Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Digital health & life sciences

Privacy & Security Policy Development for Virtual Care & Telehealth Platforms

A virtual care platform's privacy policy has to do more than a typical SaaS policy: it has to tell patients plainly what happens when a session is recorded, how identity is verified, and where their record goes if a clinic connects to a hospital network. Ontario Health's verification standard and hospital reviewers both expect this document to actually say something specific, not recite boilerplate. We write the policy, and the HINP plain-language service description alongside it, from how your platform actually handles a visit.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the policy set has to say

Patients and connected custodians both need a plain answer to specific questions this niche raises that a generic privacy policy leaves out.

Recording and session capture

Whether visits are recorded, for what purpose, how long recordings are kept, and how a patient can decline or ask that a recording be deleted.

Identity verification during onboarding

What identity documents or selfies are collected, why, and how long that data is retained after verification is complete, sized to avoid collecting more than the visit actually needs.

Cross-border and sub-processor disclosure

Plain disclosure that video, transcription or support functions may run through US-based sub-processors, since most platforms host primarily in Canada but rely on cross-border vendors for specific functions.

Asynchronous versus live-visit handling

Separate, clear explanations for how a symptom-triage questionnaire, an asynchronous consult and a live video visit each collect and use information, since the three flows are not interchangeable.

Patient access and correction rights

A clear process for a patient to request their own record, ask for a correction, or understand how a chart is shared with a pharmacy or referred specialist.

Regulatory map

What regulators and reviewers expect the policy to reflect

Two distinct sources shape what this document needs to say: provincial guidance on virtual visits and the HINP framework itself.

IPC guidance on virtual health care visits

Ontario's IPC guidance on privacy and security for virtual visits calls for a documented virtual-care policy, informed consent, and identity verification appropriate to the service, which shapes the structure of the patient-facing document.

Primary source →

The HINP plain-language service description

A platform linking two or more custodians must produce a plain-language description of the service under O. Reg. 329/04, a distinct document from the patient privacy policy but written to be consistent with it.

Read our guide →

College virtual-care policies constrain what the platform can offer

Physicians' college policies govern choices like recording and identity verification for the clinicians using the platform, so the patient policy needs to be checked against what contracted physicians are actually permitted to do.

Primary source →

Ontario Health verification expects the policy as evidence

A documented virtual-care privacy policy supports the attestation and PIA/TRA summary Ontario Health's verified-solutions process asks for, making this document part of the evidence package rather than a separate exercise.

Primary source →

What goes wrong

What a missing or vague policy exposes

Policy gaps in this sector have already drawn direct regulator attention, not just theoretical risk.

  • Silence on identity-data collection

    Alberta's OIPC investigation into Babylon by Telus Health found government ID, selfies and dates of birth collected beyond what the service needed, a pattern a clear, minimization-focused policy is built to prevent.

    Source →

  • No stated position on recording

    A policy that is silent or vague about whether and why sessions are recorded leaves both patients and contracted clinicians unclear on what consent actually covers.

  • A policy that conflicts with a college's requirements

    A patient policy promising something a contracted physician's college policy does not permit creates a gap that surfaces during a complaint or an audit, not before.

  • A stale policy after adding a province or a hospital partner

    A policy written for a single-province clinic that is not updated once the platform connects to a hospital or expands into Alberta or BC no longer describes what actually happens to a patient's information.

Our policy development for virtual care & telehealth platforms

What our policy development covers for a virtual care platform

Documents built around how your platform actually delivers care, not a template with the logo swapped.

UX designer creative group working about planing mobile application project with sticky notes. User experience concept
  1. Patient-facing privacy policy

    A policy covering recording, identity verification, cross-border sub-processors, asynchronous versus live care, and patient access rights, written in language a patient can actually follow.

  2. HINP plain-language service description

    Where the platform connects multiple custodians, a description written to satisfy O. Reg. 329/04 and consistent with the patient policy it sits alongside.

  3. Consent flow copy

    In-product language for the moment a patient consents to a recorded session or to identity verification, reviewed against what the policy promises.

  4. Staff and clinician data-handling guidance

    A companion document that tells contracted clinicians and support staff what the patient-facing policy commits to, so practice matches what patients were told.

  5. Ongoing update support

    Revisions as the platform adds a clinic, a province or a hospital partner, so the policy set stays accurate rather than becoming outdated documentation nobody trusts.

How the engagement runs

How we develop the policy set

Built to reflect your actual intake, consent and recording practices from the start.

  1. Step 1

    Review current practices

    We walk through how a visit actually happens today, from identity verification through recording decisions to how a chart moves to a pharmacy or a referred specialist.

  2. Step 2

    Check alignment with college and HINP obligations

    We confirm the draft matches what contracted physicians' colleges permit and, where relevant, what a HINP service description needs to say.

  3. Step 3

    Draft the policy set

    The patient-facing policy, service description and staff guidance are drafted together so all three tell the same story.

  4. Step 4

    Publish and train

    The final policy is published in-product and handed to staff, often paired with training so contracted clinicians and support agents understand what it commits to.

What it costs

What shapes policy development cost here

Cost depends on how many care models the platform supports, live video, asynchronous consult, remote monitoring, how many provinces it operates in, and whether a HINP service description is needed alongside the patient policy. A single-service, single-province clinic needs less scoping than a platform running several care models across multiple hospital partnerships.

Policy development is often delivered as part of a broader privacy program, alongside training and ongoing review inside a Virtual Privacy Office retainer, which keeps the documents current as the platform grows. We quote the initial build after reviewing your current care models and jurisdictions.

Virtual Care & Telehealth Platforms: Policy development questions, answered

It needs to state plainly whether visits are recorded, the purpose of any recording, how long it is retained, who can access it, and how a patient can decline or request deletion. Ontario's IPC guidance treats this as a core element of an adequate virtual-care privacy policy, not an optional detail.

Both apply, and they need to be consistent. Your platform policy governs how the technology handles data, while the physician's college policy governs their clinical and professional obligations around identity verification, recording and record-keeping. A conflict between the two puts contracted physicians in an awkward position, which is why the two need to be checked against each other before publishing.

It points to a documented virtual-care policy, informed patient consent, identity verification appropriate to the service, and vendor selection measured against Ontario Health's standard. A policy built around those elements answers most of what a hospital or Ontario Health reviewer will ask to see.

The service description is a specific document O. Reg. 329/04 requires when the platform links two or more custodians, aimed at explaining the shared service to those custodians and their patients. The privacy policy is broader and speaks directly to every patient using the platform. They need to align but serve different audiences and purposes.

Yes, because the two flows collect and use information differently. An asynchronous consult often relies more heavily on a written questionnaire, while a live visit centres on video and, in some cases, recording. Treating them identically in the policy leaves patients unclear on what actually happens during the kind of visit they chose.

Review it whenever the platform adds a province, a hospital or insurer partner, a new care model, or a new sub-processor that touches patient data. A policy reviewed only once a year can fall out of date quickly in a business that adds partnerships and jurisdictions as often as this sector does.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.