Skip to main content

Compliance

How GGHealth meets Canadian healthcare privacy requirements — PHIPA, PIPEDA, and data residency obligations.

Last updated: May 24, 2026

Ontario Law

PHIPA Compliance

Ontario's Personal Health Information Protection Act, 2004 (PHIPA) sets the standard for how personal health information must be collected, used, disclosed, and protected. Every layer of GGHealth is designed to meet or exceed these requirements.

Consent Management

Patient consent is captured, stored, and verified before every data access. Consent types include express, implied (within circle of care), and substitute decision-maker consent. Consent status is checked programmatically — not manually.

Circle of Care

Access to PHI is restricted to healthcare providers who have a direct care relationship with the patient. Circle membership is verified at every data retrieval — not assumed. Providers outside the circle are blocked automatically.

Lockbox Controls

Patients can restrict specific records from being shared with any provider — even those within the circle of care. Lockbox restrictions are enforced at the database level. Break-glass access for emergencies is logged, flagged, and reported.

Audit Trail

Every access, modification, export, and deletion is permanently logged with who, what, when, where, and why. Audit records use a tamper-evident SHA-256 hash chain verified daily. Patients can request their full access report.

Breach Reporting

Automated breach detection monitors access patterns in real time. Confirmed breaches are reported to the Information and Privacy Commissioner of Ontario (IPC) and affected individuals as required by PHIPA Section 12(2).

Data Retention

Clinical records are retained for a minimum of 10 years from the last entry (or 10 years after a minor reaches 18), in accordance with Ontario regulatory requirements. Secure cryptographic erasure is used at end of life.

Federal Law

PIPEDA Compliance

The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how private-sector organisations handle personal information in Canada. GGHealth adheres to PIPEDA's 10 fair information principles.

Right of Access

Individuals have the right to know what personal information is held about them, how it is used, and to whom it has been disclosed. GGHealth provides tools for patients to request and receive this information.

Data Portability

Patients and providers can export their data in portable, machine-readable formats. We never hold data hostage or make export unnecessarily difficult.

Meaningful Consent

We collect only the information necessary for the stated purpose. Consent is informed, specific, and can be withdrawn at any time (subject to legal retention requirements).

Purpose Limitation

Personal information is used only for the purposes for which it was collected. We do not use patient data for marketing, advertising, or any purpose unrelated to healthcare delivery.

Accountability

Gift of Gab Tech Inc. has designated a Privacy Officer responsible for compliance with PIPEDA and PHIPA. Our privacy practices are documented, regularly reviewed, and available for inspection.

Safeguards

Physical, organisational, and technical safeguards are in place to protect personal information — including AES-256-GCM encryption, role-based access, MFA, and tamper-evident audit logging.

Canadian Data Residency

All GGHealth data — patient records, provider information, backups, audit logs, and encryption keys — is stored and processed exclusively within Canada.

  • Azure Canada Central (Ontario) — all compute and storage
  • Audio transcription within Canada via Azure OpenAI (when configured)
  • Contractual data residency guarantees with Microsoft
  • Summarisation via Anthropic Claude (US-based, de-identified text only)
  • Canadian-hosted AI alternatives under active evaluation
  • Subject to Canadian law and jurisdiction
CA

Data stored in Canada

Compliance Roadmap

Our commitment to security and compliance is ongoing. Here is where we stand today and where we are headed.

PHIPA compliance

Complete

Consent management, circle of care, lockbox, audit trail, breach notification

PIPEDA compliance

Complete

Right of access, data portability, meaningful consent, purpose limitation

Canadian data residency

Complete

All data stored in Azure Canada Central. AI transcription uses Azure OpenAI (Canada Central) when configured; summarisation uses Anthropic Claude (US-based, de-identified text only). See Privacy Policy for full details.

AES-256-GCM encryption

Complete

Field-level encryption at rest, TLS 1.3 in transit, Azure Key Vault

Tamper-evident audit logging

Complete

SHA-256 hash chain with daily verification

SOC 2 Type I preparation

In Progress

Policies, controls documentation, and evidence collection in progress

SOC 2 Type I audit

Planned

Engagement with independent auditor — targeted for Q4 2026

SOC 2 Type II audit

Planned

Continuous monitoring over observation period — targeted for 2027

Third-party penetration testing

Planned

Engagement with independent security firm — targeted for Q3 2026