Roger Brulotte, CEO, Leaseweb Canada, on data sovereignty as a critical priority as Canadian healthcare providers rethinking how and where patient data is stored.

There was a time not so long ago when many healthcare organizations didn’t think too hard about where their data was physically stored. The goal was to have systems that were highly available, protected and secure. No easy task to be sure – not then and not now. However, as long as they had that, they were good.
Not anymore.
Geopolitical tensions, new data laws every few months and a steady drumbeat of privacy breaches continue to make headlines – clearly, we are living in a time of global instability. It’s no longer safe to assume that your data is protected just because it’s ‘in the cloud’.
This is especially true for Canadian healthcare providers. Today, you need to know exactly where it is, who has access to it and which laws it falls under.
That’s what data sovereignty is all about. And for Canadian healthcare, it has shifted from a ‘nice-to-have’ to a non-negotiable.
Why healthcare can’t afford to look the other way
Healthcare data contains people’s lives, their histories, diagnoses, treatments, even genetic markers and mental health records. This isn’t just sensitive. It’s sacred. The possibility of it falling into the wrong hands and the consequences that would follow ripple far beyond an embarrassing headline or a slap-on-the-wrist fine.
When healthcare systems get breached, the damage is personal and permanent. Patient records can be used for identity theft, insurance fraud or even blackmail. Medical histories can follow people for life, i.e. a child’s diagnosis, a fertility record, a mental health note.
Once leaked, it can’t be taken back – and the stakes go well beyond privacy.
Breaches or outages can put patient care at risk in real time. Imagine oncology patients missing a critical treatment window because ransomware froze scheduling systems, or paramedics unable to access allergy records in an emergency. These aren’t hypotheticals. We’ve already seen similar scenarios unfold in other countries.
Canada has some of the strongest privacy legislation in the world, from the Personal Information Protection and Electronic Documents Act (PIPEDA) – Canada’s federal privacy law – to provincial health privacy laws that govern how personal health information is collected, used and shared within each province’s healthcare system.
But here’s the reality check… those protections only apply if your data stays in Canada. Once it crosses borders, Canadian rules no longer shield it. Suddenly, your patients’ most personal information could be subject to foreign surveillance requests, political pressures or weaker international standards.
So basically, if your healthcare data isn’t anchored on Canadian soil, you’re rolling the dice with trust, reputation and patient safety.
We’re seeing a shift… and it’s a smart one
The good news? Healthcare leaders across Canada are waking up to this new reality. More organizations are actively taking control and bringing their data back home. Some are even moving it out of the cloud altogether, in a trend called cloud repatriation.
In 2024, IDC reported that nearly 80% of organizations they surveyed said they plan to repatriate some of their data and workloads in the next year. That’s not a small adjustment. It’s a massive shift in how organizations are thinking about Digital Transformation.
But this isn’t about abandoning cloud. It’s about being smarter with it. Many hospitals and health systems are adopting hybrid approaches. They are keeping sensitive patient records stored locally or in private clouds, while still leaning on public cloud services for less sensitive workloads. They get the best of both worlds this way – flexibility and scalability without giving up sovereignty or control.
What healthcare leaders should be asking
If you’re responsible for data strategy at a hospital, clinic or health authority, there are questions worth losing sleep over and worth asking your cloud or IaaS provider today:
- Is our patient data stored in Canada, and not just ‘accessible’ here?
- Who owns the infrastructure that houses it?
- Could foreign laws override Canadian privacy protections?
- What guarantees are in place if the provider faces legal issues or political pressure?
If the answers feel vague or evasive, clearly that’s a red flag.
These are the answers you are looking for:
- Yes. Your data is stored and processed entirely within Canadian borders, in facilities that meet or exceed healthcare compliance standards.
- Yes. The infrastructure is operated by a provider with a Canadian legal presence, so your data isn’t vulnerable to foreign government access.
- Yes. The provider adheres to recognized security and privacy standards, i.e. ISO 27001 and SOC 2, with transparency around who can access your data and what happens if something goes wrong.
- Yes. There’s a built-in commitment to resilience. This includes redundancy, failover protections and service continuity plans, ensuring Canadian healthcare data stays safe even in times of global turbulence.
In other words, don’t settle for ‘trust us’. Insist on transparency, specifics and, most of all, proof.
Why this isn’t just about rules and regulations
Yes, compliance matters. Healthcare organizations are rightly cautious about staying on the right side of PIPEDA and provincial health privacy laws.
But this goes deeper than rules. At its heart, this is all about trust.
Patients extend trust to their providers when they hand over their most personal information. They’re not just signing a consent form. They expect that information to be protected as carefully as the healthcare providers are protecting their health – really, their lives.
Losing control of that data, whether through foreign access, an outage or a legal dispute, isn’t just a technical failure. It’s a betrayal of that trust.
And make no mistake: patients are paying attention. Legal consequences are not the only result of a breach. Personal and organizational reputations face irreparable damage and the wider fallout can be painful as well. It can make people hesitate before sharing information with their doctors and that hesitation could have very real consequences for patient outcomes.
It’s tempting to think this is only a big-hospital problem, but smaller clinics and community health providers are just as vulnerable — sometimes more so. Many rely heavily on third-party providers, which can increase risk if not carefully vetted. For them, choosing the right partner isn’t just an IT decision. It’s a survival strategy.
Real-world lessons
We don’t have to look far to see how bad it can get when healthcare data sovereignty isn’t prioritised.
When one of Canada’s largest medical testing companies – LifeLabs – was hit by a massive data breach, it wasn’t just another story about hackers. This one was deeply personal and it shook millions of Canadians. The personal and health information of roughly 15 million people was exposed by the breach – most of them from Ontario and British Columbia. Names, addresses, health card numbers, login details, even lab results were now in the hands of cybercriminals.
In a desperate attempt to contain the damage, LifeLabs admitted it had paid a ransom to try to get the stolen data back. But the damage went far beyond dollars. What really made the situation more unsettling was where the data had been stored – on servers in the United States.
That meant Canadian patients’ most private medical information wasn’t just governed by Canadian privacy laws. It was also open to US jurisdiction and surveillance. For anyone who assumed their data was safely tucked away under Canadian protection, this was a harsh reality check.
The privacy commissioners of Ontario and B.C. later ruled that LifeLabs had failed to protect this highly sensitive information. Their decision was clear: patients had been let down.
And for Canada’s healthcare sector, the message was equally clear. Data sovereignty could no longer be treated as an afterthought. Where data lives and who has control over it is now a matter of trust, security and even national responsibility.
Bringing it home
We live in uncertain times. Geopolitical tensions, new regulations and relentless cyberthreats are now part of the daily reality. Healthcare providers can’t control those forces, but they can control how they prepare for them – starting with one simple question: where does your data live?
Across Canada, healthcare leaders are rethinking data sovereignty. It’s no longer a box to tick after the fact – it’s becoming a cornerstone of strategy. By choosing cloud and infrastructure partners that prioritise Canadian residency, transparency and compliance-first practices, providers are putting themselves in a stronger position to face whatever comes next.
And here’s the thing: this isn’t about choosing between innovation and protection. With thoughtful cloud and hybrid strategies, you can have both. Modern, scalable systems that improve patient experiences and the confidence that sensitive data is stored and managed locally, on Canadian soil.
Because when it comes to patient data, local doesn’t just mean safer. It means healthier.

