Legal
Privacy Policy
Last updated May 23, 2026 · Effective immediately
Health-E-Now Inc. is a Canadian technology platform. We do not provide healthcare services. Healthcare is provided by independent, Canadian-licensed physicians who use our platform. Under Ontario's Personal Health Information Protection Act, 2004 (PHIPA), each treating physician is the Health Information Custodian (HIC) of the information created during your visits with them. Health-E-Now Inc. acts as that physician's Electronic Service Provider and agent for the secure storage and transmission of your health information (PHIPA §10(4), §17). This page explains, in plain language, what we collect on the physician's behalf, how it's used, who it's shared with, where it lives, and the rights you have.
Who we are and our role under PHIPA
"Health-E-Now," "we," "us," and "our" refer to Health-E-Now Inc., an Ontario corporation (Ontario Corporation No. 1001412428), with registered office at 2-558 Upper Gage Ave, Suite 316, Hamilton ON L8V 4J6, operating health-e-now.com.
The treating physicians who provide care through our platform are independent CPSO-licensed Ontario physicians. Each treating physician is the Health Information Custodian (HIC) of the PHI created during your visits with them, in line with PHIPA §3(1). Health-E-Now Inc. is not a custodian of that PHI; we operate the platform — software, scheduling, storage, video, intake, recordkeeping, billing — as an electronic service provider within the meaning of PHIPA §10(4) and as an agent of the treating physicians under §17. We handle PHI only on the physicians' instructions and only for the purposes set out below.
Our public statement of information practices required by PHIPA §16(1) is available at /notice-of-information-practices.
What we collect
- Identity — legal name, date of birth, address, phone, email.
- Government identification — verified through Stripe Identity once at signup. Stripe Identity asks you to upload a photo of a government-issued ID and a short selfie video; Stripe performs an automated biometric comparison (face on the ID vs. face in the selfie) to confirm that you are the person on the ID. We receive only the verification result and date — a pass/fail and a verification session ID. The ID image, the selfie, and the biometric template are held by Stripe under Stripe's data-retention policy and are not retained on Health-E-Now systems after verification completes. CPSO Policy 6-22 requires identity verification before a virtual visit.
- OHIP / health-card number — only if you choose to provide it; required if an encounter is billed to OHIP on your behalf.
- Health information — your visit history, AI-assisted intake chart, doctor's notes (Subjective, Objective, Assessment, Plan), prescriptions, sick notes, lab requisitions, referrals.
- Billing — tokenized payment-method reference (the raw card number stays with Stripe), receipts, refund records.
- Visit media — audio streamed for live transcription (not stored beyond the visit unless you separately consent); video recordings only if you separately consent.
- Technical data — IP address, device, and browser logs needed for security and audit. Retained 30 days unless required for a regulatory investigation.
How we use it
We collect and use your PHI only to:
- Provide your medical visits, prescriptions, and follow-up care.
- Send the documents you authorize (Rx, sick note, lab requisition, referral) to the recipient you choose.
- Maintain a complete medical record for the period required by Ontario law (10 years from your last visit, per CPSO Policy 4-12).
- Bill you for uninsured services and convenience, and — where applicable and at your direction — bill OHIP for insured services. See How we differ from OHIP.
- Comply with legal obligations (reportable conditions, suspected child or elder abuse, court orders) — only as required by law and with notice to you unless prohibited.
Where your data lives
In Canada. Our primary database, attached storage, and backups are hosted in Toronto on infrastructure operated by Supabase, deployed on AWS ca-central-1 (Toronto). All PHI at rest stays in Canada.
Cross-border processing disclosure. Some of our agents and sub-processors are headquartered in the United States and operate global infrastructure. Specifically:
- Stripe (US) — payment processing and Stripe Identity (gov ID + selfie + biometric verification).
- Anthropic (US) — AI intake, AI scribe, document drafting. Routed to North American infrastructure under a zero-retention, no-training agreement.
- Deepgram (US) — live transcription. Routed to North American infrastructure under a zero-retention agreement.
- Daily.co (US-headquartered) — real-time video rooms. We use the Healthcare plan with Canadian-region rooms where available; rooms are ephemeral and not recorded by default.
- Resend (US) — transactional email (sign-in links, appointment reminders, document delivery). Email bodies contain only the minimum needed for the message; subject lines do not contain PHI beyond a first name.
- Vercel — application hosting and edge CDN. No PHI is cached at the edge; PHI is served only to authenticated browsers over TLS 1.3.
- Sentry — error monitoring with PHI scrubbed from breadcrumbs and headers.
Because these US-based agents operate global infrastructure, PHI in flight to them, or processed by them, may be subject to United States legal processes including the CLOUD Act and lawful-access requests by US authorities. We have minimized what each agent sees, contracted with each of them under written agreements that require confidentiality and use solely on our instructions, and we disclose this so you can make an informed choice about whether to use the service.
Who we share with
We share your PHI only:
- With your treating physician for the visit (they are the custodian of the resulting record).
- With recipients you specify — pharmacy of your choice, employer for a sick note, specialist for a referral, lab for a requisition. The pharmacy you use is always a choice you actively make at the end of the visit; we never pre-select one for you.
- With our agents and service providers, each bound by written agreement to use your data only on our instructions and to maintain confidentiality. See Trust + Security for the current list and Notice of Information Practices.
- For B2B paramedical-clinic visits only, with the requesting clinic — but only if you have consented to that specific record-sharing arrangement.
- When required by law — court order, subpoena, public-health reporting. We notify you unless legally prohibited.
We do not sell PHI. We do not share PHI with advertisers, data brokers, or social platforms.
Your rights under PHIPA
- Access (§52) — request a copy of your PHI. From your account: Account → Privacy → Download my data. The file includes your profile, every visit, every SOAP note, every signed document, and your consent log. You can also email us — we'll respond within 30 days.
- Correction (§55) — ask us to correct anything you believe is wrong. We respond within 30 days; if we disagree we'll attach your statement of disagreement.
- Withdraw consent (§19) — for any specific use beyond what's strictly required for your care.
- Lock-box (§37(1)(a)) — restrict specific visits from being seen by future treating providers on Health-E-Now, by referring paramedical clinics, by Leader Clinic dashboards, or by platform reporting. The treating physician for the locked visit and you retain access. Note: this may affect the quality of care a future physician can provide, and we may be required to tell them that information has been withheld.
- Complaint (§56) — to our Privacy Officer first, then to the IPC of Ontario if unresolved. See Complaints + inquiries.
- Account closure — close your account from Account → Privacy. The medical record is retained per CPSO's 10-year rule, but no new PHI is collected.
Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). The most sensitive PHI columns (intake answers, SOAP narrative, prescription contents, transcripts) are additionally encrypted at the application layer with customer-managed keys before they reach the database. Access is restricted by Row-Level Security at the database — your data is queryable only by you, your treating physician, and (for B2B visits, with your consent) the requesting clinic. Staff sign-in requires multi-factor authentication, idle sessions time out, and every PHI access (read or write) lands in an insert-only audit log retained for 10 years. We monitor for unusual access patterns daily and our Privacy Officer reviews flagged events.
Breach notification
If we or one of our agents becomes aware of a privacy breach that affects your PHI, we will notify you and the Information and Privacy Commissioner of Ontario at the first reasonable opportunity, in accordance with PHIPA §12 and O. Reg. 224/17. The notice will describe what happened, what PHI was involved, what we are doing in response, and what you can do. For breaches that are required to be reported to the IPC (e.g. use or disclosure without authority, theft, loss, or unauthorized access), we will report to the IPC promptly and provide the annual statistical report PHIPA requires.
Retention
- Medical record — 10 years from your last visit, or 10 years past the age of majority if you were a minor at the time (CPSO Policy 4-12).
- Identity-verification result — kept as a pass/fail outcome and date only. The ID image and selfie are held by Stripe under Stripe's own retention policy and are not retained by Health-E-Now after verification completes.
- Visit recordings — not retained by default. If a doctor enables recording and you consent, the recording is retained only as long as needed to produce the SOAP note and is then deleted; if it becomes part of the chart, the 10-year rule applies.
- Audit log and consent log — 10 years minimum, insert-only.
- Web + access logs — 30 days unless required for a regulatory investigation.
- Marketing communications — if you unsubscribe, we retain a suppression record permanently to make sure you are not re-emailed.
AI use
We use AI for pre-visit intake, live transcription, and drafting documents (chart notes, prescriptions, sick notes, requisitions). AI does not diagnose, prescribe, or make clinical decisions. Every document is reviewed and signed by the treating physician. You can decline AI on any visit without affecting your care. See our AI Disclosure + Acceptable Use page for the full breakdown of where AI sits in the workflow.
Consent
We capture the following consents and log them with a timestamp, IP, user agent, and the version of the policy you accepted:
- Terms of Use acceptance.
- Privacy Policy acceptance.
- General telehealth consent (acknowledging the limitations of virtual care and the possibility of an in-person referral).
- AI scribe consent — separate, explicit, can be declined per visit.
- Video session consent — recording is off unless you separately consent at visit start.
- Stripe Identity verification consent (gov ID + selfie + biometric comparison).
- CASL marketing consent — unchecked by default, with one-click unsubscribe in every commercial email.
- Record-sharing consent for B2B paramedical-clinic visits.
- Pharmacy-of-choice — you actively select a pharmacy at the end of each visit, never a default.
Consents can be withdrawn from Account → Privacy; withdrawal stops further use for that purpose but does not undo prior lawful uses.
Cookies + analytics
We use only strictly-necessary cookies for sign-in, payment, and cookie consent. Analytics and marketing cookies do not fire on your device until you opt in via the cookie banner. We re-prompt every 12 months. See our Cookie Policy for the full list.
Children
Physicians on the platform see children only with the explicit consent of a parent or legal guardian, who must be the account holder and add the child as a dependent. Children 12+ in Ontario may consent to their own care for certain treatments under the Health Care Consent Act and PHIPA; ask us if you'd like that flow.
Changes to this policy
We will email you about any material change at least 30 days before it takes effect and re-prompt for any consent that the change affects. The current version is always at this URL with a "last updated" date.
Contact us
Privacy Officer
Health-E-Now Inc.
2-558 Upper Gage Ave, Suite 316, Hamilton ON L8V 4J6
privacy@health-e-now.com
If you are not satisfied with our response, you may contact the Information and Privacy Commissioner of Ontario at 1-800-387-0073 or www.ipc.on.ca. For complaints about a physician's conduct, contact the CPSO.
This page is provided as plain-language guidance and is not a substitute for the full PHIPA statute. The full Act is available at ontario.ca/laws/statute/04p03.