VPO · Digital health & life sciences
Virtual Privacy Officer for Virtual Care & Telehealth Platforms
A Virtual Privacy Officer settles the question that decides everything else for a telehealth platform: whether the company is itself a health information custodian, an electronic service provider, or a health information network provider under PHIPA. That classification usually gets revisited every time a new clinic, hospital or province enters the picture, which is why this is ongoing work, not a one-time memo. We run the classification, the resulting agreements and the province-by-province PIA calendar as one program.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a telehealth VPO manages day to day
The role sits between the company's contracts, its clinical operations and every provincial regulator with a stake in the answer.
The custodian, ESP or HINP classification per relationship
Status can differ contract by contract: the company might be the custodian for its own clinic, an ESP for a hospital's platform licence, and a HINP the moment it links two custodians together.
Consent and identity-verification practices
How patients are told about recording, data sharing and identity checks, and whether the identity-proofing step collects only what the visit actually requires.
The multi-province PIA and TRA calendar
Alberta, BC and Quebec each attach their own assessment or filing obligation to a new system or expansion, and the calendar has to track deadlines across all of them at once.
Contracted clinicians as PHIPA agents
Whether nurse practitioners, physicians and support staff are employees or contractors, their access, training and conduct still sit under the custodian's responsibility.
Vendor and sub-processor data agreements
Data processing terms with the video vendor, identity-verification service, EMR platform and CRM tool need to match the classification the platform actually holds.
The breach and incident register
A running record of incidents, reportable or not, kept in the form each applicable regulator expects and ready to produce on request.
Regulatory map
The classification framework a telehealth VPO applies
PHIPA sets three distinct roles for a platform, and each one carries a different set of duties.
Custodian status when clinicians are engaged directly
A platform that employs or contracts clinicians is generally a health information custodian in its own right, carrying the full range of PHIPA obligations rather than a vendor's narrower ones.
ESP status for pure technology supply
A platform that only supplies technology to a custodian's clinicians is an electronic service provider, which may not use the personal health information except as necessary to provide the service.
HINP duties once two or more custodians connect
Linking multiple custodians triggers prescribed duties under O. Reg. 329/04: a plain-language description of the service, a PIA, a TRA, written agreements with each custodian, and access logs.
Alberta's pre-launch PIA filing
A custodian operating in Alberta must submit a PIA to the OIPC before implementing a new health information system, a step that has to be planned into the launch timeline, not treated as a formality after go-live.
BC and Quebec add their own project-level assessments
A BC health authority deployment brings FIPPA's PIA and disclosure requirements, and any Quebec patient brings Law 25's project PIAs and cross-border transfer assessments into scope.
What goes wrong
What the classification work is meant to prevent
Getting the status question wrong, or skipping the paperwork it triggers, is exactly what has drawn regulator attention in this sector already.
Launching without the required PIA
Alberta's OIPC found that Babylon by Telus Health launched without the HIA privacy impact assessments its custodian status required, one of 31 findings in the published investigation.
Collecting more identity data than the role justifies
The same investigation found government ID, selfies and dates of birth collected beyond what the service needed, an over-collection problem a clear classification and data-minimization review would have caught earlier.
Signing the wrong agreement for the actual role
A platform that is really a HINP but signs only an ESP-style vendor agreement leaves the plain-language description, PIA and access-log duties undone, a gap a hospital's own privacy office will eventually notice.
Losing track of status as the company scales
A platform that starts as an ESP for one hospital and later begins employing clinicians directly needs its classification re-assessed, since the old agreements no longer describe the current relationship.
Our vpo for virtual care & telehealth platforms
What our VPO service delivers for a virtual care platform
The engagement produces the classification, the agreements and the ongoing calendar a growing platform needs to stay current.

Custodian, ESP or HINP determination
A documented assessment of the platform's status for each clinic, hospital and insurer relationship, reviewed again whenever a new contract or province enters the picture.
PIA and TRA program management
Coordination of the assessments each relevant province requires, sequenced against launch dates and procurement deadlines rather than done after the fact.
HINP agreements and service descriptions
Drafting or reviewing the plain-language service description and written agreements O. Reg. 329/04 requires when the platform connects more than one custodian.
Consent and identity-verification policy review
A check of what patients are told and what identity data is actually collected, sized to avoid the over-collection pattern regulators have already flagged in this sector.
Contractor clinician training oversight
A program that treats contracted clinicians and support agents as PHIPA agents, with training and access review that does not depend on an employment relationship.
Vendor and sub-processor compliance monitoring
Ongoing review of data agreements with the video, identity-verification, EMR and CRM vendors the platform depends on, kept aligned with the platform's current classification.
How the engagement runs
How the VPO engagement runs
The work starts with the classification question and builds outward into the calendar and agreements it drives.
Step 1
Classify each relationship
We review how clinicians are engaged and how the platform connects to hospitals or clinics to determine custodian, ESP or HINP status for each one.
Step 2
Map data flows and jurisdictions
We identify which provinces the platform's patients and partners sit in, since that determines which PIA and filing obligations apply.
Step 3
Build the PIA and TRA calendar
Assessments are scheduled against real deadlines, launch dates, procurement cycles and Ontario Health verification windows, so nothing is done as an afterthought.
Step 4
Draft or review agreements
HINP written agreements, plain-language descriptions and vendor DPAs are drafted or reviewed to match the classification the platform actually holds.
Step 5
Maintain the program
The VPO revisits classification and the calendar as the platform adds clinics, provinces or a US customer, keeping the program current rather than static.
What it costs
What shapes VPO cost for a virtual care platform
Cost depends on how many custodian relationships the platform holds, how many provinces its patients and partners sit in, whether HINP status applies, and how many vendor agreements need review. A platform in Ontario only, licensing to one hospital, needs a lighter program than one running clinics in three provinces and connecting several health authorities.
The Virtual Privacy Office plan starts at $2,200 CAD per month and includes coaching hours, an incident management protocol, review of policies and agreements, and training and human risk assessments, which map directly onto this classification and PIA work. We scope exact hours after reviewing current contracts.
Virtual Care & Telehealth Platforms: VPO questions, answered
It depends on how your clinicians are engaged. If the platform employs or contracts the clinicians providing care, it is generally the custodian, or acts through custodian physicians. If it only supplies the technology to clinicians employed by someone else, it is an electronic service provider, with the narrower duty to use personal health information only as necessary to provide the service.
The platform, as the health information network provider, signs a written agreement with each connected custodian and prepares the PIA and TRA covering the shared service, alongside a plain-language description each custodian can give its own patients. A VPO typically drafts these documents and coordinates sign-off across every connected clinic.
Alberta requires custodians to submit a PIA to the OIPC before implementing a new system. BC attaches PIA duties to health authority deployments under FIPPA, and Quebec's Law 25 requires project-level assessments before certain projects go live. Ontario skips regulator pre-filing but expects a PIA/TRA summary as verification evidence.
It can. Adding a hospital that employs its own clinicians and connecting it to a clinic you already run can shift the platform from a simple ESP relationship into HINP territory, since you would now be linking two custodians. Each new relationship needs its own classification check rather than assuming the prior determination still applies.
Contracted clinicians can still count as agents under PHIPA, so the VPO builds their training, access provisioning and offboarding into the same program used for employees, adjusted for the fact that HR processes and standard onboarding checklists often do not apply to contractors automatically.
Often the workload is lighter but still real, since the platform is likely an ESP in that scenario with its own use-limitation and agreement obligations. A VPO can confirm that classification and keep the resulting agreement current, which is usually a smaller engagement than a multi-clinic HINP program.
More for virtual care & telehealth platforms
Other services for this niche
- Privacy & security for virtual care & telehealth platforms — overview
- Virtual CISO
- Penetration Testing
- Incident Response Planning
- Privacy & Security Policy Development
- Privacy & Security Training
- Vendor Security Review & Questionnaire Support
- SOC 2 Readiness
- ISO 27001 Readiness
- AI Privacy Impact Assessment
- HIPAA Readiness
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.