Privacy Policy
Effective Date: March 22, 2026
At Kind Physiotherapy, we are committed to protecting the privacy and confidentiality of our website visitors and patients. This policy outlines how we handle information collected through our website.
HEALTH INFORMATION PRIVACY & MANAGEMENT POLICY
Practice Name: Kind Physiotherapy
Custodian & Privacy Officer: Brianna Chan, Registered Physiotherapist
Effective Date: March 22, 2026
Last Revised: September 7, 2026
1. PURPOSE & LEGISLATIVE AUTHORITY
This policy outlines the administrative, technical, and physical safeguards governing the collection, use, disclosure, retention, and secure disposal of health information at Kind Physiotherapy Inc.
This policy operates under the authority of and in full compliance with:
-
Health Information Act (HIA) (Alberta)
-
Health Information Regulation (HIR) (Alberta)
-
College of Physiotherapists of Alberta (CPTA) Standards of Practice
As the sole owner and practitioner, Brianna Chan serves as both the Custodian and the designated Privacy Officer responsible for ensuring clinic compliance.
2. COLLECTION OF HEALTH INFORMATION
-
Principle of Least Amount Necessary: The clinic collects only the health and demographic information necessary to provide physiotherapy assessment, treatment, care planning, billing, and practice administration.
-
Notification at Collection: At or before the time of collection, patients are informed of:
-
The purpose for collecting their health information.
-
The legal authority under the HIA authorizing collection.
-
Contact information for the Privacy Officer to answer questions.
-
-
Direct Collection: Information is collected directly from the patient unless indirect collection (e.g., physician referral, insurer report) is authorized by the patient or permitted under HIA Section 22.
3. USE OF HEALTH INFORMATION
-
Authorized Uses: Individually identifying health information is used solely for:
-
Providing physiotherapy treatment and related health services.
-
Internal management, quality assurance, and practice auditing.
-
Obtaining payment or processing billing claims for services provided.
-
-
Limitation: Health information will not be used or processed for any purpose outside direct patient care or clinic administration without express consent or explicit HIA authorization.
4. ACCESS CONTROLS & AUDIT POLICY
-
Role-Based Access Control (RBAC): Only authorized staff accessing records for direct clinical care or administrative necessity may access patient files. Implementation of strict RBAC roles is enforced within Jane App.
-
Prohibition of Browsing: There is an absolute operational prohibition against accessing or browsing records of non-assigned patients out of curiosity or without clinical necessity.
-
Audit Logs: Automated audit trails are active in Jane App to log all record accesses, modifications, and exports. Routine access log audits are conducted to monitor system activity.
-
Training: Annual privacy training and compliance reviews are mandatory.
5. PHYSICAL & TECHNICAL SAFEGUARDS POLICY
Pursuant to Section 8 of the Health Information Regulation, the Custodian implements robust safeguards to defend against external cyber threats, hacking, credential theft, or unauthorized visual access:
-
Multi-Factor Authentication (MFA): Enforced MFA across all systems and primary clinical software (Jane App).
-
Session Security: Automatic system screen-lock triggers after a maximum of 15 minutes of inactivity.
-
Visual Privacy: Visual privacy screens are installed on device screens at reception and on all portable devices to prevent shoulder-surfing.
-
Encryption: Technical safeguards enforce AES-256 encryption at rest and TLS 1.3 encryption in transit for all electronic health data.
-
Physical Controls: Clinic premises and file storage areas are locked when unattended. Workstations are positioned away from public sightlines.
6. CLINICAL DOCUMENTATION & CHARTING INTEGRITY POLICY
To prevent loss of data integrity, accidental overwriting, improper editing, or unauthorized alteration of clinical charts:
-
Immutable Audit Trails: Jane App maintains immutable audit trails recording every entry, revision, and edit timestamp.
-
Timestamped Charting: All clinical notes are signed and timestamped electronically upon completion.
-
Credential Management: Strict user credential management is enforced. Account credentials and logins shall never be shared.
7. DISCLOSURE OF HEALTH INFORMATION
-
Express Consent Requirements: Written patient consent is required prior to disclosing health information to third parties, except where non-consent disclosure is authorized by HIA (e.g., Section 35 circle-of-care disclosures or legal obligations).
8. BUSINESS CONTINUITY: DATA RETENTION & RECOVERY PLAN
To protect against technical failure, ransomware, or physical disaster causing loss or unavailability of critical patient records:
-
Automated Encrypted Backups: Automated daily encrypted backups are performed and stored in secure Canadian AWS data centers (Montreal).
-
Disaster Recovery Procedures: Jane Software Inc. hosts data on secure, SOC 2-audited AWS servers located in Canada (Montreal/Calgary). Jane maintains an active Disaster Recovery Plan incorporating multi-availability zone automated backups (daily, weekly, monthly, yearly) encrypted both in transit and at rest. Testing of recovery from backups is routinely performed by Jane. In the event of clinic closure or subscription termination, full batch data exports are performed to ensure compliance with Alberta record retention standards.
9. VENDOR MANAGEMENT POLICY: THIRD-PARTY AGREEMENTS
To mitigate third-party vendor risks (e.g., software vendors mishandling data or suffering external breaches):
-
Information Manager Agreements (IMAs): An executed HIA Section 66 Information Manager Agreement (IMA) must be in place prior to engaging any health software or cloud vendor (including Jane Software Inc.).
-
Data Residency: Mandatory Canadian data residency is contractually required for all primary and backup servers hosting clinic health data (e.g., Montreal, Canada).
-
Breach Notification Clause: All vendor contracts must include an immediate breach notification clause requiring prompt notification to the Custodian upon discovery of any real or suspected security incident.
10. MOBILE DEVICE & PORTABLE HARDWARE POLICY
This policy governs the secure use of all mobile devices—including laptops, tablets, smartphones, and external storage media—used to access or process clinic health information:
-
Authorized Devices Only: Health information may only be accessed on hardware officially designated and secured by the Custodian. Personal or unencrypted third-party devices are strictly prohibited from connecting to or storing clinic health data.
-
Mandatory Full-Disk Encryption: All mobile hardware (laptops, tablets, smartphones) must have full-disk encryption enabled (e.g., BitLocker, FileVault, or native iOS/Android hardware encryption) using AES-256 standards.
-
Biometric / Passcode Protection: Devices must be secured with a strong passphrase or biometric control (Face ID / Fingerprint). Simple 4-digit PINs are prohibited.
-
Prohibition of Local Storage: Patient records, clinical notes, and health photos must be captured, charted, and stored directly inside the EMR (Jane App). Saving patient health information to local camera rolls, local computer download folders, unencrypted USB drives, or personal cloud storage (e.g., iCloud, Google Drive) is strictly prohibited.
-
Public Network Access: When accessing Jane App or clinic email outside the clinic physical premises, mobile devices must connect via an encrypted cellular network or a secure Virtual Private Network (VPN). Unsecured public Wi-Fi networks (e.g., coffee shops, airports) must never be used without an active VPN.
-
Remote Wipe & Theft Protocols:
-
All mobile devices must have "Find My Device" and remote wipe capabilities enabled.
-
In the event of a lost or stolen mobile device, the Custodian will execute a remote wipe immediately and follow the Breach Notification & Incident Management Protocols (Section 12).
-
11. PATIENT RIGHTS: ACCESS, CORRECTION & DISAGREEMENT
-
Right of Access (HIA Sec. 7–11): Patients have a right to inspect or receive a copy of their health record upon written request. Requests will be processed within 30 calendar days. In accordance with the Health Information Regulation, a basic processing fee of $25.00 may be charged to cover retrieval and reproduction costs for the first 20 pages.
-
Right to Request Correction (HIA Sec. 13): Patients may request correction of factual errors or omissions in their record in writing. The clinic will grant or refuse the request in writing within 30 days.
-
Statement of Disagreement (HIA Sec. 14): If a correction request is refused, the applicant will be informed of their right to either request a review by the OIPC or submit a written Statement of Disagreement (maximum 500 words) setting out the requested correction and reasons. When submitted, the Custodian will attach the Statement of Disagreement to the health record and disclose it to any third parties who received the record in the preceding 12 months, where reasonably practicable.
12. BREACH NOTIFICATION & INCIDENT MANAGEMENT
-
Breach Identification & Mitigation: Any loss of, unauthorized access to, or unauthorized disclosure of individually identifying health information will be contained immediately upon discovery.
-
Mandatory Statutory Notification (HIA Sec. 60.1): If the Custodian determines that a privacy breach creates a risk of harm to an individual, the Custodian will notify the following parties without delay / as soon as practicable:
-
The Office of the Information and Privacy Commissioner (OIPC) of Alberta.
-
The Minister of Health.
-
The affected individual(s).
-
-
Breach Logging: All security incidents, regardless of harm assessment, will be documented in the clinic's internal Privacy Incident Log.
13. RETENTION & SECURE DESTRUCTION
-
Retention: Clinical health records are retained for a minimum of 10 years from the date of last entry (or 10 years past the age of majority for minors) in accordance with CPTA standards.
-
Disposal: Paper records are cross-cut shredded on-site or via a certified bonded service. Electronic hardware is permanently sanitized/wiped prior to disposal.
14. Use of Technology & AI Administrative Assistants
Mandatory Guidelines for AI Scribe Usage:
-
Verbal Consent First: Practitioners must inform the patient and obtain verbal consent before activating Jane AI Scribe. If a patient declines, manual charting must be used.
-
Mandatory Human Verification: Practitioners retain 100% clinical accountability for chart accuracy. Practitioners must read, edit, and verify the AI-generated draft before signing and locking the entry. Never sign an unreviewed AI draft.
-
Purging Temporary Transcripts: Ensure audio/transcripts are set to auto-purge upon note completion. Do not store raw audio files locally on personal computers or mobile devices.
-
Access Security: AI Scribe functionality must be accessed using individual practitioner logins backed by Two-Factor Authentication (2FA).
-
Zero AI Model Training: Audio streams, transcripts, and generated summaries processed via Jane AI Scribe are strictly prohibited from being used to train, fine-tune, or improve public or proprietary artificial intelligence/machine learning models.
-
Ephemeral Audio Processing & Data Residency: Audio data is processed strictly in transit using encrypted channels (TLS 1.3) within Canadian data centers (AWS Montreal/Calgary). Raw audio recordings are never saved or stored permanently on local devices, servers, or cloud storage.
15. CONTACT & INQUIRIES
Questions, access requests, or privacy concerns regarding this policy should be directed to:
Brianna Chan, Privacy Officer
Kind Physiotherapy Inc.
1910 102 St. NW, Edmonton, AB, T6N 1N3
Email: brianna@kindphysiotherapy.com
Phone: (780) 984-9887