Privacy policy
What information OHIPay handles on the web and in the OHIPay app, why, where it is kept, and for how long. In plain words.
Who we are
OHIPay is a product of Medinote Technologies Inc. Medinote Technologies Inc. operates OHIPay: the billing workspace at app.ohipay.ca and the OHIPay app for iPhone and Android phones. In this policy, "we" means Medinote Technologies Inc. operating OHIPay.
OHIPay is billing software for Ontario physicians and the staff who bill for them. Only people with an account set up by OHIPay can use it.
Your physician is in charge of patient information
Under Ontario's Personal Health Information Protection Act (PHIPA), each physician who uses OHIPay is the health information custodian of their patients' information. Medinote Technologies Inc., operating OHIPay, is the physician's agent and electronic service provider: we handle patient information only to provide OHIPay to that physician, as they direct, or as the law requires.
If you are a patient and want to see or correct your information, please ask your physician. If you contact us, we will direct you to your physician and help them answer.
What information OHIPay handles
About physicians and their staff
- Name, email address, OHIP billing number and practice details.
- Sign-in records: when you signed in, and the network address and browser or app that was used.
- Your two-factor sign-in setting, if you turn it on.
About patients, entered or scanned by the physician
- Name, date of birth, sex, health card number and version code.
- Diagnosis codes, the services billed, service and admission dates, the hospital, and the referring physician.
- The Ministry's answers: health card check results, and the payment and error reports on each claim.
Technical information
- Records of requests and errors on our servers, used to run and protect the service.
How we use it
- To run the physician's billing: price claims, warn about likely Ministry rejections, check health cards with the Ministry, send claims to the Ministry, and match the Ministry's payments to claims.
- To keep OHIPay secure, including recording who looked at patient information and when.
- To answer support requests.
- When the law requires it.
We do not sell information, we do not use it for advertising, and we do not contact patients.
Physicians who use OHIPay agree to three ways it works, which we state here too:
- One patient record per health card. A patient seen by two physicians who both use OHIPay has one record, shared by both.
- Billing history across physicians. A physician billing for a patient can see which services other OHIPay physicians billed for that patient, without seeing who those physicians are.
- Learning from rejections. OHIPay counts which fee-code combinations the Ministry rejects, across all practices, to improve its warnings. These counts contain no patient information.
The Ontario Ministry of Health
OHIPay sends patient and claim information to the Ontario Ministry of Health because that is how a physician bills OHIP and checks a health card. The Ministry is the payer, not a company working for us.
- Health card checks go to the Ministry's Health Card Validation service.
- Claims go to the Ministry's MC EDT service from OHIPay on the physician's computer, or automatically each night if nightly sending is turned on for that physician. The OHIPay app never sends claims itself.
- The Ministry sends back payment and error reports, which OHIPay matches to claims.
Scanning a health card with the app
- When you point the camera at a health card, the app first tries to read the card number on the phone itself. If it can, it sends only the number and version code to OHIPay, and no picture at all.
- If the phone cannot read it, the app sends only a narrow strip of the photo, around the card number, not the whole card.
- A photo you choose from your photo library is sent whole.
- On OHIPay's server, a card image is read in memory and then deleted. It is never saved to disk or to the database.
- On the phone, a card photo sits in the app's private temporary storage only until it has been read, and is then deleted. Photos you take in the app are not added to your photo library.
To read the number on the phone, the app uses Google's ML Kit text recognition, which runs on the device. Google says ML Kit may send Google diagnostic information about the app and the device, such as the device model, operating system and app version, performance measurements and an identifier for the installation. It does not send the card image or the text read from it.
Face ID, Touch ID and fingerprint
You can lock the app with Face ID, Touch ID, a fingerprint or your phone's passcode. This is handled entirely by your phone. OHIPay never receives your face, fingerprint or any other biometric information, only whether the phone unlocked. It is off until you turn it on, and the on/off setting stays on your phone.
What the app keeps on your phone
- Your sign-in. A sign-in token, kept in the phone's secure storage (the iOS Keychain, or storage protected by the Android Keystore). It is valid for up to 30 days, is never moved to another phone, and is not copied into phone backups.
- App settings. Which OHIPay server you use, display and sorting choices, whether biometric unlock is on, and a marker that the app has been installed.
- No patient information stays on your phone. Patient information you see in the app is held in the app's memory only, and is cleared when you sign out. The one exception is a card photo, held in private temporary storage until it has been read and then deleted, as described above.
Signing out, and a lost phone
Signing out deletes the sign-in from that phone. It does not cancel the sign-in on OHIPay's servers, which stays valid until it expires, up to 30 days after you signed in.
To end every session, including one on a lost or stolen phone, change your password on the web (Settings, then Change password), or ask support@ohipay.ca to do it for you.
No tracking, no advertising
- There are no advertisements in OHIPay.
- The app contains no analytics, advertising or crash-reporting software, and does not use your phone's advertising identifier. The only exception is the ML Kit diagnostics described above.
- We do not track you across other companies' apps or websites.
- This website, ohipay.ca, uses no cookies and no analytics. It remembers your light or dark display choice in your own browser. The OHIPay web app uses a cookie to keep you signed in.
Companies that help us run OHIPay
| Company | What they do for us | Patient information? | Where |
|---|---|---|---|
| OVH | Runs the servers the application and database live on. | Yes, all of it | Beauharnois, Québec |
| Amazon Web Services (S3) | Stores the encrypted database backups. The key to read them is kept away from Amazon. | Encrypted only; they cannot read it | Canada (Montréal) |
| Resend | Sends account email, such as invitations and password resets, and our own operational alerts. | No | United States |
| Google (Fonts) | The health-card lookup pages of the web app load a web font from Google, which sees page details such as the network address and page address. | No | United States |
| Google (ML Kit) | Reads the health card number on the phone. May send Google diagnostic information about the app and device. | No | On the phone; diagnostics go to Google |
| Medinote | A separate telehealth platform. If a physician turns on the Medinote connection, patient information flows from Medinote into OHIPay. | Yes, flowing in from Medinote | Under Medinote's own terms |
| Amazon Bedrock | AI suggestions. Built but switched off: no AI provider receives any information today. | None today | Canada |
Apple and Google distribute the OHIPay app through their app stores. Downloading and updating the app is covered by their own privacy policies; OHIPay sends them no patient information.
We give physicians 30 days' written notice before adding a company to this list or moving where information is stored.
Where information is kept
All patient information, live and in backups, stays in Canada. The application and its database run on OVH servers in Beauharnois, Québec. Backups are encrypted on our own server before they leave it, and stored with Amazon Web Services in the Canada (Montréal) region.
How long we keep it
- Patient and claim information: for as long as the physician uses OHIPay.
- When a physician leaves: 60 days to take a copy of their records, then deletion from our live systems within 30 days. See how to delete your account.
- Encrypted backups: routine backups are kept 30 days, monthly archives 400 days.
- The Ministry's files about claims (claim files, payment and error reports): 10 years from when each was created.
- Records of who looked at patient information, and records of accepted terms: kept as proof of proper handling.
- Physician account and business records: about 6 years after the relationship ends.
- On the phone: the sign-in token until you sign out or it expires (up to 30 days); a card photo only until it has been read.
How we protect it
Health card numbers and patient details are encrypted on our servers, and everything travels over encrypted connections. Physicians can turn on two-factor sign-in. Access to patient information is recorded.
Access, correction and complaints
- Physicians and staff can ask us for a copy of their own account information, or to correct it, at support@ohipay.ca.
- Patients should ask their physician, who is in charge of their records.
- A concern about patient information can be raised with the Information and Privacy Commissioner of Ontario (ipc.on.ca). A concern about a physician's own account information can be raised with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
Children
OHIPay is for physicians and their staff and is not meant for children. A physician may bill for patients who are children; that information is handled as described above.
Changes to this policy
We will post any change on this page with a new date, and tell physicians by email before a change that affects how their patients' information is handled.
Contact
Email support@ohipay.ca, or write to Medinote Technologies Inc., 1338 Wellington Street West, Ottawa, Ontario K1Y 3B7, Canada.