Health-E-Now

Public

Trust + security at Health-E-Now.

Health-E-Now Inc. is a Canadian technology platform — an Electronic Service Provider and agent of the independent physicians who use the platform to provide care. Those physicians are the Health Information Custodians under Ontario's PHIPA. That comes with real obligations on our end as their ESP. Below is exactly what we do — controls, frameworks, sub-processors, and how to get in touch if something doesn't look right.

Controls in place

Plain-English summaries. Auditors will find each of these in our policies + system configurations.

  • Data residency

    Canada · only

    Your PHI lives in a Toronto data centre (Supabase / AWS ca-central-1). Backups are encrypted and stored in the same region. We do not transfer PHI to the United States or any other country.

  • Encryption in transit

    TLS 1.3 + HSTS

    Every request is encrypted with TLS 1.3. HTTP Strict Transport Security is enabled with a 2-year max-age, includeSubDomains, and HSTS preload.

  • Encryption at rest

    AES-256-GCM · CMK

    Sensitive PHI columns (SOAP narrative, intake answers, prescription contents, transcripts) are encrypted at the application layer with customer-managed keys before they ever reach the database. Even Supabase support can't read them without our cooperation.

  • Patient lock-box

    PHIPA §37

    Patients can lock any visit so it's restricted from sharing with referring clinics, leader-clinics, and admin reporting. Only the treating doctor and the patient retain access.

  • Audit log

    Insert-only · 10yr retention

    Every PHI access — read or write — lands in an append-only audit log enforced at the database via Row-Level Security policies. We can show you who looked at your record, when, from which IP, and what they did.

  • Multi-factor authentication

    Required for clinicians

    All clinicians, clinic staff, leader-clinic staff, and admins are required to enroll in TOTP-based 2FA. Patients are encouraged but not required.

  • Idle session timeout

    30 min staff · 60 min patient

    Inactive sessions are signed out automatically. The interval is shorter for staff routes than patient routes.

  • IP geofencing

    Canada-default

    Staff access from outside Canada is logged and flagged for review in the daily anomaly digest. Patient access is logged but not blocked.

  • Anomaly detection

    Daily scan

    Our cron sweeps the audit log every 24 h for unusual access patterns: volume spikes (>300 PHI reads), staff activity in the 02:00–05:00 ET window, stale CPSO licenses. Anomalies email the privacy officer + appear in /admin/anomalies.

  • Recording disclosure

    Opt-in · per-visit consent

    Visits are not recorded by default. When a doctor enables recording, the patient must explicitly consent on camera and the consent is logged with timestamp + choice in the consent log.

  • Right of access (PHIPA §52)

    Self-serve JSON export

    From your account, one click downloads a complete bundle of your record — profile, dependents, every visit, every encounter, every signed document, your full consent log. Most providers take 30 days; we take 2 seconds.

  • Right of correction (PHIPA §55)

    30-day SLA

    Email privacy@health-e-now.com. If we disagree, we attach your statement of disagreement to the record per the Act.

Frameworks

FrameworkStatusNotes
PHIPACompliantOntario Personal Health Information Protection Act, 2004
PIPEDACompliantFederal private-sector privacy law
CPSO Virtual CareAlignedPolicy 6-22 — identity verification, recording, prescribing
SOC 2 Type IIIn progressAudit window starts 2026 Q3 — Drata-managed evidence
HITRUST CSFPlannedTargeted for 2027 once enterprise pipeline justifies it
ISO 27001AlignedControls mapped; certification not yet pursued

Sub-processors

Each is contractually bound to use your data only on our instructions. PHI never goes to any sub-processor outside the categories listed here.

ProviderPurposeRegion
SupabasePostgres database + Storage + Authca-central-1 (Toronto)
VercelApplication hosting + edge CDNGlobal edge (no PHI cached)
StripePayment processing + IdentityCanada
Daily.coReal-time video roomsCanada / North America
DeepgramLive transcription (visit AI scribe)Canada / North America · zero-retention contract
AnthropicAI intake + AI scribe SOAP generationNorth America · zero-retention contract
ResendTransactional email (auth + reminders)Global
SentryError monitoring · PHI scrubbed from breadcrumbsGlobal

We'll notify you in advance of any material change to this list per our privacy policy.

Found something?

We run an informal bug-bounty: security@health-e-now.com. Report a vulnerability in good faith and we'll coordinate a fix, credit you, and (for material findings) compensate you fairly. Please give us 90 days before public disclosure.