Privacy Policy for Our Health Clinic

Effective date: October 9, 2025

Our clinic is committed to protecting the privacy of our patients and visitors. This privacy policy explains how we collect, use, disclose and retain personal health information (PHI) and other personal information under Ontario's Personal Health Information Protection Act, 2004 (PHIPA) and applicable federal and provincial laws. We also incorporate guidance from the Information and Privacy Commissioner of Ontario's Privacy Management Handbook for Small Health Care Organizations (May 8 2025), including governance and accountability, privacy procedures and controls, and ongoing monitoring. By seeking care or using our services, you agree to the practices described below.

1. Scope and compliance

This policy applies to all PHI and personal information that we collect about patients and visitors through our clinic, including our WellPoint practice management system and any online booking portals. Our clinic operates as a health information custodian (HIC) under PHIPA and is responsible for ensuring compliance. We maintain a privacy management program that addresses governance, policies, staff training, risk assessments and safeguards.

2. Accountability and privacy officer

We have appointed a Privacy Officer, who is responsible for:

  • Ensuring compliance with PHIPA and this policy.
  • Developing and maintaining privacy and security policies.
  • Providing education and training to staff on privacy obligations and confidentiality agreements.
  • Acting as the contact person for questions or complaints about our practices.
  • Responding to privacy breaches and notifying affected individuals and authorities as required.

We make a public statement about our privacy practices and provide contact information for the Privacy Officer on our website.

3. What information we collect and why

We collect PHI and personal information necessary to provide healthcare services, manage our practice and meet legal obligations. This may include:

  • Demographic information (name, address, date of birth) and contact details.
  • Health information related to your care, such as medical history, symptoms, diagnoses, test results and treatment plans.
  • Billing and insurance information required for claims submissions (e.g., insurer name, policy number, banking details for eClaims); we collect only what is necessary to process payments.
  • Electronic communications data when you use our website or WellPoint portal (e.g., IP address, device information, appointment requests).

We collect PHI to:

  • Assess, diagnose and treat patients.
  • Communicate with patients, substitute decision-makers and other healthcare professionals involved in your care (the circle of care), unless you expressly instruct otherwise.
  • Schedule appointments, manage billing and submit insurance or eClaims.
  • Comply with legal and regulatory requirements.
  • Improve our services and ensure quality assurance.

4. Consent to collect, use and disclose information

4.1 Valid consent

Under PHIPA, consent for the collection, use and disclosure of PHI must be knowledgeable, relate to the information and not be obtained through deception or coercion. Consent can be express (spoken or written) or implied, except where express consent is required by law. We will explain the purposes for which we collect your information and answer any questions.

4.2 Implied consent within the circle of care

For most direct care activities, your consent is implied and we may share PHI with other healthcare professionals involved in your treatment (e.g., referring physicians, specialists, physiotherapists) unless you specifically instruct us not to. The circle of care does not include insurers or third-party providers; we will obtain express consent before sharing information with them, unless otherwise permitted by law.

4.3 Express consent and eClaims

We require express consent when using your PHI for purposes beyond direct care, such as submitting electronic claims through TELUS Health eClaims, communicating with insurers or sharing information with researchers. You may decline or withdraw consent for these purposes at any time.

4.4 Withdrawing consent

You may withdraw or withhold consent at any time by providing us with notice. Withdrawal is not retroactive and may be subject to legal or contractual restrictions. Please note that refusing or withdrawing consent may affect our ability to provide certain services or process insurance claims.

4.5 Capacity and substitute decision-makers

We will determine whether patients have capacity to consent. If a patient is incapable, a substitute decision-maker (e.g., parent, guardian, attorney for personal care) may provide consent on the patient's behalf as outlined in PHIPA.

5. Use and disclosure of your information

We will use or disclose PHI only for the purposes identified above or as permitted or required by law. Examples include:

  • Treatment and care: communicating with other members of the circle of care.
  • Payment: submitting claims to insurers or health plans.
  • Administrative services: managing appointments, billing and quality improvement.
  • Regulatory compliance: reporting to regulatory colleges or government agencies when required by law (e.g., mandatory reporting of certain infections, reportable diseases or abuse).
  • Serious risk: where there is a risk of serious bodily harm to a patient or another person.
  • Research or marketing: only with your express consent or as permitted by law.

We do not sell or rent personal information. We will not disclose PHI to third parties for marketing or unrelated purposes without your permission.

5.1 Service providers and cross-border transfers

We may use service providers (e.g., cloud hosting providers, eClaims platforms, IT support) to process or store PHI. PHIPA does not require data to be stored in Ontario or Canada, but we remain accountable for protecting PHI and ensuring that service providers use appropriate safeguards. We use Canadian data centers where possible and require written agreements and confidentiality obligations from any service provider with access to PHI.

5.2 WellPoint system

Our WellPoint practice management system is used to schedule appointments, chart patient encounters, process payments and submit eClaims. The system:

  • Uses encryption and secure authentication to protect data.
  • Implements role-based access controls and logs all user access.
  • Maintains audit trails for appointments, chart entries and billing transactions.
  • Provides secure portals for patients to book appointments and view limited information.
  • Includes administrative, technical and physical safeguards consistent with PHIPA and industry best practices.

We restrict access to WellPoint to authorized staff and practitioners and ensure they sign confidentiality agreements. We monitor system activity and audit logs to detect unauthorized access.

6. Safeguards and security measures

We protect PHI through physical, technical and administrative safeguards:

  • Physical safeguards: secure offices, locked filing cabinets and controlled access to areas where records are stored. Paper records are cross-cut shredded and destroyed securely.
  • Technical safeguards: encryption of data at rest and in transit; secure authentication, multi-factor authentication, and automatic session timeouts; regular backups; firewalls and anti-virus measures. For mobile devices, we use strong whole-disk encryption and discourage storage of PHI on portable devices; passwords alone are not sufficient.
  • Administrative safeguards: privacy training and confidentiality agreements for all staff, regular risk assessments, and policies governing the collection, use and disclosure of PHI.

We maintain a data inventory and assess privacy risks, including the use of artificial intelligence (AI). When using AI tools (e.g., transcription scribes), we evaluate risks and implement controls as recommended in the IPC handbook.

7. Retention and destruction of records

We retain patient records in accordance with legal and professional obligations. Generally, records are kept for at least 10 years after the date of the last entry for adult patients, or10 years after a child patient turns 18. Records may be kept longer if there are legal proceedings or other requirements (up to 15 years or more). After the retention period, we securely destroy records by cross-cut shredding paper and permanently wiping or destroying electronic media.

8. Access and correction rights

Under PHIPA, you have the right to request access to your health records and request corrections if you believe they are inaccurate or incomplete. To request access or correction:

  1. Submit your request in writing to our Privacy Officer. We may require proof of identity.
  2. We will respond within 3 days (with the possibility of an extension up to 10 days) and may charge a reasonable fee for copying or retrieval.
  3. We will provide an explanation if we refuse access or correction and will annotate the record to show that a correction was requested and refused.

We will correct records when you demonstrate that they are inaccurate and provide us with correct information.

9. Breach notification

If a breach of PHI occurs (e.g., theft, loss, unauthorized use or disclosure), our agents must notify the Privacy Officer immediately. The Privacy Officer will:

  • Investigate the breach and take steps to contain it.
  • Notify individuals whose PHI has been compromised and explain steps they can take to protect themselves.
  • Notify the Information and Privacy Commissioner of Ontario and any relevant regulatory college or ministry as required by law.
  • Keep records of the breach and corrective actions.

We also maintain an incident response plan and review breaches to prevent recurrence.

10. Website, cookies and digital identifiers

Our website and WellPoint portal may use cookies or similar technologies to improve user experience. Cookies collect non-identifying information such as IP address, browser type and pages visited. You can adjust your browser settings to refuse cookies; however, this may affect functionality.

As of August 2025, Ontario is proposing regulations under the More Convenient Care Act, 2025 to enable digital health identifiers and access to the provincial electronic health record. If these regulations come into force, we will adopt measures to ensure patients can access their records via digital means and that we comply with any additional requirements.

11. Accessibility and language

We are committed to providing information in accessible formats in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). Healthcare providers must create, provide and receive information in accessible formats and communications and make websites accessible. Our public website and online booking portal are designed to meet WCAG 2.1 Level AA requirements (as required for organizations with 50 or more employees). We will accommodate alternative formats upon request.

12. Complaints and contact information

If you have questions about this policy, wish to request access or correction, or wish to make a complaint about our privacy practices, please contact our Privacy Officer:

Rimple Garcha

OsteoMed Wellness Centre

Address: 83 Loyalist Trail Unit D7, Oakville ON

Phone: (365) 726-7777

Email: osteomedontario@gmail.com

We take all complaints seriously. If you are not satisfied with our response, you may contact the Information and Privacy Commissioner of Ontario:

Information and Privacy Commissioner of Ontario

2 Bloor Street East, Suite 1400, Toronto ON M4W 1A8

Tel: 416-326-3333 / 1-800-387-0073

www.ipc.on.ca

13. Changes to this policy

We may update this policy to reflect legislative or operational changes. The effective date at the top of the policy indicates when it last changed. We will post the revised policy on our website and, where appropriate, notify patients. Changes will apply to information collected after the new policy takes effect.

This policy is based on current laws and guidance available as of October 9, 2025. We will review and update our practices as privacy legislation evolves, including any amendments to PHIPA or related regulations.