.

Transparency

The patient can see whether AI is authorized and review recent access to their record.

Security

Access is restricted, pseudonymized, logged and automatically blocked when a condition is missing.

Assessment before change

A privacy impact assessment is required before a new AI system or processing outside Québec.

Accountability

RECODEX remains accountable for information entrusted to a supplier and must govern that supplier in writing.

This general explanation does not replace legal advice or the official policy approved by the privacy officer.