Compliance & Security

    Handled with the discretion medicine deserves.

    One platform, both regulatory regimes — Canada and the United States.

    United States

    HIPAA, HITECH, and the state-level layer.

    United States · 45 CFR 160 & 164
    HIPAA

    Safeguards for Protected Health Information. BAAs available.

    Breach notification
    HITECH

    Notification within 60 days. Encryption at rest and in transit.

    Patient SMS consent
    TCPA

    Documented opt-in for SMS confirmations and callback flows.

    CMIA · NY SHIELD · TX HB300 · MA 201 CMR 17
    State Laws

    State privacy standards layered on top of federal HIPAA.

    Canada

    PIPEDA nationally. Provincial statutes where they govern.

    Federal · Canada
    PIPEDA

    Private-sector handling of personal information, including cross-border transfers.

    Ontario
    PHIPA

    The governing statute for Ontario custodians of personal health information.

    British Columbia · Alberta
    PIPA

    Applies to private clinics in BC and AB, with cross-border disclosure duties.

    Alberta
    HIA

    Health Information Act, with mandatory Privacy Impact Assessments.

    MB · NS · NL · NB
    PHIA

    Provincial health information acts, each with its own notification thresholds.

    Quebec
    Law 25

    Strictest Canadian regime: Privacy Officer, algorithmic transparency, 72-hour reporting.

    A locked medical records cabinet drawer in soft daylight
    The Standard

    A patient record is held the same way at 3am as it is at 3pm.

    Encrypted, access-logged by person, retained only as long as your policy says.

    Security Controls

    Controls we don't negotiate on.

    01
    Encryption in transit
    TLS 1.3 across every leg — telephony, SMS, EMR handoff, dashboard.
    02
    Encryption at rest
    AES-256 for recordings, transcripts, and structured PHI.
    03
    Retention policy
    Recordings retained per your policy: 30 days, 90 days, or purged nightly. Transcripts optional.
    04
    Access control
    Role-based access with mandatory MFA. Break-glass access is logged and reviewed monthly.
    05
    Audit trail
    Every call, every escalation, every EMR write — immutable, time-stamped, exportable.
    06
    Sub-processors
    Named, disclosed, and BAA / DPA-covered. Full list available on request.
    07
    Breach protocol
    Notification within 24 hours of confirmation — well inside PIPEDA, PHIPA, HIPAA, and Law 25 statutory windows.
    Data Residency

    Your patients' data stays where you tell it to.

    Canadian clinics store in Canada, US clinics in the US. PHI never crosses a border without your written instruction.

    Canada
    Montréal · Toronto
    United States
    US-East · US-West
    Backups
    Same region only
    Model training
    Never on PHI
    Business Associate Agreements (US) and Data Processing Agreements (Canada) executed on request.