Effective date: October 9, 2025
Our clinic is committed to protecting the privacy of our patients and visitors. This privacy policy explains how we collect, use, disclose and retain personal health information (PHI) and other personal information under Ontario's Personal Health Information Protection Act, 2004 (PHIPA) and applicable federal and provincial laws. We also incorporate guidance from the Information and Privacy Commissioner of Ontario's Privacy Management Handbook for Small Health Care Organizations (May 8 2025), including governance and accountability, privacy procedures and controls, and ongoing monitoring. By seeking care or using our services, you agree to the practices described below.
This policy applies to all PHI and personal information that we collect about patients and visitors through our clinic, including our WellPoint practice management system and any online booking portals. Our clinic operates as a health information custodian (HIC) under PHIPA and is responsible for ensuring compliance. We maintain a privacy management program that addresses governance, policies, staff training, risk assessments and safeguards.
We have appointed a Privacy Officer, who is responsible for:
We make a public statement about our privacy practices and provide contact information for the Privacy Officer on our website.
We collect PHI and personal information necessary to provide healthcare services, manage our practice and meet legal obligations. This may include:
We collect PHI to:
Under PHIPA, consent for the collection, use and disclosure of PHI must be knowledgeable, relate to the information and not be obtained through deception or coercion. Consent can be express (spoken or written) or implied, except where express consent is required by law. We will explain the purposes for which we collect your information and answer any questions.
For most direct care activities, your consent is implied and we may share PHI with other healthcare professionals involved in your treatment (e.g., referring physicians, specialists, physiotherapists) unless you specifically instruct us not to. The circle of care does not include insurers or third-party providers; we will obtain express consent before sharing information with them, unless otherwise permitted by law.
We require express consent when using your PHI for purposes beyond direct care, such as submitting electronic claims through TELUS Health eClaims, communicating with insurers or sharing information with researchers. You may decline or withdraw consent for these purposes at any time.
You may withdraw or withhold consent at any time by providing us with notice. Withdrawal is not retroactive and may be subject to legal or contractual restrictions. Please note that refusing or withdrawing consent may affect our ability to provide certain services or process insurance claims.
We will determine whether patients have capacity to consent. If a patient is incapable, a substitute decision-maker (e.g., parent, guardian, attorney for personal care) may provide consent on the patient's behalf as outlined in PHIPA.
We will use or disclose PHI only for the purposes identified above or as permitted or required by law. Examples include:
We do not sell or rent personal information. We will not disclose PHI to third parties for marketing or unrelated purposes without your permission.
We may use service providers (e.g., cloud hosting providers, eClaims platforms, IT support) to process or store PHI. PHIPA does not require data to be stored in Ontario or Canada, but we remain accountable for protecting PHI and ensuring that service providers use appropriate safeguards. We use Canadian data centers where possible and require written agreements and confidentiality obligations from any service provider with access to PHI.
Our WellPoint practice management system is used to schedule appointments, chart patient encounters, process payments and submit eClaims. The system:
We restrict access to WellPoint to authorized staff and practitioners and ensure they sign confidentiality agreements. We monitor system activity and audit logs to detect unauthorized access.
We protect PHI through physical, technical and administrative safeguards:
We maintain a data inventory and assess privacy risks, including the use of artificial intelligence (AI). When using AI tools (e.g., transcription scribes), we evaluate risks and implement controls as recommended in the IPC handbook.
We retain patient records in accordance with legal and professional obligations. Generally, records are kept for at least 10 years after the date of the last entry for adult patients, or10 years after a child patient turns 18. Records may be kept longer if there are legal proceedings or other requirements (up to 15 years or more). After the retention period, we securely destroy records by cross-cut shredding paper and permanently wiping or destroying electronic media.
Under PHIPA, you have the right to request access to your health records and request corrections if you believe they are inaccurate or incomplete. To request access or correction:
We will correct records when you demonstrate that they are inaccurate and provide us with correct information.
If a breach of PHI occurs (e.g., theft, loss, unauthorized use or disclosure), our agents must notify the Privacy Officer immediately. The Privacy Officer will:
We also maintain an incident response plan and review breaches to prevent recurrence.
Our website and WellPoint portal may use cookies or similar technologies to improve user experience. Cookies collect non-identifying information such as IP address, browser type and pages visited. You can adjust your browser settings to refuse cookies; however, this may affect functionality.
As of August 2025, Ontario is proposing regulations under the More Convenient Care Act, 2025 to enable digital health identifiers and access to the provincial electronic health record. If these regulations come into force, we will adopt measures to ensure patients can access their records via digital means and that we comply with any additional requirements.
We are committed to providing information in accessible formats in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Healthcare providers must create, provide and receive information in accessible formats and communications and make websites accessible. Our public website and online booking portal are designed to meet WCAG 2.1 Level AA requirements (as required for organizations with 50 or more employees). We will accommodate alternative formats upon request.
If you have questions about this policy, wish to request access or correction, or wish to make a complaint about our privacy practices, please contact our Privacy Officer:
Rimple Garcha
OsteoMed Wellness Centre
Address: 83 Loyalist Trail Unit D7, Oakville ON
Phone: (365) 726-7777
Email: osteomedontario@gmail.com
We take all complaints seriously. If you are not satisfied with our response, you may contact the Information and Privacy Commissioner of Ontario:
Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400, Toronto ON M4W 1A8
Tel: 416-326-3333 / 1-800-387-0073
We may update this policy to reflect legislative or operational changes. The effective date at the top of the policy indicates when it last changed. We will post the revised policy on our website and, where appropriate, notify patients. Changes will apply to information collected after the new policy takes effect.
This policy is based on current laws and guidance available as of October 9, 2025. We will review and update our practices as privacy legislation evolves, including any amendments to PHIPA or related regulations.