Trust · Canada

PIPEDA: programme in progress.

PIPEDA applies to private-sector organisations in most of Canada, and several provinces have their own health privacy laws for health information custodians (Ontario’s PHIPA and Alberta’s HIA, for example). Our server is in the United States. The product already has the safeguards listed below. The contracts, the Canadian hosting and the breach workflow are still open.

Status as of 24 September 2026MedAppz Canada
An illustration of a clinic team reviewing a shared, secured workspace

Where we stand, as of 24 September 2026

This covers PIPEDA and provincial health privacy laws. MedAppz does not claim compliance with it or any certification under it. This is a programme in progress, and this table is where it stands. Records are stored on one server: Boston, United States · Hostinger VPS. Canadian patient data would leave Canada.

ItemStatusNote
Service agreement with contractual privacy protectionsIn progressOur processing addendum is written for India. A Canadian version is not yet published.
Canadian hosting regionNot startedThere is one server, in the US. No Canadian region is set up.
Sub-processor agreementsNot startedWe hold no signed agreement with any sub-processor yet: not the host, not the AI or speech vendors, not the SMS, email or WhatsApp providers.
Breach reporting to the OPC, and breach recordsNot startedThe breach register tracks Indian deadlines only. The OPC report and the 24-month breach record are not built.
Provincial health privacy law reviewNot startedWe have not assessed any province’s health privacy law.
Audit trail, emergency access, access reviews, backupsIn placeListed below, each with the module that does it.

In place in the product today

Each of these runs in the product now. The line under each one names the part of the law it relates to. That is a pointer for your own review, not a claim that the clause is met.

An audit trail that cannot be editedRecord opens, searches and exports are written once: who, when, from where, under which permission. The log is append-only by database trigger and hash-chained day by day; the chain is re-verified nightly.Audit schema and AuditLens · Safeguards — Principle 4.7
One clinic cannot read another’s rowsRow-level security on every tenant table, bound to the transaction. The account the application runs as cannot switch it off.Database row-level security · Safeguards — Principle 4.7
Emergency access that expires and is reviewedBreak-glass access needs a written reason, lasts at most four hours (a database constraint), and lands on a review queue.BreakGlass · Safeguards — Principle 4.7
Consent records, by notice versionMessages are gated on the consent notice the patient accepted, by version, at the moment of sending. Withdrawal cancels what is queued.ConsentVault and the consent service · Consent — Principle 4.3
Access reviews with two-person revocationThe Security Centre runs dated access-review campaigns over privileged grants (full patient data, money, platform, emergency access). A challenge raises a two-person approval; a campaign cannot close with unread items.Security Centre · Accountability — Principle 4.1
Strong sign-in and short sessionsArgon2id password hashing, lockout after five failures, optional or organisation-required app-based two-factor, 15-minute access tokens with rotating refresh tokens, and a five-minute idle-out on shared devices.Identity
Encryption in transit, and sealed credentialsTLS on every connection, with certificates renewed automatically. Keys and passwords a clinic gives us are sealed with AES-256-GCM, bound to the organisation, and never shown back.TLS and the secrets envelope
Nightly verified backups, with a rehearsed restoreThe database and files are dumped every night and each dump is checked before the run counts as a success. A full restore was rehearsed on 3 September 2026.ops/backup.sh
Exports are whitelisted and recordedOnly listed views can be exported, each needs its permission, and each export is recorded with its row count and data classes.Exports · Limiting use and disclosure — Principle 4.5
AI you can switch off, or send redactedOne setting per organisation: off, redacted (the default) or full. Redacted strips the name, date of birth, hospital number, phone and email before the request leaves our server. A named person accepts every draft.AI governance

What you would need to do

  • Check which law applies to you. A custodian under a provincial health privacy law may have rules on storing records outside the province or outside Canada.
  • Tell patients that their information may be processed in the United States, if you go ahead.
  • Name a privacy officer and keep your own breach records.
  • Do not move real patient records in until the service agreement is signed.
This page describes our product. It is not legal advice; take your own advice on how the law applies to your practice.

Sub-processors and where they are

Every outside service the product can send data to, where it processes it, and whether an agreement is signed. The list is generated from the register the product itself reads, the same one the Trust Centre shows.

ServiceLocationAgreement
HostingerThe rented server the database, the application and the uploaded files run onOne rented regionNone signed yet
S3-compatible object storageWhere uploaded files and documents live when object storage is switched onThe bucket region the deployment configuredNone signed yet
AnthropicAI drafting and answeringUnited StatesNone signed yet
OpenAIAI drafting and answeringUnited StatesNone signed yet
Google (Gemini)AI drafting and answeringUnited StatesNone signed yet
NVIDIA NIMAI drafting and answeringUnited StatesNone signed yet
The configured speech-to-text serviceTurning a consultation recording into a transcriptWherever SPEECH_API_BASE_URL points — api.openai.com (United States) unless changedNone signed yet
The clinic’s own Jitsi serverCarrying the live audio and video of a video visitWherever the clinic hosts itNone signed yet
ResendSending emailUnited States / European UnionNone signed yet
MSG91Sending SMSIndiaNone signed yet
Meta (WhatsApp Business)Sending WhatsApp messages through the official APIMeta’s global networkNone signed yet
The clinic’s paired WhatsApp numberSending WhatsApp messages from the clinic’s own handset sessionMeta’s global network, through the clinic’s own numberNone signed yet
Google (Firebase Cloud Messaging)Delivering push notifications to a phoneGoogle’s global networkNone signed yet
RazorpayTaking a payment online, and holding a standing UPI Autopay or e-mandate authorisationIndiaNone signed yet
PhonePeTaking a payment onlineIndiaNone signed yet
StripeTaking a payment onlineUnited StatesNone signed yet
Pine LabsTaking a card payment on the counter terminalIndiaNone signed yet
Google SheetsReceiving a scheduled exportGoogle’s global networkNone signed yet
Google Business Profile and MetaReading reviews and publishing the clinic’s repliesGoogle and Meta’s global networksNone signed yet
The clinic’s own mail serverThe mailbox MedAppz proxies rather than copiesWherever the clinic’s mail is hostedNone signed yet
The hospital’s own GST Suvidha ProviderRegistering the hospital’s own patient invoices with the Invoice Registration PortalIndiaNone signed yet
The clinic’s own Tally serverReceiving the accounting export, and answering which vouchers it tookWherever the clinic runs TallyNone signed yet
A database the clinic bringsA destination the clinic asked the product to write toWherever the clinic hosts itNone signed yet

Send us your PIPEDA questions

Your security questionnaire is longer than this page. Leave a number and we will answer it line by line, including where the answer is “not yet”.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.