
Health information carries statutory duties, a named custodian, and mandatory breach reporting. We build environments where meeting those obligations is straightforward — and evidenced when someone asks.
Tell us what you handle and who audits you. We'll be straight about what we'd address first.
We won't sell your data or send you marketing you didn't ask for.
Health care and life sciences clients we support
Under PHIPA you remain the health information custodian. Your IT provider is an agent acting on your instructions — which means the obligation to safeguard, and the consequence of failing to, stays with you.
That has a practical implication we design around: you need to be able to demonstrate that you exercised due diligence in how your environment was built, not simply that you hired someone.
Our Compliance ApproachWe provide the technical controls and the evidence. Your privacy officer owns the statutory interpretation — we build to their determination rather than substituting our own.
Notification duties to affected individuals, the Information and Privacy Commissioner, and in some cases regulatory colleges run in parallel with the technical response.
Isolate affected systems and stop further access. Nothing else matters until the exposure is closed.
Which records, whose, and over what period. This is the question that determines everything downstream.
Affected individuals at the first reasonable opportunity, plus the IPC, and colleges where applicable.
Close the entry point, document what changed, and retain the incident record for the review that follows.
This is the sequence we recommend. PHIPA sets no fixed deadlines — this is not legal advice.
In a clinical setting, IT that's merely inconvenient becomes a care delay. That changes how support has to be structured.
Server sizing, database maintenance, and update testing before you're the one who finds the defect mid-clinic.
Large-file workflows need real bandwidth and storage planning. Imaging is usually the first thing a generic setup gets wrong.
Machines that boot quickly, survive gloved use and frequent cleaning, and don't lock a clinician out mid-appointment.
Encrypted transmission of clinical information between providers, with a record of what was sent and to whom.
Guest, staff, clinical, and connected medical devices separated — medical devices are frequently unpatchable and must be isolated.
Local plus offsite copies including imaging data, with restores tested — because a clinical record loss is not recoverable from paper.
If you operate under GxP conditions, a routine patch isn't routine — changes to validated systems require assessment, documentation, and sometimes revalidation before they're applied.
We don't patch validated systems on an automatic schedule — changes are assessed for validation impact before they're applied. Change control has to be built into how the environment is managed.
Patches and configuration changes to validated systems are evaluated for validation impact, not pushed on a schedule.
Who approved it, what changed, when, and why — the audit trail an inspector expects to see for every change.
Validated systems isolated from general IT, so routine maintenance elsewhere can't affect them.
Access control, audit trails, and backup integrity aligned to ALCOA principles for regulated records.
No shared logins at reception or on clinical workstations — the audit trail has to attribute access to a person.
Workstations, servers, backups, and transmission. The control that keeps a lost device from becoming a reportable breach.
Administrative staff don't need clinical records; a locum needs access that expires. Least privilege, actually applied.
Enabled and kept long enough to investigate months later, because that's when a complaint usually surfaces.
Connected devices often can't be patched or run unsupported operating systems. They get segmented, not ignored.
A written record of controls, so an accreditation review or privacy complaint is a filing exercise.
Often yes, but it depends on your circumstances rather than a single blanket rule — PHIPA doesn't prohibit offshore storage outright, but it does require appropriate safeguards and, in practice, many custodians adopt a Canadian-residency policy. Where residency is required we host in Canadian regions and document it. The determination itself belongs to your privacy officer.
We support the environment it runs in — servers, network, workstations, backups, integrations — and we take the vendor call when the application itself is at fault. We're not the EMR vendor and won't claim expertise in clinical workflow configuration that belongs to them.
Isolate them. Connected medical devices frequently can't be patched without voiding certification, so the answer isn't to update them — it's to segment them so a compromise elsewhere can't reach them and they can't reach the internet. Pretending they can be brought current is the wrong answer.
Containment first, then establishing scope, which is where retained audit logs become critical — without them you cannot tell an affected patient or the IPC what was actually accessed. We handle the technical response and produce the incident documentation; your privacy officer handles the notification decisions.
Yes. We treat validated systems differently from the rest of the estate. Changes to validated systems get assessed for validation impact and documented before application. Tell us which systems are validated and we'll treat them accordingly.
The obligations under PHIPA don't scale down with your size, and small clinics are targeted precisely because controls are usually weaker. The implementation is smaller, but individual logins, encryption, tested backups, and audit logging aren't optional extras for a two-physician practice.
Tell us what you handle, who audits you, and what your last review flagged. We'll tell you honestly which gaps matter clinically and which are paperwork.