PIPEDA
Canada’s federal private-sector privacy law sets ground rules for handling personal information in commercial activity and may apply to cross-border information flows.
Choosing a tool for yourself or your healthcare team? Make privacy and security part of the decision. The requirements depend on your organization, province, the information involved, and how you’ll use it.
A useful review identifies which rules apply, what information is involved, where it moves, and who is responsible at each stage.
Canada’s federal private-sector privacy law sets ground rules for handling personal information in commercial activity and may apply to cross-border information flows.
Ontario’s health privacy law governs personal health information and includes duties for health information custodians and people acting on their behalf.
Other provincial private-sector or health privacy laws may apply, including Quebec requirements that need dedicated review.
If you’re choosing for a team, involve the people responsible for clinical care, IT, privacy, security, legal advice, and purchasing, along with the product provider.
Treat compliance as an organizational and deployment-specific process, not a product label.
Document the proposed workflow, information, systems, locations, vendors, and user roles.
Identify the information types and the federal, provincial, contractual, and organizational requirements that may apply.
Review purpose, authority, consent, safeguards, access, retention, incident handling, and vendor responsibilities.
Document decisions, configure the approved deployment, train users, and reassess material changes.
These official resources can help you prepare questions for your legal, privacy, and security advisers.
Explore Dragon Medical One for yourself or your team.
Explore DMOInclude privacy in future workflow planning.
Explore next stepsAsk where to find privacy information for a specific product.
Contact the teamNo. Compliance depends on the organization, applicable law, information, purpose, configuration, contracts, safeguards, people, and actual workflow.
PHIPA is Ontario legislation. Other provinces and territories have their own legal frameworks, and federal law may also be relevant. Obtain advice for the jurisdictions involved.
No. Do not submit patient information or other sensitive health information through general sales, webinar, portal, or contact forms.
The team may include privacy, legal, security, IT, clinical, procurement, records, vendor, implementation, and business stakeholders depending on the proposed use case.
Tell us which product you’re considering and how you plan to use it—without sending patient information. We can help you find information for your review team.