Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Digital health & life sciences

Privacy & Security for Virtual Care & Telehealth Platforms

A virtual care platform sits in an unusual spot: depending on how clinicians are engaged, the company can be the custodian of the health information itself, not merely a vendor serving one. That single determination shapes every policy, agreement and audit that follows, and it changes again the moment the platform licenses its technology to a hospital or crosses into the US. We build the privacy and security program around that fork, sized to a team that is often 15 to 300 people with a largely contracted clinical workforce.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Founders, medical directors and the part-time counsel or compliance director who ends up owning privacy at a Canadian direct-to-patient video, messaging or asynchronous-consult platform, plus the CTOs and VPs of Sales who get pulled in once a hospital questionnaire or an insurer RFP lands.

Platforms that both run their own clinic and license the underlying technology to hospitals, Ontario Health Teams or employer benefits programs, which means answering to patients, regulators and enterprise procurement teams at the same time.

Teams whose clinicians are largely independent contractors rather than employees, which complicates who counts as an 'agent' under PHIPA and who is responsible for training, access logs and consent at the point of care.

Companies planning a first sale into the US, where a signed Business Associate Agreement turns a Canadian software company into a party directly liable for the safeguards a US covered entity expects.

Over shoulder view of african man video calling female virtual doctor consulting patient on tablet at home. Online telemedicine chat visit meeting. Ehealth, telehealth consultation

Services

Privacy & security services for virtual care & telehealth platforms

Each service below is scoped for how virtual care & telehealth platforms actually operate — their systems, their regulators and the reviews they face.

What you hold

What has to be governed across a virtual care platform

The data set is wider than a typical health app because identity proofing, live video and clinical records all pass through the same product in real time.

Identity documents and selfies

Government ID and selfie images collected during patient verification sit alongside clinical data, yet they are frequently over-collected relative to what the visit actually requires.

Live video, audio and any recordings

The video stack itself, whether Twilio, Vonage or a similar provider, and any decision to record a session for clinical or training purposes, each carry separate consent and retention questions.

Prescriptions, e-fax logs and lab requisitions

Prescriptions routed through PrescribeIT, pharmacy fax gateways and lab requisitions feeding OLIS create paper-like trails inside a digital product, with their own misdirection risk.

OHIP, RAMQ and AHCIP numbers with claims data

Provincial health numbers and billing codes travel alongside clinical notes, employer or insurer eligibility files, and mental-health notes that deserve tighter handling than general intake data.

The EMR and its integrations

Whether the platform runs on TELUS CHR, PS Suite, Accuro or OSCAR Pro, integrations into OTNhub, eConsult and ConnectingOntario extend the environment well past the company's own servers.

Regulatory map

The regulatory fork that shapes everything else

Which regime applies, and how much of it applies directly to the company rather than through a contract, depends on a status question most platforms answer wrong on day one.

Custodian, ESP or HINP under PHIPA

A platform employing or contracting clinicians is usually itself a health information custodian, or acts through custodian physicians; a pure technology supplier is an electronic service provider, and a platform linking two or more custodians becomes a health information network provider with prescribed duties under O. Reg. 329/04.

Read our guide →

Alberta's HIA requires a PIA before launch

Custodians in Alberta must submit a privacy impact assessment to the OIPC before implementing a new health information system, a requirement a Canadian virtual-care app has already been found to have skipped.

Primary source →

BC's FIPPA reaches health authority deployments

Where a BC health authority is involved as a public body, its PIA, breach-notice and out-of-Canada disclosure duties under FIPPA apply on top of whatever the platform company owes under BC's private-sector law.

Primary source →

Quebec's Law 25 layers on project-level assessments

Serving Quebec patients brings project PIAs, cross-border transfer assessments and an incident register into scope, on top of any obligations under Quebec's health-information Act for services delivered to health bodies.

Primary source →

PIPEDA sets the federal floor

The commercial relationship with the patient is governed by PIPEDA regardless of provincial status, including mandatory breach reporting to the OPC on the real-risk-of-significant-harm standard.

Read our guide →

HIPAA arrives the moment a US contract is signed

Serving a US provider or payer makes the platform a business associate under a signed BAA, with its own risk-analysis, safeguard and 60-day breach-notification mechanics running alongside the Canadian regime.

Read our guide →

What goes wrong

How virtual care platforms actually end up in front of a regulator

The incidents that matter to this niche are mostly about what gets collected and disclosed, not exotic attacks.

  • Launching before the PIA is done

    Alberta's OIPC investigated Babylon by Telus Health and published 31 findings, including that it launched without the required HIA privacy impact assessments and over-collected government ID, selfies and dates of birth.

    Source →

  • Marketing pixels on intake and booking pages

    Ad-tech and analytics pixels placed on a mental-health intake or booking flow can share sensitive visit information with third parties, the pattern the FTC pursued against BetterHelp.

    Source →

  • Credential stuffing on patient accounts

    Consumer-facing health accounts without enforced multi-factor authentication are attractive credential-stuffing targets, the gap the OPC's joint 23andMe investigation identified alongside weak breach detection.

    Source →

  • A sub-processor incident triggering three regimes at once

    A breach at a video, transcription or CRM vendor can trigger PHIPA notification, PIPEDA's reporting duty and a BAA's contractual clock simultaneously, depending on which patients and provinces it touches.

  • Insider snooping by contracted clinicians or support staff

    Unauthorized access by contracted clinicians or call-centre agents into records outside their assigned patients is the conduct behind Ontario's first administrative monetary penalties under PHIPA.

  • Ransomware against the EMR or back office

    A platform built for 24-hour availability loses that promise the moment ransomware locks the EMR or scheduling system, turning a security incident into a service outage patients notice immediately.

When organisations call us

When a virtual care platform actually picks up the phone

Most engagements start with a deadline someone else set, not an internal decision to get ahead of compliance.

  • A hospital or Ontario Health Team procurement

    Hospital and OHT procurement typically requires a PIA and TRA summary, or a SOC 2 Type 2 report, before the contract can proceed, often timed to the 31 March hospital fiscal year-end.

  • Applying to Ontario Health's Virtual Visits Verification

    The verified-solutions list requires an attestation letter, PIA/TRA summaries and scenario testing completed within 12 months; applications are first-come, first-served with no fee, which rewards platforms that prepare early.

  • An insurer or employer benefits RFP

    Benefits renewal season clusters around 1 January, and a vendor security schedule inside an RFP forces a documented answer to questions the platform may never have written down before.

  • A US clinic or payer hands over a BAA

    The first US contract arrives with a Business Associate Agreement attached, and signing it before the safeguards and risk analysis exist creates exposure the company only discovers later.

  • A competitor's regulator finding changes the conversation

    A published investigation into another Canadian virtual-care app's launch practices makes boards and investors ask whether the same gaps exist in-house, well before any regulator has come knocking directly.

  • Cyber-insurance renewal or a sector breach

    Insurers renewing coverage for a company holding identity documents, video and clinical records ask sharper questions than a generic SaaS renewal, and a breach at a comparable platform accelerates the timeline.

Virtual Care & Telehealth Platforms: privacy & security questions, answered

A virtual care platform usually decides, or has decided for it, whether it is the custodian of the health information or a vendor serving one, and that status changes which obligations sit with the company directly versus which flow through a customer contract. A symptom-tracking app rarely carries that same fork, since it typically has no clinician relationship of its own to classify.

Resolving custodian, electronic service provider or health information network provider status comes first, because it determines which agreements, PIAs and policies are actually required. A Virtual Privacy Officer engagement is the usual starting point, with a vCISO added once hospital or Ontario Health testing enters the picture.

Provincial scope narrows the list but does not remove it. An Ontario-only platform still faces PHIPA's custodian, ESP and HINP framework and Ontario Health's verification standard if it sells to hospitals, and PIPEDA applies to the commercial relationship regardless of which province a patient sits in.

Yes. Running a clinic with contracted physicians typically makes the platform a custodian in its own right. Licensing the same technology to a hospital that employs its own clinicians usually makes the platform an electronic service provider, or a health information network provider if it links more than one custodian, with a different agreement and PIA obligation attached to each role.

The moment a US provider or payer signs you as a vendor, a Business Associate Agreement makes the platform directly liable under HIPAA's Security Rule, with its own risk analysis, safeguards and 60-day breach notification clock running alongside PHIPA, PIPEDA and any provincial obligations already in place.

Often yes, because the standard is free to apply to and the underlying work, a PIA, a TRA summary or SOC 2 Type 2, and scenario testing, is largely the same evidence a hospital or insurer will eventually ask for anyway. Completing it early turns a future procurement delay into a document you can hand over immediately.

Contracted clinicians can still count as agents under PHIPA, meaning the custodian remains responsible for their training, access controls and conduct even without an employment relationship. That responsibility needs to be built into onboarding, access provisioning and the incident response plan from the start, not treated as a contractor's separate concern.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.