New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Digital health & life sciences
Privacy & Security for Virtual Care & Telehealth Platforms
A virtual care platform sits in an unusual spot: depending on how clinicians are engaged, the company can be the custodian of the health information itself, not merely a vendor serving one. That single determination shapes every policy, agreement and audit that follows, and it changes again the moment the platform licenses its technology to a hospital or crosses into the US. We build the privacy and security program around that fork, sized to a team that is often 15 to 300 people with a largely contracted clinical workforce.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Founders, medical directors and the part-time counsel or compliance director who ends up owning privacy at a Canadian direct-to-patient video, messaging or asynchronous-consult platform, plus the CTOs and VPs of Sales who get pulled in once a hospital questionnaire or an insurer RFP lands.
Platforms that both run their own clinic and license the underlying technology to hospitals, Ontario Health Teams or employer benefits programs, which means answering to patients, regulators and enterprise procurement teams at the same time.
Teams whose clinicians are largely independent contractors rather than employees, which complicates who counts as an 'agent' under PHIPA and who is responsible for training, access logs and consent at the point of care.
Companies planning a first sale into the US, where a signed Business Associate Agreement turns a Canadian software company into a party directly liable for the safeguards a US covered entity expects.

Services
Privacy & security services for virtual care & telehealth platforms
Each service below is scoped for how virtual care & telehealth platforms actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Virtual Care & Telehealth Platforms
A vCISO who builds the security roadmap a telehealth platform needs to pass Ontario Health verification, hospital TRAs and enterprise scrutiny at once.
Virtual Privacy Officer
Virtual Privacy Officer for Virtual Care & Telehealth Platforms
A Virtual Privacy Officer who resolves custodian, ESP or HINP status under PHIPA and runs the multi-province PIA calendar a telehealth platform needs.
Penetration Testing
Penetration Testing for Virtual Care & Telehealth Platforms
Penetration testing scoped to a telehealth platform's video/WebRTC layer, patient mobile app and EMR integrations, sized for hospital procurement.
Incident Response Planning
Incident Response Planning for Virtual Care & Telehealth Platforms
One incident response plan for a virtual care platform that reconciles PHIPA notification, Alberta's HIA, PIPEDA and BAA breach clocks running together.
Privacy & Security Policy Development
Privacy & Security Policy Development for Virtual Care & Telehealth Platforms
Patient-facing privacy policies and HINP service descriptions for virtual care platforms, covering recording, consent and identity verification.
Privacy & Security Training
Privacy & Security Training for Virtual Care & Telehealth Platforms
Role-specific PHIPA training for a telehealth platform's contracted clinicians, support agents and sales staff answering security questionnaires.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Virtual Care & Telehealth Platforms
Answer a hospital, health authority or insurer's vendor security questionnaire with accurate, reusable evidence, including US sub-processor disclosures.
SOC 2 Readiness
SOC 2 Readiness for Virtual Care & Telehealth Platforms
SOC 2 Type 2 readiness built for Ontario Health's verified-solutions path, covering video, EMR-integration and sub-processor controls a telehealth report needs.
ISO 27001 Readiness
ISO 27001 Readiness for Virtual Care & Telehealth Platforms
ISO 27001 certification built around a virtual care platform's dual structure: the clinic it operates and the software it licenses to hospitals.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Virtual Care & Telehealth Platforms
An AI Privacy Impact Assessment for a virtual care platform's symptom-checker or triage tool, covering data collection, bias and escalation to a clinician.
HIPAA Readiness
HIPAA Readiness for Virtual Care & Telehealth Platforms
HIPAA readiness for a Canadian telehealth platform entering the US: BAA obligations, the 60-day breach clock, and FTC exposure for direct-to-consumer apps.
What you hold
What has to be governed across a virtual care platform
The data set is wider than a typical health app because identity proofing, live video and clinical records all pass through the same product in real time.
Identity documents and selfies
Government ID and selfie images collected during patient verification sit alongside clinical data, yet they are frequently over-collected relative to what the visit actually requires.
Live video, audio and any recordings
The video stack itself, whether Twilio, Vonage or a similar provider, and any decision to record a session for clinical or training purposes, each carry separate consent and retention questions.
Prescriptions, e-fax logs and lab requisitions
Prescriptions routed through PrescribeIT, pharmacy fax gateways and lab requisitions feeding OLIS create paper-like trails inside a digital product, with their own misdirection risk.
OHIP, RAMQ and AHCIP numbers with claims data
Provincial health numbers and billing codes travel alongside clinical notes, employer or insurer eligibility files, and mental-health notes that deserve tighter handling than general intake data.
The EMR and its integrations
Whether the platform runs on TELUS CHR, PS Suite, Accuro or OSCAR Pro, integrations into OTNhub, eConsult and ConnectingOntario extend the environment well past the company's own servers.
Regulatory map
The regulatory fork that shapes everything else
Which regime applies, and how much of it applies directly to the company rather than through a contract, depends on a status question most platforms answer wrong on day one.
Custodian, ESP or HINP under PHIPA
A platform employing or contracting clinicians is usually itself a health information custodian, or acts through custodian physicians; a pure technology supplier is an electronic service provider, and a platform linking two or more custodians becomes a health information network provider with prescribed duties under O. Reg. 329/04.
Alberta's HIA requires a PIA before launch
Custodians in Alberta must submit a privacy impact assessment to the OIPC before implementing a new health information system, a requirement a Canadian virtual-care app has already been found to have skipped.
BC's FIPPA reaches health authority deployments
Where a BC health authority is involved as a public body, its PIA, breach-notice and out-of-Canada disclosure duties under FIPPA apply on top of whatever the platform company owes under BC's private-sector law.
Quebec's Law 25 layers on project-level assessments
Serving Quebec patients brings project PIAs, cross-border transfer assessments and an incident register into scope, on top of any obligations under Quebec's health-information Act for services delivered to health bodies.
PIPEDA sets the federal floor
The commercial relationship with the patient is governed by PIPEDA regardless of provincial status, including mandatory breach reporting to the OPC on the real-risk-of-significant-harm standard.
HIPAA arrives the moment a US contract is signed
Serving a US provider or payer makes the platform a business associate under a signed BAA, with its own risk-analysis, safeguard and 60-day breach-notification mechanics running alongside the Canadian regime.
What goes wrong
How virtual care platforms actually end up in front of a regulator
The incidents that matter to this niche are mostly about what gets collected and disclosed, not exotic attacks.
Launching before the PIA is done
Alberta's OIPC investigated Babylon by Telus Health and published 31 findings, including that it launched without the required HIA privacy impact assessments and over-collected government ID, selfies and dates of birth.
Marketing pixels on intake and booking pages
Ad-tech and analytics pixels placed on a mental-health intake or booking flow can share sensitive visit information with third parties, the pattern the FTC pursued against BetterHelp.
Credential stuffing on patient accounts
Consumer-facing health accounts without enforced multi-factor authentication are attractive credential-stuffing targets, the gap the OPC's joint 23andMe investigation identified alongside weak breach detection.
A sub-processor incident triggering three regimes at once
A breach at a video, transcription or CRM vendor can trigger PHIPA notification, PIPEDA's reporting duty and a BAA's contractual clock simultaneously, depending on which patients and provinces it touches.
Insider snooping by contracted clinicians or support staff
Unauthorized access by contracted clinicians or call-centre agents into records outside their assigned patients is the conduct behind Ontario's first administrative monetary penalties under PHIPA.
Ransomware against the EMR or back office
A platform built for 24-hour availability loses that promise the moment ransomware locks the EMR or scheduling system, turning a security incident into a service outage patients notice immediately.
When organisations call us
When a virtual care platform actually picks up the phone
Most engagements start with a deadline someone else set, not an internal decision to get ahead of compliance.
A hospital or Ontario Health Team procurement
Hospital and OHT procurement typically requires a PIA and TRA summary, or a SOC 2 Type 2 report, before the contract can proceed, often timed to the 31 March hospital fiscal year-end.
Applying to Ontario Health's Virtual Visits Verification
The verified-solutions list requires an attestation letter, PIA/TRA summaries and scenario testing completed within 12 months; applications are first-come, first-served with no fee, which rewards platforms that prepare early.
An insurer or employer benefits RFP
Benefits renewal season clusters around 1 January, and a vendor security schedule inside an RFP forces a documented answer to questions the platform may never have written down before.
A US clinic or payer hands over a BAA
The first US contract arrives with a Business Associate Agreement attached, and signing it before the safeguards and risk analysis exist creates exposure the company only discovers later.
A competitor's regulator finding changes the conversation
A published investigation into another Canadian virtual-care app's launch practices makes boards and investors ask whether the same gaps exist in-house, well before any regulator has come knocking directly.
Cyber-insurance renewal or a sector breach
Insurers renewing coverage for a company holding identity documents, video and clinical records ask sharper questions than a generic SaaS renewal, and a breach at a comparable platform accelerates the timeline.
Virtual Care & Telehealth Platforms: privacy & security questions, answered
A virtual care platform usually decides, or has decided for it, whether it is the custodian of the health information or a vendor serving one, and that status changes which obligations sit with the company directly versus which flow through a customer contract. A symptom-tracking app rarely carries that same fork, since it typically has no clinician relationship of its own to classify.
Resolving custodian, electronic service provider or health information network provider status comes first, because it determines which agreements, PIAs and policies are actually required. A Virtual Privacy Officer engagement is the usual starting point, with a vCISO added once hospital or Ontario Health testing enters the picture.
Provincial scope narrows the list but does not remove it. An Ontario-only platform still faces PHIPA's custodian, ESP and HINP framework and Ontario Health's verification standard if it sells to hospitals, and PIPEDA applies to the commercial relationship regardless of which province a patient sits in.
Yes. Running a clinic with contracted physicians typically makes the platform a custodian in its own right. Licensing the same technology to a hospital that employs its own clinicians usually makes the platform an electronic service provider, or a health information network provider if it links more than one custodian, with a different agreement and PIA obligation attached to each role.
The moment a US provider or payer signs you as a vendor, a Business Associate Agreement makes the platform directly liable under HIPAA's Security Rule, with its own risk analysis, safeguards and 60-day breach notification clock running alongside PHIPA, PIPEDA and any provincial obligations already in place.
Often yes, because the standard is free to apply to and the underlying work, a PIA, a TRA summary or SOC 2 Type 2, and scenario testing, is largely the same evidence a hospital or insurer will eventually ask for anyway. Completing it early turns a future procurement delay into a document you can hand over immediately.
Contracted clinicians can still count as agents under PHIPA, meaning the custodian remains responsible for their training, access controls and conduct even without an employment relationship. That responsibility needs to be built into onboarding, access provisioning and the incident response plan from the start, not treated as a contractor's separate concern.
Related industries
Answers & guides
- How do you prepare for a hospital or healthcare vendor security and privacy review?
- Does HIPAA apply to my software or business?
- What is PIPEDA, and does it apply to my business?
- What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?
- PIA vs TRA: which assessment do you need (or do you need both)?
- What a SaaS Vendor Needs Before Selling Into Canadian Healthcare
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.