Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

VPO · Digital health & life sciences

Virtual Privacy Officer for Virtual Care & Telehealth Platforms

A Virtual Privacy Officer settles the question that decides everything else for a telehealth platform: whether the company is itself a health information custodian, an electronic service provider, or a health information network provider under PHIPA. That classification usually gets revisited every time a new clinic, hospital or province enters the picture, which is why this is ongoing work, not a one-time memo. We run the classification, the resulting agreements and the province-by-province PIA calendar as one program.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a telehealth VPO manages day to day

The role sits between the company's contracts, its clinical operations and every provincial regulator with a stake in the answer.

The custodian, ESP or HINP classification per relationship

Status can differ contract by contract: the company might be the custodian for its own clinic, an ESP for a hospital's platform licence, and a HINP the moment it links two custodians together.

Consent and identity-verification practices

How patients are told about recording, data sharing and identity checks, and whether the identity-proofing step collects only what the visit actually requires.

The multi-province PIA and TRA calendar

Alberta, BC and Quebec each attach their own assessment or filing obligation to a new system or expansion, and the calendar has to track deadlines across all of them at once.

Contracted clinicians as PHIPA agents

Whether nurse practitioners, physicians and support staff are employees or contractors, their access, training and conduct still sit under the custodian's responsibility.

Vendor and sub-processor data agreements

Data processing terms with the video vendor, identity-verification service, EMR platform and CRM tool need to match the classification the platform actually holds.

The breach and incident register

A running record of incidents, reportable or not, kept in the form each applicable regulator expects and ready to produce on request.

Regulatory map

The classification framework a telehealth VPO applies

PHIPA sets three distinct roles for a platform, and each one carries a different set of duties.

Custodian status when clinicians are engaged directly

A platform that employs or contracts clinicians is generally a health information custodian in its own right, carrying the full range of PHIPA obligations rather than a vendor's narrower ones.

Read our guide →

ESP status for pure technology supply

A platform that only supplies technology to a custodian's clinicians is an electronic service provider, which may not use the personal health information except as necessary to provide the service.

Read our guide →

HINP duties once two or more custodians connect

Linking multiple custodians triggers prescribed duties under O. Reg. 329/04: a plain-language description of the service, a PIA, a TRA, written agreements with each custodian, and access logs.

Primary source →

Alberta's pre-launch PIA filing

A custodian operating in Alberta must submit a PIA to the OIPC before implementing a new health information system, a step that has to be planned into the launch timeline, not treated as a formality after go-live.

Primary source →

BC and Quebec add their own project-level assessments

A BC health authority deployment brings FIPPA's PIA and disclosure requirements, and any Quebec patient brings Law 25's project PIAs and cross-border transfer assessments into scope.

Primary source →

What goes wrong

What the classification work is meant to prevent

Getting the status question wrong, or skipping the paperwork it triggers, is exactly what has drawn regulator attention in this sector already.

  • Launching without the required PIA

    Alberta's OIPC found that Babylon by Telus Health launched without the HIA privacy impact assessments its custodian status required, one of 31 findings in the published investigation.

    Source →

  • Collecting more identity data than the role justifies

    The same investigation found government ID, selfies and dates of birth collected beyond what the service needed, an over-collection problem a clear classification and data-minimization review would have caught earlier.

  • Signing the wrong agreement for the actual role

    A platform that is really a HINP but signs only an ESP-style vendor agreement leaves the plain-language description, PIA and access-log duties undone, a gap a hospital's own privacy office will eventually notice.

  • Losing track of status as the company scales

    A platform that starts as an ESP for one hospital and later begins employing clinicians directly needs its classification re-assessed, since the old agreements no longer describe the current relationship.

Our vpo for virtual care & telehealth platforms

What our VPO service delivers for a virtual care platform

The engagement produces the classification, the agreements and the ongoing calendar a growing platform needs to stay current.

Young man working remotely at a standing desk in his living room
  1. Custodian, ESP or HINP determination

    A documented assessment of the platform's status for each clinic, hospital and insurer relationship, reviewed again whenever a new contract or province enters the picture.

  2. PIA and TRA program management

    Coordination of the assessments each relevant province requires, sequenced against launch dates and procurement deadlines rather than done after the fact.

  3. HINP agreements and service descriptions

    Drafting or reviewing the plain-language service description and written agreements O. Reg. 329/04 requires when the platform connects more than one custodian.

  4. Consent and identity-verification policy review

    A check of what patients are told and what identity data is actually collected, sized to avoid the over-collection pattern regulators have already flagged in this sector.

  5. Contractor clinician training oversight

    A program that treats contracted clinicians and support agents as PHIPA agents, with training and access review that does not depend on an employment relationship.

  6. Vendor and sub-processor compliance monitoring

    Ongoing review of data agreements with the video, identity-verification, EMR and CRM vendors the platform depends on, kept aligned with the platform's current classification.

How the engagement runs

How the VPO engagement runs

The work starts with the classification question and builds outward into the calendar and agreements it drives.

  1. Step 1

    Classify each relationship

    We review how clinicians are engaged and how the platform connects to hospitals or clinics to determine custodian, ESP or HINP status for each one.

  2. Step 2

    Map data flows and jurisdictions

    We identify which provinces the platform's patients and partners sit in, since that determines which PIA and filing obligations apply.

  3. Step 3

    Build the PIA and TRA calendar

    Assessments are scheduled against real deadlines, launch dates, procurement cycles and Ontario Health verification windows, so nothing is done as an afterthought.

  4. Step 4

    Draft or review agreements

    HINP written agreements, plain-language descriptions and vendor DPAs are drafted or reviewed to match the classification the platform actually holds.

  5. Step 5

    Maintain the program

    The VPO revisits classification and the calendar as the platform adds clinics, provinces or a US customer, keeping the program current rather than static.

What it costs

What shapes VPO cost for a virtual care platform

Cost depends on how many custodian relationships the platform holds, how many provinces its patients and partners sit in, whether HINP status applies, and how many vendor agreements need review. A platform in Ontario only, licensing to one hospital, needs a lighter program than one running clinics in three provinces and connecting several health authorities.

The Virtual Privacy Office plan starts at $2,200 CAD per month and includes coaching hours, an incident management protocol, review of policies and agreements, and training and human risk assessments, which map directly onto this classification and PIA work. We scope exact hours after reviewing current contracts.

Virtual Care & Telehealth Platforms: VPO questions, answered

It depends on how your clinicians are engaged. If the platform employs or contracts the clinicians providing care, it is generally the custodian, or acts through custodian physicians. If it only supplies the technology to clinicians employed by someone else, it is an electronic service provider, with the narrower duty to use personal health information only as necessary to provide the service.

The platform, as the health information network provider, signs a written agreement with each connected custodian and prepares the PIA and TRA covering the shared service, alongside a plain-language description each custodian can give its own patients. A VPO typically drafts these documents and coordinates sign-off across every connected clinic.

Alberta requires custodians to submit a PIA to the OIPC before implementing a new system. BC attaches PIA duties to health authority deployments under FIPPA, and Quebec's Law 25 requires project-level assessments before certain projects go live. Ontario skips regulator pre-filing but expects a PIA/TRA summary as verification evidence.

It can. Adding a hospital that employs its own clinicians and connecting it to a clinic you already run can shift the platform from a simple ESP relationship into HINP territory, since you would now be linking two custodians. Each new relationship needs its own classification check rather than assuming the prior determination still applies.

Contracted clinicians can still count as agents under PHIPA, so the VPO builds their training, access provisioning and offboarding into the same program used for employees, adjusted for the fact that HR processes and standard onboarding checklists often do not apply to contractors automatically.

Often the workload is lighter but still real, since the platform is likely an ESP in that scenario with its own use-limitation and agreement obligations. A VPO can confirm that classification and keep the resulting agreement current, which is usually a smaller engagement than a multi-clinic HINP program.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.