Regulatory
Compliance
How GGHealth meets Canadian healthcare privacy requirements — PHIPA, PIPEDA, and data residency obligations.
Last updated: May 24, 2026
PHIPA Compliance
Ontario's Personal Health Information Protection Act, 2004 (PHIPA) sets the standard for how personal health information must be collected, used, disclosed, and protected. Every layer of GGHealth is designed to meet or exceed these requirements.
Consent Management
Patient consent is captured, stored, and verified before every data access. Consent types include express, implied (within circle of care), and substitute decision-maker consent. Consent status is checked programmatically — not manually.
Circle of Care
Access to PHI is restricted to healthcare providers who have a direct care relationship with the patient. Circle membership is verified at every data retrieval — not assumed. Providers outside the circle are blocked automatically.
Lockbox Controls
Patients can restrict specific records from being shared with any provider — even those within the circle of care. Lockbox restrictions are enforced at the database level. Break-glass access for emergencies is logged, flagged, and reported.
Audit Trail
Every access, modification, export, and deletion is permanently logged with who, what, when, where, and why. Audit records use a tamper-evident SHA-256 hash chain verified daily. Patients can request their full access report.
Breach Reporting
Automated breach detection monitors access patterns in real time. Confirmed breaches are reported to the Information and Privacy Commissioner of Ontario (IPC) and affected individuals as required by PHIPA Section 12(2).
Data Retention
Clinical records are retained for a minimum of 10 years from the last entry (or 10 years after a minor reaches 18), in accordance with Ontario regulatory requirements. Secure cryptographic erasure is used at end of life.
PIPEDA Compliance
The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how private-sector organisations handle personal information in Canada. GGHealth adheres to PIPEDA's 10 fair information principles.
Right of Access
Individuals have the right to know what personal information is held about them, how it is used, and to whom it has been disclosed. GGHealth provides tools for patients to request and receive this information.
Data Portability
Patients and providers can export their data in portable, machine-readable formats. We never hold data hostage or make export unnecessarily difficult.
Meaningful Consent
We collect only the information necessary for the stated purpose. Consent is informed, specific, and can be withdrawn at any time (subject to legal retention requirements).
Purpose Limitation
Personal information is used only for the purposes for which it was collected. We do not use patient data for marketing, advertising, or any purpose unrelated to healthcare delivery.
Accountability
Gift of Gab Tech Inc. has designated a Privacy Officer responsible for compliance with PIPEDA and PHIPA. Our privacy practices are documented, regularly reviewed, and available for inspection.
Safeguards
Physical, organisational, and technical safeguards are in place to protect personal information — including AES-256-GCM encryption, role-based access, MFA, and tamper-evident audit logging.
Canadian Data Residency
All GGHealth data — patient records, provider information, backups, audit logs, and encryption keys — is stored and processed exclusively within Canada.
- Azure Canada Central (Ontario) — all compute and storage
- Audio transcription within Canada via Azure OpenAI (when configured)
- Contractual data residency guarantees with Microsoft
- Summarisation via Anthropic Claude (US-based, de-identified text only)
- Canadian-hosted AI alternatives under active evaluation
- Subject to Canadian law and jurisdiction
Data stored in Canada
Compliance Roadmap
Our commitment to security and compliance is ongoing. Here is where we stand today and where we are headed.
PHIPA compliance
CompleteConsent management, circle of care, lockbox, audit trail, breach notification
PIPEDA compliance
CompleteRight of access, data portability, meaningful consent, purpose limitation
Canadian data residency
CompleteAll data stored in Azure Canada Central. AI transcription uses Azure OpenAI (Canada Central) when configured; summarisation uses Anthropic Claude (US-based, de-identified text only). See Privacy Policy for full details.
AES-256-GCM encryption
CompleteField-level encryption at rest, TLS 1.3 in transit, Azure Key Vault
Tamper-evident audit logging
CompleteSHA-256 hash chain with daily verification
SOC 2 Type I preparation
In ProgressPolicies, controls documentation, and evidence collection in progress
SOC 2 Type I audit
PlannedEngagement with independent auditor — targeted for Q4 2026
SOC 2 Type II audit
PlannedContinuous monitoring over observation period — targeted for 2027
Third-party penetration testing
PlannedEngagement with independent security firm — targeted for Q3 2026