Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

AI-PIA · Digital health & life sciences

AI Privacy Impact Assessment for Virtual Care & Telehealth Platforms

An AI-PIA for a virtual care platform examines the symptom-checker or triage tool patients meet before, or instead of, a clinician, since that tool collects and interprets health information on its own. The trigger is usually adding or licensing a triage feature and realizing nobody has looked closely at what it actually collects or how its recommendations get made. A provincial regulator has already published findings on exactly this kind of tool, which is why we treat the assessment as concrete work, not a general ethics exercise.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the assessment has to examine

A patient-facing triage tool raises questions a clinician-facing documentation tool does not, since it interacts with the patient directly before any human reviews the exchange.

What the tool actually collects from patients

Symptom descriptions, dates of birth, and sometimes identity data flow into the tool before a clinician ever sees them, and the assessment checks whether each item is actually needed for the triage outcome.

How the triage recommendation is made

Whether the logic is a licensed vendor's model or built in-house, patients and clinicians both benefit from a clear account of what the tool weighs and how confident its output actually is.

The escalation path to a human clinician

A defined point where the tool hands off to a clinician, particularly for higher-risk symptoms, matters as much for privacy accountability as for clinical safety.

Retention of AI interaction logs

Chat transcripts and triage sessions with the tool need their own retention rule, distinct from the clinical record they may or may not become part of.

The AI vendor as a data recipient

Many triage tools are licensed rather than built in-house, which means patient inputs flow to a vendor whose own data handling becomes part of the platform's risk, not a separate concern.

Regulatory map

How AI use here sits alongside existing privacy obligations

An AI-PIA does not replace the platform's underlying PHIPA status; it adds a specific layer of scrutiny on top of it.

PHIPA still governs the data the AI processes

Whether the platform is a custodian, ESP or HINP determines who is accountable for the personal health information a triage tool handles, regardless of how the recommendation itself gets generated.

Read our guide →

The OPC's principles for responsible AI

Federal guidance on trustworthy and privacy-protective generative AI sets out expectations around transparency, accountability and human oversight that a triage tool assessment should be measured against.

Primary source →

Medical device classification is a separate question

Whether a triage tool is a regulated medical device sits under a distinct regulatory framework from privacy law, and the AI-PIA does not answer that question; it addresses the privacy risk regardless of how the device question is ultimately resolved.

What goes wrong

What the assessment is built to catch

The most concrete lesson for this niche comes from a regulator's actual findings on a comparable tool.

  • Collecting more than a symptom checker needs

    Alberta's OIPC investigation into Babylon by Telus Health specifically flagged date of birth collected through a symptom-checking function as part of a broader over-collection finding across the app.

    Source →

  • A triage tool with no clear escalation trigger

    A tool that does not reliably route higher-risk symptoms to a human clinician creates both a clinical and a privacy accountability gap, since it is making consequential decisions without documented oversight.

  • Bias in triage recommendations

    A licensed or in-house model trained on data that does not represent the platform's actual patient population can produce systematically different guidance across groups, a fairness issue with real privacy and clinical consequences.

  • An AI vendor with unclear data practices

    Licensing a triage tool without reviewing what the vendor does with patient inputs on their end extends the platform's risk into a vendor relationship that was never formally assessed.

Our ai-pia for virtual care & telehealth platforms

What our AI-PIA covers for a virtual care platform

Focused on the patient-facing triage and symptom-checking features this niche actually runs, not a generic AI governance exercise.

Elderly man make distant video call communicating with doctor online
  1. Data handling review

    An evaluation of exactly what a triage or symptom-checker tool collects, why, and where that data goes, sized against what the visit or interaction actually requires.

  2. Bias and misuse considerations

    A review of where triage recommendations could produce unfair or inconsistent outcomes across patient groups, with direction on improving transparency and oversight.

  3. Regulatory alignment overview

    A comparison of current practices against OPC guidance on responsible AI and the platform's existing PHIPA obligations, without asserting formal compliance certification.

  4. Escalation and human-oversight guidance

    Support defining and documenting the point at which a triage tool hands off to a clinician, so the assessment produces a practical process, not just a written principle.

  5. Vendor AI review

    Where the triage tool is licensed rather than built in-house, a review of what the vendor discloses about its own data practices as part of the overall assessment.

How the engagement runs

How the AI-PIA runs

Built around the specific triage or symptom-checking feature in question, not a company-wide AI audit.

  1. Step 1

    Identify the AI touchpoint

    We confirm exactly what patient-facing AI feature is in scope, whether a symptom checker, a triage questionnaire, or another patient-interacting tool.

  2. Step 2

    Map data flows

    We trace what the tool collects, where it goes, whether a vendor is involved, and how long interaction data is retained.

  3. Step 3

    Assess bias, misuse and escalation

    We review how recommendations are generated, where fairness concerns could arise, and how reliably the tool escalates to a human clinician.

  4. Step 4

    Document findings and guidance

    We deliver a clear record of the assessment and practical recommendations your team can act on, sized to support Ontario Health or hospital review requests.

What it costs

What shapes AI-PIA cost for a virtual care platform

Cost depends on whether the triage tool is built in-house or licensed from a vendor, how much clinical decision-making the tool actually performs, and how many distinct AI-driven patient touchpoints exist across the platform. A simple symptom-intake questionnaire needs a lighter assessment than a tool making an active triage recommendation.

This work is often paired with the platform's broader PIA and TRA program once a new AI feature is added or licensed, so the assessment stays current as the tool changes. We scope the engagement after reviewing what the tool actually does and quote from there.

Virtual Care & Telehealth Platforms: AI-PIA questions, answered

It can be both, and they are separate questions. Medical device classification sits under its own regulatory framework and depends on what the tool actually claims to do, while the privacy question, what data it collects and how it is used, applies regardless of that classification. An AI-PIA addresses the privacy side directly and does not wait on the device question being resolved.

Alberta's OIPC investigation into Babylon by Telus Health found date of birth collected through the app's symptom-checking function as part of a broader pattern of over-collection that also included government ID and selfie images, one of 31 findings in the published report.

It needs to cover what the vendor's model actually does with patient inputs on their end, not just how your platform presents the tool to patients. Reviewing the vendor's data practices, retention and any sub-processing they rely on is part of the assessment, since licensing the tool does not transfer away the privacy risk it creates.

If a tool produces systematically different recommendations for different groups of patients, the personal characteristics driving that difference, and how the tool weighs them, become a transparency and fairness question the assessment needs to document, alongside whatever clinical review already exists.

Generally yes, since even general guidance is generated from personal health information the patient provided, and the assessment looks at how that data is handled regardless of how clinically definitive the output is. A lighter-touch tool may need a shorter assessment, but skipping it entirely leaves the same over-collection risk unexamined.

A general PIA looks at a system or integration as a whole, while an AI-PIA focuses specifically on how an algorithmic feature makes decisions, what bias or misuse risks it carries, and how transparent that process is to patients and clinicians. The two often run together when a new AI-driven feature is also a new system integration.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.