Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Digital health & life sciences

Minimum Viable Privacy Program for Health Charities & Patient Organizations

Minimum Viable Privacy packages a working baseline into one program a small health charity can afford: a gap review of your donor CRM and any patient-facing program, the policies a funder or insurer actually checks, training for ten people, and twelve hours of coaching, for $5,499 CAD a year. It suits the organization that just received a funder clause, is standing up its first helpline or support group, or needs a defensible answer before campaign season, without hiring anyone.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What MVP concentrates on first at this size

A health charity this size cannot protect everything equally, so the baseline starts with the system and the determination that matter most, then works outward.

The donor CRM, still the highest-value target

Whether you run Keela, CanadaHelps or a Raiser's Edge-class platform, that one system holds constituent records and giving history, so getting its access list and settings right delivers most of the available protection first.

Whether any program crosses into custodian territory

MVP's gap review answers, in plain terms, whether your helpline or support program makes the organization a health information custodian, a determination too many small organizations have never actually made.

A named owner instead of nobody

Most organizations this size have no job title that includes privacy; MVP assigns the function, typically to the VP of Finance & Operations, and equips them to hold it.

Volunteer access to sensitive systems

Helpline volunteers and gala committees who touch caller notes or donor lists need access limits appropriate to unpaid, high-turnover roles, not the same login every staff member gets.

A retention clock that starts on day one

Old donor spreadsheets and informal helpline notes accumulate for years with no disposal rule; the baseline sets a first retention schedule to work from.

Regulatory map

The compliance floor MVP clears for a small health charity

Before any control gets built, MVP answers the two questions most organizations this size have never actually resolved.

Whether PIPEDA applies to your donor file at all

The OPC treats core fundraising as non-commercial, so many organizations owe no federal privacy duty on their donor data at all; MVP's gap review documents that answer instead of leaving it assumed.

Read our guide →

Whether your program makes you a health information custodian

If a support program means the organization actually delivers health care, PHIPA's custodian duties attach; MVP states clearly whether that threshold is met.

Read our guide →

CASL's fundraising exemption, applied correctly

MVP's policy work confirms which of your emails qualify for the charity fundraising exemption and which still need consent, closing a common, avoidable gap.

Primary source →

A first consent framework for any program

Where a helpline or support group collects health-condition information, MVP builds a baseline consent approach even without full custodian obligations.

What goes wrong

What stays exposed without any baseline at all

Organizations that skip a baseline entirely tend to discover the gap the same few ways, none of them at a convenient time.

  • A vendor notice with nobody ready to read it

    The 2020 Blackbaud incident showed a fundraising platform's breach becomes the charity's own decision to make; without a baseline, that decision gets made for the first time under pressure.

    Source →

  • A helpline confidentiality lapse nobody trained against

    A volunteer forwarding a caller's story to personal email, with no training and no confidentiality undertaking on file, is the kind of self-inflicted incident MVP's training is built to prevent.

  • A funder question with no honest answer

    When a contribution agreement's privacy clause finally gets read closely, an organization with no policy or determination has nothing to point to, weakening the next grant conversation.

  • Wealth-screening data nobody governs

    Prospect research collected without a stated policy is the kind of file that shocks donors if it ever surfaces, whether through a leak or a routine access request.

Our mvp program for health charities & patient organizations

What the MVP year delivers for your organization

The package is fixed and sequenced so the highest-value pieces land first, built around your systems and calendar rather than a generic checklist.

Elderly man make distant video call communicating with doctor online
  1. Baseline privacy gap review

    A structured look at your donor CRM, any patient-facing program, and consent language, benchmarked against the statutes that actually apply, producing a short, ranked list rather than a lengthy audit.

  2. Prioritized control recommendations

    Directional guidance on what to fix first once the which-law and custodian-status questions are answered, chosen for impact against limited hours.

  3. Core policy development

    A starter donor privacy policy, a short volunteer confidentiality undertaking for helpline volunteers, and a retention schedule reconciling program and donor records.

  4. Readiness assessment workshops

    Working sessions with the executive director and program lead rehearsing the situation that prompted the purchase: a funder clause, a new support program, or an insurer's questionnaire.

  5. Training with ten seats

    Role-appropriate privacy and security training and human-risk assessment for up to ten people, enough to cover key fundraising, program and helpline staff at this size of organization.

  6. Twelve hours of coaching

    Expert time spent wherever the year takes you: a wealth-screening question, a helpline volunteer's confidentiality concern, or a funder's due-diligence request as it lands.

How the engagement runs

How the baseline gets built over the term

  1. Step 1

    Intake and the applicability determination

    We confirm which statutes apply to your donor file and whether any program crosses into custodian territory, so every later decision starts from a documented answer.

  2. Step 2

    Gap review and a ranked plan

    The CRM, any program intake and consent language are reviewed against that determination, producing a short list the executive director can approve in one meeting.

  3. Step 3

    Policy drafting and readiness workshops

    Core policies are drafted and refined live with your team, then rehearsed in a workshop built around the funder, program launch or insurer situation that started the engagement.

  4. Step 4

    Training rollout and coaching close-out

    The ten training seats are delivered by role, and remaining coaching hours handle whatever surfaced mid-year, ending the term with a clear view of what a larger program would add.

What it costs

What MVP costs and what your organization gets for it

Minimum Viable Privacy is $5,499 CAD per year, billed annually on a twelve-month term, and covers the gap review, core policy development, readiness assessment workshops, twelve hours of coaching, and training with human-risk assessments for ten seats. The price is fixed and published, so a treasurer or board can approve it without a procurement process.

Organizations that outgrow it, typically by launching a patient registry, meeting the health information custodian threshold, or facing recurring hospital-partner due diligence, usually move to the Virtual Privacy Office retainer once the MVP year ends, and everything built during MVP carries forward.

Health Charities & Patient Organizations: MVP program questions, answered

Five things, sized to the organization: a named owner, usually the VP of Finance & Operations; a documented answer to which privacy law applies to your donor data and whether any program crosses into custodian territory; a short policy set covering donor privacy, program consent and volunteer confidentiality; basic CRM access controls; and trained staff and volunteers. That is what MVP delivers across its term, without a hire or a large consulting budget.

MFA on the donor CRM and email; a defined, tiered access list for staff and volunteers; a written incident response contact list, even a short one; a confirmed answer on whether any list activity has turned commercial under PIPEDA; and a ten-minute training refresher on gift-redirection fraud for finance and development staff. These five cover the failure modes that actually recur in this sector's campaign-season incidents.

MVP's gap review covers both: it determines whether your registry or support program makes the organization a health information custodian, and builds baseline consent language for that program even where custodian status does not apply. A large or research-linked registry with multiple data-sharing partners typically outgrows MVP's scope and is better served by the Virtual Privacy Office, but the baseline determination happens either way.

Yes, and it is a common profile for the program. MVP's ten training seats can prioritize helpline volunteer leads and core staff, its policy work produces the volunteer confidentiality undertaking your helpline needs, and the gap review specifically checks helpline note-handling and access. Organizations with volunteer counts well beyond what ten training seats can directly reach usually add training capacity as a scoped addition.

Nothing is wasted. A registry that starts sharing data with a research partner typically needs a data-sharing agreement, REB-aware consent language and closer vendor oversight than MVP's fixed scope covers, which is when organizations step up to the Virtual Privacy Office. Every policy, schedule and determination produced during MVP transfers directly into that retainer rather than being redone.

For organizations in the five-to-fifty-staff range with one core donor system and a modest program footprint, yes, that is exactly the profile MVP is built for. Organizations running a hospital-foundation relationship, a large registry, or operations across several provinces typically need broader scope than the fixed MVP package covers and move directly to a Virtual Privacy Office engagement instead.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.