MedEssist Privacy Policy
Last Updated August 4, 2026
MedEssist Ltd. ("MedEssist", "we", "us", or "our") provides software services to pharmacies and other healthcare organizations across Canada. This Privacy Policy explains how MedEssist collects, uses, discloses, retains, and safeguards personal information, and describes the rights and choices available to individuals whose information we handle. It is designed to meet our obligations under applicable Canadian privacy laws, including PIPEDA, PHIPA (Ontario), PIPA (BC and Alberta), the Act respecting the protection of personal information in the private sector (Quebec), and other provincial legislation, as well as the criteria of the AICPA Trust Services Criteria for Privacy (SOC 2).
For the purpose of this policy:
- Personal Information (PI) means general information used to facilitate communication, such as name, date of birth, email address, and telephone number.
- Personal Health Information (PHI) means information collected in connection with the provision of a requested health service (for example, immunization records, screening intake, or clinical assessment data).
- Pharmacy means the pharmacy, clinic, or other health information custodian that has contracted with MedEssist to use our software.
- Data Subject means the individual to whom the personal information relates (typically a patient or a pharmacy staff user).
MedEssist generally acts as a service provider / information manager to the Pharmacy (which is the "health information custodian" under PHIPA and the equivalent controller under other laws). For information collected directly by MedEssist (e.g., pharmacy staff account credentials, marketing enquiries), MedEssist acts as the controller.
1. Purpose for Collecting and Processing Personal Information
We collect and process personal information only for the following defined purposes:
- To deliver the health services requested by the individual through their Pharmacy (e.g., vaccination bookings, clinical intake, follow-up, documentation).
- To enable Pharmacies and their authorized healthcare providers to schedule appointments, prepare and store required clinical documentation, and comply with their own regulatory and record-keeping obligations.
- To communicate with patients on behalf of the Pharmacy (e.g., appointment reminders, results, aftercare instructions) using SMS and email.
- To authenticate pharmacy users and maintain audit logs of access to patient records for security and accountability.
- To provide, maintain, secure, monitor, troubleshoot, and improve the MedEssist platform.
- To meet MedEssist's own legal, regulatory, contractual, and accreditation obligations (e.g., SOC 2, breach notification, responding to lawful requests).
- With de-identified/anonymized data only: research, education, service improvement, and analytics.
MedEssist does not use personal information for automated decision-making that produces legal or similarly significant effects, and does not sell personal information.
2. Lawful Basis for Collecting and Processing Personal Information
MedEssist and its Pharmacy customers rely on the following lawful bases:
- Consent – Express consent obtained by the Pharmacy from the patient at the time of booking, intake, or documentation (and, where applicable, implied consent within the "circle of care" as permitted under PHIPA and analogous provincial laws).
- Performance of a service requested by the individual – Processing necessary to deliver the health service the patient requested (PIPEDA s. 7; PHIPA s. 37).
- Legal obligation – Processing required to comply with statutory record-keeping, reporting (e.g., mandatory public-health reporting by the Pharmacy), and breach notification obligations.
- Legitimate business interests – Limited operational uses such as security monitoring, audit logging, fraud prevention, and platform improvement, balanced against the rights of data subjects.
- Contract – Processing pharmacy staff information as necessary to administer accounts under our agreement with the Pharmacy.
The Pharmacy remains responsible for obtaining and documenting patient consent for the underlying health service; MedEssist provides the technical mechanisms to capture that consent.
3. Types of Personal Information Collected or Processed
MedEssist processes the following categories of information:
Personal Information (PI)
- Identifiers: name, date of birth, gender.
- Contact details: email address, telephone number, mailing address.
- Government/health identifiers where required by the service: health card number, OHIP/RAMQ/other provincial health numbers.
- Pharmacy user account data: name, work email, role, employer pharmacy, hashed authentication tokens (passwords are handled by Google Identity/Authentication).
Personal Health Information (PHI)
- Clinical intake and screening responses submitted through MedEssist forms.
- Immunization and medication administration records (product, lot number, dose, site, administering clinician).
- Clinical notes, assessment outcomes, referrals, and follow-up documentation created by the Pharmacy.
- Test results uploaded or generated through the platform.
- Any additional fields configured by the Pharmacy on custom forms.
Technical and Usage Information
- Log data: IP address, browser/user-agent, timestamps, pages accessed, actions taken.
- Audit records of which pharmacy user accessed which patient record and when.
- Device and session identifiers used for authentication and abuse prevention.
Communications Metadata
- Delivery status of SMS/email sent through Twilio (no PHI content is sent through these channels).
MedEssist complies with the Minimum Necessary Standard by only collecting the minimum amount of information that is reasonably necessary to provide the requested healthcare service or other authorized purpose. Individual healthcare providers may configure additional data collection on their own forms. MedEssist does not monitor or control the content of that custom collection; the configuring Pharmacy is responsible for ensuring it complies with applicable law.
4. Choice and Consent
- Patients provide consent at the point of collection through the Pharmacy's booking or documentation workflow, which explicitly identifies the health service and the information required.
- Patients may decline to provide optional fields. If information required to deliver the requested service is withheld, the Pharmacy may not be able to deliver that service.
- Patients may withdraw consent at any time by (a) clicking the unsubscribe/cancel-registration link at the bottom of any MedEssist email; (b) contacting the Pharmacy directly to request modification or deletion; or (c) contacting MedEssist's Privacy Officer (see Section 11).
- Pharmacy user consent is captured on first login through acceptance of this Privacy Policy and the applicable Terms of Service.
- Withdrawal of consent does not affect processing that occurred prior to withdrawal or processing that MedEssist or the Pharmacy is legally required to continue (e.g., retention of clinical records for the mandated retention period).
5. Methods of Collection (Including Cookies and Tracking)
MedEssist collects personal information through the following methods:
- Directly from the patient via web-based intake forms, booking pages (e.g., bookmyshot.com, bookmypharmacy.com), and SMS/email replies to communications initiated by the Pharmacy.
- Directly from the Pharmacy when staff enter or edit clinical documentation through the MedEssist dashboard.
- From integrated third parties authorized by the Pharmacy (e.g., video conferencing platform such as Zoom for Healthcare, when connected by the Pharmacy).
MedEssist does not use third-party advertising cookies or cross-site tracking on patient-facing pages. Where non-essential cookies are used on marketing pages, we present a cookie notice and honour "Do Not Track" and opt-out signals where technically feasible.
6. Use, Retention, and Disposal
Use
Personal information is used only for the purposes identified in Section 1 and only by authorized personnel on a need to know basis.
Retention
MedEssist retains personal information for the shorter of:
- the period the Pharmacy instructs us to retain it
- the period necessary to fulfil the purposes described in this policy; or
- A minimum of 10 years or the period required by applicable law.
Backups containing personal information are retained for 30 days on a rolling basis and are protected using the same controls as production data. Audit logs are retained for at least 1 year to support security investigations and SOC 2 requirements. Anonymized/de-identified data may be retained indefinitely, as it is no longer personal information.
Disposal
When retention periods expire, or when a data subject or Pharmacy validly requests deletion:
- Records are deleted from production databases;
- Deletion is propagated to backups on the next retention cycle;
- Deletion actions are logged for audit purposes.
Where full deletion is not possible (e.g., legally required retention), data is placed under access restriction until it can be securely destroyed.
7. Data Subject Rights
Subject to the requirements and exceptions of applicable law, data subjects have the right to:
- Access – Request confirmation of whether MedEssist processes their personal information, and a copy of that information.
- Correction / Rectification – Request correction of inaccurate or incomplete information.
- Deletion / Erasure – Request deletion of information no longer required for a lawful purpose.
- Withdraw Consent – Withdraw previously given consent, subject to legal or contractual restrictions.
- Restriction / Objection – Object to or request restriction of certain processing.
- Portability – Request a copy of information provided by the data subject in a commonly used, machine-readable format, where applicable.
- Complaint – Lodge a complaint with MedEssist's Privacy Officer and with the relevant privacy regulator (e.g., the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, the CAI in Quebec).
Because MedEssist typically acts on behalf of the Pharmacy, patients should ordinarily direct access/correction requests to their Pharmacy first. MedEssist will support the Pharmacy in fulfilling verified requests, and will respond directly to requests made to us within 30 days (extension possible where permitted by law, with notice to the requester). We verify identity before disclosing or modifying personal information. Requests may be sent to support@medessist.com, attention: Privacy Officer.
8. Use of Subprocessors
MedEssist engages a limited number of vetted subprocessors to deliver the service. Each subprocessor is bound by written agreements imposing confidentiality, security, and data protection obligations at least as protective as those in this policy.
MedEssist maintains a current list of subprocessors and will provide advance notice of material changes to Pharmacies. Where a subprocessor is located outside Canada, personal information may be subject to the laws of that jurisdiction; MedEssist implements contractual safeguards (e.g., data processing agreements, standard contractual clauses where applicable) to protect the information.
9. Technical and Organizational Measures
MedEssist maintains a written information security program aligned with SOC 2 that includes the following safeguards:
Technical Measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256, managed via Google Cloud KMS).
- Logical separation of PI and PHI: PI is stored in a database used by public-facing booking surfaces; PHI is stored in a separate database that is not reachable from public endpoints.
- Role-based access control and least-privilege permissions.
- Mandatory secondary authentication for healthcare providers accessing PHI at each site, at login and after periods of inactivity.
- Detailed audit logging of every access to a patient record (who, what, when).
- Continuous monitoring, vulnerability scanning, and patching of infrastructure.
- Secure software development lifecycle: peer code review, automated testing, dependency scanning, and staged deployments.
- Regular backups with tested restoration procedures.
Organizational Measures
- Full production database access is restricted to two lead software engineers (Victor Yu and Parth Desai) and to Canadian healthcare providers with appropriate technical training who are employed by MedEssist (e.g., pharmacists, registered pharmacy technicians).
- All software development is performed in Canada and the United States.
- Background checks and confidentiality agreements for personnel with access to PI/PHI.
- Annual privacy and security awareness training for all staff.
- Documented incident response, business continuity, and disaster recovery plans, tested at least annually.
- Vendor risk assessment for all subprocessors before onboarding and on a recurring basis.
- Data Protection Impact Assessments for material changes to processing.
- MedEssist will not contact patients directly without the Pharmacy's consent, except for technical service issues.
10. Quality – Including Data Subjects' Responsibilities for Quality
MedEssist takes reasonable steps to keep personal information accurate, complete, and current for the purposes for which it is used. This includes:
- Providing Pharmacies with tools to review, correct, and update patient records.
- Timestamping and audit-logging every record modification.
- Reviewing information quality when a correction request is received.
Data subjects share responsibility for the quality of their information by:
- Providing accurate, current, and complete information when submitting intake forms or booking appointments;
- Promptly notifying the Pharmacy (or MedEssist's Privacy Officer) of any changes to their name, contact details, health card information, or clinical information relevant to the service;
- Reviewing information shown back to them during a booking or intake workflow and correcting it before submission.
MedEssist is not responsible for consequences arising from inaccurate information supplied by the data subject or the Pharmacy, but will act promptly to correct verified inaccuracies.
11. Monitoring and Enforcement
Governance
MedEssist's Privacy Officer, Michael Do (a licensed pharmacist in Ontario, Canada), is accountable for MedEssist's compliance with this policy. The Privacy Officer approves any component of the platform through which information is collected, and can be reached at:
Michael Do, Privacy Officer
MedEssist Ltd.
Email: support@medessist.com
Internal Monitoring
- Reviews access logs and security alerts on an ongoing basis;
- Performs periodic internal privacy and security audits;
- Undergoes an independent SOC 2 examination on an annual basis ;
- Reviews this Privacy Policy at least annually and updates it when practices change.
Complaints
Any individual may submit a privacy complaint to the Privacy Officer. MedEssist will acknowledge complaints within 10 business days and provide a substantive response within 30 days. Investigations are documented, root cause is identified, and corrective and preventive actions are tracked to closure. Data subjects may also complain to their applicable privacy regulator.
Enforcement
Violations of this policy by MedEssist personnel or contractors are subject to disciplinary action up to and including termination and referral to law enforcement or professional regulators where warranted.
Breach Response
If a privacy or security breach is identified or reported, the Privacy Officer will implement MedEssist's incident response process:
- Coordinate with data and communications partners (Google Cloud, Twilio, and others as applicable) to assess the scope, cause, and containment options.
- If the cause can be corrected in MedEssist's code or configuration, deploy a fix as soon as possible.
- Notify affected Pharmacies, affected patients, and — where required by law — the applicable privacy regulator(s) (e.g., OPC under PIPEDA's breach notification requirements; IPC under PHIPA), by email or telephone, describing the information involved and providing guidance on protective steps (e.g., resetting credentials).
- Conduct a post-incident review, update policies, controls, and training as needed, and document the incident in MedEssist's breach register.
Changes to this Policy
We will post any changes to this Privacy Policy on this page and update the "Last Updated" date. Material changes will be communicated to Pharmacies and, where appropriate, to patients through in-product notice or email.
Contact
For any questions, requests, or complaints regarding this Privacy Policy, contact: Michael Do, Privacy Officer
MedEssist Ltd. support@medessist.com