Health-E-Now

Legal · PHIPA s.16

Notice of Information Practices

Last updated May 23, 2026

Ontario's Personal Health Information Protection Act, 2004 (PHIPA) requires health information custodians to make a written public statement describing their information practices, the steps they take to protect personal health information, and how to reach their contact person. This is that statement.

Who we are and our role

The treating physicians who provide care through the Health-E-Now platform are independent CPSO-licensed Ontario physicians and are the Health Information Custodians (HICs) of the personal health information (PHI) created during your visits.

Health-E-Now Inc. (Ontario Corporation No. 1001412428) operates the platform — the website, scheduling, video, intake, recordkeeping software, billing, and storage. We act as an electronic service provider and an agent of the treating physicians under PHIPA §10(4), §17, and §6(3). We handle PHI only on the physicians' instructions and only for the purposes set out in this notice.

What we collect

Why we collect it

We collect, use, and disclose PHI only for these purposes:

How we use AI

We use AI to help with intake, live transcription, and drafting documents for the physician's review. AI does not diagnose, prescribe, or make clinical decisions. You can decline AI for any visit without affecting your care. See our AI Disclosure for the full breakdown.

Who we disclose to

We do not sell PHI. We do not disclose PHI to advertisers, data brokers, social platforms, or any party for marketing purposes.

Cross-border processing

All PHI is stored in Canada (Toronto / AWS ca-central-1). Some of our agents are headquartered in the United States and operate global infrastructure — Anthropic and Deepgram (AI / transcription, North American region with zero-retention contracts), Stripe (payments + identity verification), Resend (transactional email). When PHI is in flight to or processed by a US-based agent, it may be subject to US legal processes such as the CLOUD Act. We have minimized what each such agent sees, and we disclose this so you can make an informed choice.

Your rights under PHIPA

Safeguards

Administrative, physical, and technical safeguards include encryption in transit (TLS 1.3) and at rest (AES-256), Row-Level Security on every PHI table, multi-factor authentication for staff, idle session timeouts, patient-restricted Postgres audit triggers, customer-managed-key application-layer encryption on the most sensitive columns, daily anomaly scans, and an immutable audit log retained 10 years. See Trust + Security for control-by-control detail.

Breach notification

If we become aware of a privacy breach that affects your PHI, we will notify you and the Information and Privacy Commissioner of Ontario at the first reasonable opportunity in accordance with PHIPA §12 and O. Reg. 224/17. We will tell you what happened, what we are doing, and what you can do.

Contact our Privacy Officer

Privacy Officer
Health-E-Now Inc.
2-558 Upper Gage Ave, Suite 316, Hamilton ON L8V 4J6
privacy@health-e-now.com

External oversight

You may also contact the Information and Privacy Commissioner of Ontario:

2 Bloor Street East, Suite 1400, Toronto ON M4W 1A8
Tel: 1-800-387-0073 · www.ipc.on.ca