Security & privacy

Built around patient data.

Handling OHIP claims means handling protected health information. OHIPay is designed with that as the default, not an afterthought. Here is how patient data is handled — in plain terms, and without overstating what the product is.

The practices

What we do to protect it

These describe current engineering practices in the product. They are how the system is built — not a claim of certification under any specific compliance framework.

Encrypted at rest

Health card numbers and demographic details are encrypted at rest and in transit. They're decrypted only when a claim or a lookup genuinely needs them.

PHI stays server-side

Patient identifiers are decrypted in-process on the server for the moment they're needed — not held in the browser or shipped to a client-side cache. In lists, names and health numbers are masked, and shown in full only for actions that genuinely require them.

Card images never stored

When a health card is scanned, the image is processed in memory to read the number and then discarded. Card photos aren't written to disk.

Per-physician access scoping

Access to claims and patient records is scoped per physician, so a user sees the records their role is entitled to — not the whole database.

Sensitive access is logged

Reads and edits to patient records are recorded in an audit trail, so who looked at what — and when — is answerable after the fact.

Canadian data residency

The service and its data are hosted in Canada. If you need specifics on where and how your data would be stored, we'll walk through it before you rely on it.

Want the detail behind any of these? Ask us how your data would be handled before you commit — we'd rather answer a specific question than wave at a logo.

Being straight with you

What we don't claim

It matters as much to say what OHIPay is not. We'd rather be modest and accurate than impressive and wrong.

  • We don't claim SOC 2, HIPAA, ISO, or any other compliance certification.
  • We don't claim endorsement or certification by the Ministry of Health or OHIP.
  • The billing engine is advisory: it flags likely issues, and never guarantees a claim will be accepted or paid.

Independent software

OHIPay is independent billing software and is not affiliated with, endorsed by, or certified by the Ontario Ministry of Health or OHIP.

It helps you prepare and submit claims and warns about likely rejections — but the decision to accept, adjust, or reject a claim rests entirely with the Ministry.

Questions about your data

Ask us anything before you rely on it

If your practice has specific requirements about how patient data is stored and handled, bring them to a walkthrough and we'll go through the details.

Prefer email? Write to hello@ohipay.ca