Law 25
What it changes in practice
The central rule is simple: health information is not freely given to an AI. Every access needs a reason, authorization and a record.
Necessity
Only the information necessary for a specific task should be read.
Consent
AI access to a record requires clear, valid and revocable consent.
Transparency
The patient can see whether AI is authorized and review recent access to their record.
Security
Access is restricted, pseudonymized, logged and automatically blocked when a condition is missing.
Assessment before change
A privacy impact assessment is required before a new AI system or processing outside Québec.
Accountability
RECODEX remains accountable for information entrusted to a supplier and must govern that supplier in writing.
This general explanation does not replace legal advice or the official policy approved by the privacy officer.