MIHEALTH GLOBAL SYSTEMS INC.
Mihealth Global Systems Inc. (“Mihealth”) provides a platform for the secure storage of, and access to, personal health information. In the course of our activities in providing this service, we may collect, use and disclose Personal Information. To demonstrate our commitment to your privacy, Mihealth has prepared this policy statement to inform you how we endeavour to ensure the privacy and confidentiality of your Personal Information.
WHAT PERSONAL INFORMATION DOES mihealth HOLD?
Mihealth is not a "health information custodian" within the meaning of health privacy legislation. We may hold the following types of personal information (“Personal Information”) on behalf of our customers for the purposes described below:
1. Personal information, including but not limited to:Name, Address, Email Address, Credit Card Information.
2. Personal Health information, including but not limited to:Allergies, Chronic Disease Lab Results, Current Health Problems, Demographics (age, etc),
Electronic Lab Results, Emergency Contact Information, Family History, Health Risk Factors, immunizations, Lab
Results, Long-Term Medications, Messages, Occupation, Passwords, Passport Information, Past Health Problems,
Pharmacy Information, Physician Information, Preventive Care Information, Radiology History, Short-Term
Medications, Stopped Medications, Supplementary Insurance Information, Travel History and Vital Statistics.
OUR COLLECTION AND USE OF PERSONAL INFORMATION
Whether provided orally or in writing (including through electronic media), we limit the collection of Personal Information to what is reasonably required for our purposes. Mihealth collects Personal Information in order to:
- • Establish a relationship with you;
- • Provide you with our services and ongoing support;
- • Provide you with information about new or existing services;
- • Process or collect fees for services;
- • Conduct healthcare-related and healthcare delivery-related research;
- • Support core business functions within Mihealth;
- • Meet legal and regulatory requirements; and
- • Such other purposes consistent with these purposes.
We will not sell, lease, or rent your personal information to any third-party or to a third-party for research purposes without your explicit consent. We may share anonymized and aggregate information with third-parties; anonymized and aggregate information is any information that has been stripped of your name and contact information and aggregated with information of others or anonymized so that you cannot reasonably be identified as an individual.
We endeavour to collect information directly from you as much as possible but may receive Personal Information about you from other sources (e.g. from your physician; from references for individual service providers).
We receive and store certain types of information when you interact with our website. Our purpose in doing so is to allow our website to work correctly, to evaluate its use, and to support website analytics and marketing campaigns. Such information may include technical information such as your internet protocol address, your computer's operating system and browser type, the address of a referring website, if any, and the path you take through our web pages.
To provide a continuous experience for you on Mihealth’s site, we use “cookies” to recognize you as you use or return to our sites. A cookie is a small text file that a website or email may save to your browser and store on your hard drive.
Our use of Personal Information is limited to the purposes described in this Policy, or consistent purposes. Mihealth does not otherwise sell, trade, barter, exchange or disclose for consideration any Personal Information.
WHEN Mihealth MAY DISCLOSE YOUR PERSONAL INFORMATION
Mihealth generally will not disclose your Personal Information unless required to do so to provide you with our services or by law.
Mihealth may disclose your Personal Information to individuals or organizations who are or may be:
- • Our advisers or service providers;
- • Partners in conducting healthcare-related and healthcare delivery-related research;
- • Involved in a transfer of all or part of the assets or business of Mihealth;
Where Mihealth discloses Personal Information to individuals or organizations that perform services on its behalf, we will require those service providers to use such information solely for the purposes of providing services to Mihealth or you and to have appropriate safeguards for the protection of that Personal Information.
Where Personal Information may be subject to transfer to another organization in contemplation of a merger, sale of assets or business units or change of ownership, we will do this only if the parties have entered into an agreement under which the collection, use and disclosure of the information (including any Personal Information) is restricted to those purposes that relate to the business transaction.
Please note that there are circumstances where the use and/or disclosure of Personal Information may be justified or permitted or where Mihealth is obliged to disclose information without consent. An example of disclosure without consent is where it may be required by law or by order of a court or governmental tribunal. Where obliged or permitted to disclose information without consent, Mihealth will not disclose more information than is required.
Mihealth uses service providers or suppliers that help with our business operations who may access or store your Personal Information. Examples are billing and refund vendors, credit card processors, and companies that help us improve our product and service offerings and our web sites. We require these service providers and suppliers to keep the information secure. We also prohibit them from using your information for any purposes other than those requested by us.
While Mihealth is the custodian of the Personal Information provided to us, some associated services are provided by third party service providers. While your personal health information is stored in Canada, some of our service providers and the databases where they store personal information (other than your personal health information) are located in the United States of America. Please note that Personal Information located in any jurisdiction is subject to the laws of that jurisdiction.
Unless permitted by law, Mihealth will collect no Personal Information without obtaining the consent of the individual concerned. However, we may seek consent to use and disclose Personal Information after it has been collected in those cases where we wish to use the information for a new or different purpose.
By providing Personal Information to Mihealth you agree and consent that we may collect, use and disclose your Personal Information in accordance with this Policy. In addition, where appropriate, specific authorizations or consents may be obtained from time to time.
If you choose not provide us with any required Personal Information, we may not be able to offer you our services. If you choose to withdraw your consent, which you are free to do, we will inform you of any consequences in doing so.
THE ACCURACY AND RETENTION OF PERSONAL INFORMATION
Mihealth endeavours to ensure that any Personal Information in its custody is as accurate, current and complete as necessary for the purposes for which we use that information.
We keep Personal Information in our custody only as long as it is required for the reasons it was collected. The length of time we retain information varies, depending on the purpose for which it was collected and the nature of the information. This period may extend beyond the end of your relationship with us but it will be only for so long as it is necessary for us to have sufficient information to respond to any issues that may arise at a later date.
Personal Information in our possession (i.e. the personal health information in your Mihealth record) is kept for 20 years from the date of the creation of your record.
When Personal Information in our possession or custody is no longer required for Mihealth's purposes, we have procedures to destroy, delete, erase or convert it into an anonymous form.
All information in Mihealth's custody or possession is held in Canada.
PROTECTION OF PERSONAL INFORMATION
Mihealth endeavours to maintain appropriate physical, procedural and technical security with respect to its offices and information storage facilities so as to prevent any loss, misuse, unauthorized access, disclosure, or modification of Personal Information in our custody or possession. This also applies to our disposal or destruction of such information.
Mihealth protects Personal Information by restricting access to it to those employees or service providers that Mihealth has determined need to know that information to allow Mihealth to provide our services.
Any employee misuse of Personal Information will be considered a serious offence for which disciplinary action will be taken, up to and including termination of employment. Where an individual or organization is provided Personal Information in order to provide services to or for Mihealth, any misuse of such information will be considered a serious issue for which action will be taken, up to and including termination of any agreement between Mihealth and that individual or organization.
ACCESS TO YOUR PERSONAL INFORMATION
With respect to personal health information in your record, you may access it at any time. Where Personal Information is in the custody of Mihealth, we permit a reasonable right of access and review and will endeavour to provide the information in question within a reasonable time, generally no later than 30 days following the request. Mihealth’s Access Guide provides further information as to how Mihealth deals with access requests.
Mihealth will make this policy statement available on its web site as well as other places that Mihealth’s management determines appropriate. Mihealth may, from time to time, conduct privacy impact assessments on its service offerings, and will make summaries of such assessments available upon request.
RESOLVING YOUR PRIVACY CONCERNS
In the event of questions about: access to your Personal Information; (our collection, use, management or disclosure of Personal Information; or this Policy; please contact Mihealth's Privacy Officer:
Mihealth Global Systems Inc.
2300 Yonge Street, Suite 1709
Toronto, Ontario M4P 1E4