Public
Trust + security at Health-E-Now.
Health-E-Now Inc. is a Canadian technology platform — an Electronic Service Provider and agent of the independent physicians who use the platform to provide care. Those physicians are the Health Information Custodians under Ontario's PHIPA. That comes with real obligations on our end as their ESP. Below is exactly what we do — controls, frameworks, sub-processors, and how to get in touch if something doesn't look right.
Controls in place
Plain-English summaries. Auditors will find each of these in our policies + system configurations.
Data residency
Canada · onlyYour PHI lives in a Toronto data centre (Supabase / AWS ca-central-1). Backups are encrypted and stored in the same region. We do not transfer PHI to the United States or any other country.
Encryption in transit
TLS 1.3 + HSTSEvery request is encrypted with TLS 1.3. HTTP Strict Transport Security is enabled with a 2-year max-age, includeSubDomains, and HSTS preload.
Encryption at rest
AES-256-GCM · CMKSensitive PHI columns (SOAP narrative, intake answers, prescription contents, transcripts) are encrypted at the application layer with customer-managed keys before they ever reach the database. Even Supabase support can't read them without our cooperation.
Patient lock-box
PHIPA §37Patients can lock any visit so it's restricted from sharing with referring clinics, leader-clinics, and admin reporting. Only the treating doctor and the patient retain access.
Audit log
Insert-only · 10yr retentionEvery PHI access — read or write — lands in an append-only audit log enforced at the database via Row-Level Security policies. We can show you who looked at your record, when, from which IP, and what they did.
Multi-factor authentication
Required for cliniciansAll clinicians, clinic staff, leader-clinic staff, and admins are required to enroll in TOTP-based 2FA. Patients are encouraged but not required.
Idle session timeout
30 min staff · 60 min patientInactive sessions are signed out automatically. The interval is shorter for staff routes than patient routes.
IP geofencing
Canada-defaultStaff access from outside Canada is logged and flagged for review in the daily anomaly digest. Patient access is logged but not blocked.
Anomaly detection
Daily scanOur cron sweeps the audit log every 24 h for unusual access patterns: volume spikes (>300 PHI reads), staff activity in the 02:00–05:00 ET window, stale CPSO licenses. Anomalies email the privacy officer + appear in /admin/anomalies.
Recording disclosure
Opt-in · per-visit consentVisits are not recorded by default. When a doctor enables recording, the patient must explicitly consent on camera and the consent is logged with timestamp + choice in the consent log.
Right of access (PHIPA §52)
Self-serve JSON exportFrom your account, one click downloads a complete bundle of your record — profile, dependents, every visit, every encounter, every signed document, your full consent log. Most providers take 30 days; we take 2 seconds.
Right of correction (PHIPA §55)
30-day SLAEmail privacy@health-e-now.com. If we disagree, we attach your statement of disagreement to the record per the Act.
Frameworks
| Framework | Status | Notes |
|---|---|---|
| PHIPA | Compliant | Ontario Personal Health Information Protection Act, 2004 |
| PIPEDA | Compliant | Federal private-sector privacy law |
| CPSO Virtual Care | Aligned | Policy 6-22 — identity verification, recording, prescribing |
| SOC 2 Type II | In progress | Audit window starts 2026 Q3 — Drata-managed evidence |
| HITRUST CSF | Planned | Targeted for 2027 once enterprise pipeline justifies it |
| ISO 27001 | Aligned | Controls mapped; certification not yet pursued |
Sub-processors
Each is contractually bound to use your data only on our instructions. PHI never goes to any sub-processor outside the categories listed here.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Postgres database + Storage + Auth | ca-central-1 (Toronto) |
| Vercel | Application hosting + edge CDN | Global edge (no PHI cached) |
| Stripe | Payment processing + Identity | Canada |
| Daily.co | Real-time video rooms | Canada / North America |
| Deepgram | Live transcription (visit AI scribe) | Canada / North America · zero-retention contract |
| Anthropic | AI intake + AI scribe SOAP generation | North America · zero-retention contract |
| Resend | Transactional email (auth + reminders) | Global |
| Sentry | Error monitoring · PHI scrubbed from breadcrumbs | Global |
We'll notify you in advance of any material change to this list per our privacy policy.
Found something?
We run an informal bug-bounty: security@health-e-now.com. Report a vulnerability in good faith and we'll coordinate a fix, credit you, and (for material findings) compensate you fairly. Please give us 90 days before public disclosure.