Noterro is a Canadian health-tech company subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). We've carefully designed Noterro to align with PIPEDA requirements and help clinics meet their own compliance obligations. Noterro serves as a service provider to clinics, storing and processing patient data on their behalf.
This information is not a legal interpretation of the law and is not binding. This information is not intended to, nor should it ever replace, formal legal counsel.
PIPEDA's Role in Health Clinics
PIPEDA applies to private-sector organizations throughout Canada that gather, use, or disclose personal information within commercial activities. Clinics using Noterro are responsible for ensuring their own compliance with PIPEDA.
What Constitutes Personal Information Under PIPEDA?
Personal information encompasses any factual or subjective details regarding an identifiable individual, whether recorded or not. This includes:
- Name
- Age
- Ethnicity
- Clinical assessments
- Medical records
- Financial records
- Contact information
PIPEDA's 10 Fair Information Principles
Principle 1 – Accountability
Clinics are responsible for personal information under their control. Each clinic must designate an individual accountable for PIPEDA compliance. Per Noterro's Terms of Use, the clinic Admin is the legal guardian of patient data entered into the platform and should serve as the point of accountability for compliance.
How it's handled in Noterro: Noterro does not control how clinics use their data. Each clinic manages access levels and data usage through settings within Noterro, internal agreements, and their own policies. For more details, see our Privacy Policy.
Principle 2 – Identifying Purposes
The purposes for collecting personal information must be identified before or during collection.
How it's handled in Noterro: Noterro serves solely as a service provider to clinics. We never sell, trade, or use patient data for any purpose other than providing the Noterro platform. Clinics remain responsible for identifying and documenting the purposes for which they collect patient data.
Principle 3 – Consent
An individual's knowledge and consent are required for the collection, use, or disclosure of personal information.
How it's handled in Noterro: Clinics can create custom consent forms using Noterro's Forms feature, documenting patient consent for data collection and use in compliance with PIPEDA.
Principle 4 – Limiting Collection
Personal information must be collected only as needed and by fair and lawful means.
How it's handled in Noterro: Clinics control which information is collected on their forms and what data is gathered from patients. Clinics should only collect information necessary for their stated purposes.
Principle 5 – Limiting Use, Disclosure, and Retention
Personal information can only be used or disclosed for the purposes for which it was collected, unless the individual consents otherwise. Information must be retained only as long as needed to serve those purposes.
How it's handled in Noterro: Clinics manage their data retention. When a clinic no longer needs patient data, they have two options:
- Request full deletion – Contact us at privacy@noterro.com to request complete deletion of your clinic's patient data from Noterro. We will process deletion requests and respond within applicable law timeframes.
- Export and retain independently – Export your clinic's records from Noterro and maintain them in accordance with your own retention policies. Clinics can export chart data at any time.
For either option, contact privacy@noterro.com to begin the process.
Principle 6 – Accuracy
Personal information must be as accurate, complete, and up to date as possible.
How it's handled in Noterro: We recommend that each staff member has their own Noterro account to manage and oversee data input. Clinic Admins can manage staff and individual permission levels. It's the clinic's responsibility to ensure only trusted individuals have access and that data remains accurate.
Principle 7 – Safeguards
Personal information must be protected by security measures appropriate to its sensitivity.
How it's handled in Noterro: Security is paramount. For details on encryption, access controls, server management, and other security safeguards, see our Privacy Policy, Security section.
Principle 8 – Openness
Organizations must make their information policies and practices publicly available.
How it's handled in Noterro: Clinics should develop clear policies and best practices aligned with PIPEDA. Noterro provides a Forms & Agreements feature to help clinics customize and document their privacy practices and obtain proper consent.
Principle 9 – Individual Access
Upon request, individuals must be informed of the existence, use, and disclosure of their personal information and given access to that information.
How it's handled in Noterro: Patients can request access to their personal information through your clinic. Clinics can export patient chart data directly from Noterro at any time or share individual charts with patients via the Web Portal. For requests directed to Noterro, contact privacy@noterro.com. We will respond within applicable law timeframes and assist your clinic as required by our contractual obligations.
Principle 10 – Challenging Compliance
Individuals can challenge an organization's compliance with PIPEDA principles. Challenges should be addressed to the person accountable for the organization's compliance.
How it's handled in Noterro: Each clinic must appoint a person responsible for PIPEDA compliance. If patients have questions about Noterro's compliance as a service provider, they can contact us at privacy@noterro.com.
Comments
0 comments
Please sign in to leave a comment.