Please note: This article is provided for general information and is not a legal interpretation of the Personal Health Information Protection Act, 2004 (PHIPA) or of any regulatory College's standards. For advice specific to your practice, please consult a legal professional or your College.
The Short Answer
Yes. Noterro is built to support Ontario health information custodians in meeting their obligations under PHIPA, and all clinic data is stored in Canada.
It's worth being precise about what that means. Under PHIPA, the legal obligations sit with the health information custodian — that's you, as the practitioner or clinic. Noterro acts as your electronic service provider and agent. Our role is to provide the technical safeguards and records you need, and to handle personal health information (PHI) only as you direct us.
For the same reason, no practice management platform can be "PHIPA certified" — no such certification exists in Ontario. Any vendor claiming one is describing something that isn't there. We can show you exactly what we provide, so you can document your own information practices with confidence.
PHIPA's Role
PHIPA is Ontario's health privacy law. It governs how health information custodians collect, use, disclose, retain and safeguard personal health information. It applies to regulated health professionals in Ontario — including massage therapists, chiropractors, physiotherapists, audiologists, speech-language pathologists, osteopaths and others — as well as to the clinics and organizations where they practise.
PHIPA sits alongside PIPEDA, Canada's federal private-sector privacy law. Ontario's PHIPA is recognized as substantially similar to PIPEDA for personal health information, meaning PHIPA is generally the governing law for clinical records held by Ontario custodians.
Where Your Data is Stored
All Noterro clinic data is stored in Canada. Your patient records, notes, documents and files do not leave the country in the ordinary course of using Noterro.
This matters under PHIPA because custodians must be transparent about their information practices, including where PHI is stored. You can state in your privacy policy that your records are stored in Canada by your practice management provider.
Safeguards Noterro Provides
PHIPA requires custodians to take reasonable steps to protect PHI against theft, loss and unauthorized use or disclosure. Here's what Noterro contributes to that:
Encryption
Data is encrypted both in transit and at rest.
Access Controls
Every staff member has a unique user account, so activity is always attributable to a named individual.
Role-based permissions let you control what each team member can see and do — for example, limiting front-desk staff to scheduling and billing while restricting access to clinical content.
Treating practitioner restrictions goes a step further. Noterro can be configured so that a patient's notes are visible only to the practitioner treating that patient, rather than to every clinician in the clinic. This supports the PHIPA principle that PHI should be accessible only to those who need it to provide care.
Two-factor authentication is available to all users, and you can restrict access by IP address to limit logins to your clinic network.
Access Logs and Activity Logs
Noterro keeps two kinds of logs, both available to you in your account:
- Access logs record who signed in and when.
- Activity logs record actions taken within the clinic — including when a record was created or modified, and by which user.
Together, these give you an audit trail you can draw on for your own quality assurance, a College inquiry, or a privacy breach investigation.
Internal Access Limits
Noterro staff operate under the principle of least privilege. Our team cannot casually browse clinic data, and access is limited to what is required to support you.
Infrastructure and Monitoring
Noterro runs on cloud infrastructure with 24/7 monitoring and alerting, and regular backups to multiple physical locations.
Secure Development
We follow a DevSecOps approach, including software composition analysis, static and dynamic application security testing, and peer code review.
CASLPO and Other Ontario Colleges
We're sometimes asked whether Noterro is "CASLPO compliant," or compliant with the standards of another Ontario College.
Regulatory Colleges — including the College of Audiologists and Speech-Language Pathologists of Ontario (CASLPO), the College of Massage Therapists of Ontario (CMTO), the College of Chiropractors of Ontario (CCO) and others — set record-keeping and privacy standards for their registrants. They do not certify, approve or endorse software vendors. Compliance with your College's standards is something you demonstrate through your own practice; Noterro's job is to make that straightforward.
Toward that end, Noterro supports the record-keeping expectations common to Ontario Colleges:
- Attributable entries. Notes are tied to the user who created them, with dates and times recorded automatically.
- An activity trail. Activity logs record when a record was created or modified and by which user.
- Retention. Noterro does not automatically delete your clinical records. You retain them for as long as your College requires — including the extended retention periods that apply to records of patients who were minors at the time of treatment.
- Your data stays yours. You can request a full export of your clinic's data at any time, and a full deletion when you no longer need it retained.
We'd encourage you to review your own College's documentation standards — for CASLPO registrants, the Records Regulation (O. Reg. 164/15) and CASLPO's Documentation Standards — and confirm that how you use Noterro matches them, including your College's expectations around correcting or amending an entry after the fact.
What Remains Your Responsibility
Noterro provides the tools; PHIPA compliance is a shared effort. As the custodian, you are responsible for:
- Designating a contact person for privacy matters, and maintaining a written statement of your information practices
- Configuring user accounts and permissions appropriately, and removing access promptly when a staff member leaves
- Obtaining and managing patient consent for the collection, use and disclosure of their PHI
- Responding to patient requests to access or correct their records
- Reporting privacy breaches to the affected individuals and, where required, to the Information and Privacy Commissioner of Ontario and your College
- Retaining records for the period your College requires
Requesting an Export or a Deletion
Email privacy@noterro.com, and our team will help you with either of the following:
- A full export of your clinic's data — for your own records, a College request, or if you're moving to another platform.
- Full deletion of your clinic's data — once you've met your retention obligations and no longer need the records held.
Comments
0 comments
Please sign in to leave a comment.