Policy development · Digital health & life sciences
Privacy & Security Policy Development for Virtual Care & Telehealth Platforms
A virtual care platform's privacy policy has to do more than a typical SaaS policy: it has to tell patients plainly what happens when a session is recorded, how identity is verified, and where their record goes if a clinic connects to a hospital network. Ontario Health's verification standard and hospital reviewers both expect this document to actually say something specific, not recite boilerplate. We write the policy, and the HINP plain-language service description alongside it, from how your platform actually handles a visit.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the policy set has to say
Patients and connected custodians both need a plain answer to specific questions this niche raises that a generic privacy policy leaves out.
Recording and session capture
Whether visits are recorded, for what purpose, how long recordings are kept, and how a patient can decline or ask that a recording be deleted.
Identity verification during onboarding
What identity documents or selfies are collected, why, and how long that data is retained after verification is complete, sized to avoid collecting more than the visit actually needs.
Cross-border and sub-processor disclosure
Plain disclosure that video, transcription or support functions may run through US-based sub-processors, since most platforms host primarily in Canada but rely on cross-border vendors for specific functions.
Asynchronous versus live-visit handling
Separate, clear explanations for how a symptom-triage questionnaire, an asynchronous consult and a live video visit each collect and use information, since the three flows are not interchangeable.
Patient access and correction rights
A clear process for a patient to request their own record, ask for a correction, or understand how a chart is shared with a pharmacy or referred specialist.
Regulatory map
What regulators and reviewers expect the policy to reflect
Two distinct sources shape what this document needs to say: provincial guidance on virtual visits and the HINP framework itself.
IPC guidance on virtual health care visits
Ontario's IPC guidance on privacy and security for virtual visits calls for a documented virtual-care policy, informed consent, and identity verification appropriate to the service, which shapes the structure of the patient-facing document.
The HINP plain-language service description
A platform linking two or more custodians must produce a plain-language description of the service under O. Reg. 329/04, a distinct document from the patient privacy policy but written to be consistent with it.
College virtual-care policies constrain what the platform can offer
Physicians' college policies govern choices like recording and identity verification for the clinicians using the platform, so the patient policy needs to be checked against what contracted physicians are actually permitted to do.
Ontario Health verification expects the policy as evidence
A documented virtual-care privacy policy supports the attestation and PIA/TRA summary Ontario Health's verified-solutions process asks for, making this document part of the evidence package rather than a separate exercise.
What goes wrong
What a missing or vague policy exposes
Policy gaps in this sector have already drawn direct regulator attention, not just theoretical risk.
Silence on identity-data collection
Alberta's OIPC investigation into Babylon by Telus Health found government ID, selfies and dates of birth collected beyond what the service needed, a pattern a clear, minimization-focused policy is built to prevent.
No stated position on recording
A policy that is silent or vague about whether and why sessions are recorded leaves both patients and contracted clinicians unclear on what consent actually covers.
A policy that conflicts with a college's requirements
A patient policy promising something a contracted physician's college policy does not permit creates a gap that surfaces during a complaint or an audit, not before.
A stale policy after adding a province or a hospital partner
A policy written for a single-province clinic that is not updated once the platform connects to a hospital or expands into Alberta or BC no longer describes what actually happens to a patient's information.
Our policy development for virtual care & telehealth platforms
What our policy development covers for a virtual care platform
Documents built around how your platform actually delivers care, not a template with the logo swapped.

Patient-facing privacy policy
A policy covering recording, identity verification, cross-border sub-processors, asynchronous versus live care, and patient access rights, written in language a patient can actually follow.
HINP plain-language service description
Where the platform connects multiple custodians, a description written to satisfy O. Reg. 329/04 and consistent with the patient policy it sits alongside.
Consent flow copy
In-product language for the moment a patient consents to a recorded session or to identity verification, reviewed against what the policy promises.
Staff and clinician data-handling guidance
A companion document that tells contracted clinicians and support staff what the patient-facing policy commits to, so practice matches what patients were told.
Ongoing update support
Revisions as the platform adds a clinic, a province or a hospital partner, so the policy set stays accurate rather than becoming outdated documentation nobody trusts.
How the engagement runs
How we develop the policy set
Built to reflect your actual intake, consent and recording practices from the start.
Step 1
Review current practices
We walk through how a visit actually happens today, from identity verification through recording decisions to how a chart moves to a pharmacy or a referred specialist.
Step 2
Check alignment with college and HINP obligations
We confirm the draft matches what contracted physicians' colleges permit and, where relevant, what a HINP service description needs to say.
Step 3
Draft the policy set
The patient-facing policy, service description and staff guidance are drafted together so all three tell the same story.
Step 4
Publish and train
The final policy is published in-product and handed to staff, often paired with training so contracted clinicians and support agents understand what it commits to.
What it costs
What shapes policy development cost here
Cost depends on how many care models the platform supports, live video, asynchronous consult, remote monitoring, how many provinces it operates in, and whether a HINP service description is needed alongside the patient policy. A single-service, single-province clinic needs less scoping than a platform running several care models across multiple hospital partnerships.
Policy development is often delivered as part of a broader privacy program, alongside training and ongoing review inside a Virtual Privacy Office retainer, which keeps the documents current as the platform grows. We quote the initial build after reviewing your current care models and jurisdictions.
Virtual Care & Telehealth Platforms: Policy development questions, answered
It needs to state plainly whether visits are recorded, the purpose of any recording, how long it is retained, who can access it, and how a patient can decline or request deletion. Ontario's IPC guidance treats this as a core element of an adequate virtual-care privacy policy, not an optional detail.
Both apply, and they need to be consistent. Your platform policy governs how the technology handles data, while the physician's college policy governs their clinical and professional obligations around identity verification, recording and record-keeping. A conflict between the two puts contracted physicians in an awkward position, which is why the two need to be checked against each other before publishing.
It points to a documented virtual-care policy, informed patient consent, identity verification appropriate to the service, and vendor selection measured against Ontario Health's standard. A policy built around those elements answers most of what a hospital or Ontario Health reviewer will ask to see.
The service description is a specific document O. Reg. 329/04 requires when the platform links two or more custodians, aimed at explaining the shared service to those custodians and their patients. The privacy policy is broader and speaks directly to every patient using the platform. They need to align but serve different audiences and purposes.
Yes, because the two flows collect and use information differently. An asynchronous consult often relies more heavily on a written questionnaire, while a live visit centres on video and, in some cases, recording. Treating them identically in the policy leaves patients unclear on what actually happens during the kind of visit they chose.
Review it whenever the platform adds a province, a hospital or insurer partner, a new care model, or a new sub-processor that touches patient data. A policy reviewed only once a year can fall out of date quickly in a business that adds partnerships and jurisdictions as often as this sector does.
More for virtual care & telehealth platforms
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.