Who we are
AnonHealth is a virtual care platform that connects patients in Canada with licensed healthcare providers. For patients in Ontario, the treating clinic acts as a Health Information Custodian under the Personal Health Information Protection Act, 2004 (PHIPA); AnonHealth acts as its electronic service provider and agent. Federally and in provinces without health-privacy legislation, we handle personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA).
What we collect
Account data, name, email, date of birth, province of residence, password hash.
Health data, reason for visit, symptoms, intake responses, clinical notes, prescriptions, lab requisitions, and messages exchanged with your provider.
Operational data, appointment times, timezone, device and browser metadata, IP addresses, and audit records of who accessed which record.
Payment data, processed by our payment provider; we retain transaction references, not full card numbers.
How we use it
Under PIPEDA and PHIPA, we use personal and personal health information only to:
- Deliver the healthcare services you request;
- Communicate about appointments, results, and follow-up care;
- Verify the identity of providers and confirm they are licensed in the province where you receive care;
- Maintain records required by applicable regulatory colleges and provincial law;
- Protect the security and integrity of the platform.
Who sees your information
Your treating provider and, when clinically necessary, other members of the circle of care access your record. Employers who sponsor coverage receive aggregated, de-identified utilization metrics only, never individual medical information. We do not sell personal information and do not use it for advertising.
Where data is stored
Records are stored in Canadian data centres (ca-central-1). Video and messaging run through vendors that support Canadian data residency. We may use service providers outside Canada for narrow operational purposes (e.g. transactional email delivery); those transfers are covered by contractual safeguards.
Retention
Clinical records are retained for at least 10 years after the last patient contact (or, for minors, 10 years after the age of majority) in line with PHIPA and provincial regulatory college requirements. Account records are kept while your account is active and deleted or anonymized within 90 days of account closure, except where longer retention is required by law.
Your rights
You have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate information;
- Withdraw consent to future collection or use where the law permits;
- Request deletion, subject to our legal obligation to retain clinical records;
- File a complaint with the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario.
Submit any of these requests through our data-request form.
Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based and every access to a record is written to an audit log. Providers with elevated privileges are required to enable multi-factor authentication. We publish and follow a breach-response process aligned with PHIPA s.12(2) mandatory reporting.
Contact
Privacy Officer, AnonHealth Inc., info@anonhealth.ca.
