Introduction, purpose and scope
This policy explains how the collection, use, communication and retention of personal information is carried out within the Clinique chiro+physio Westmount in order to ensure compliance with legal requirements relating to the protection of personal information .
At the clinic, your treating professional is responsible for ensuring the confidentiality and protection of your personal data. The professionals working in the chiro+physio Westmount premises are deemed independent and therefore individually responsible for their patients as well as their data.
Collection, use, communication, retention and destruction of personal information
- Purposes of collection. The Clinic’s professionals collect and use the personal information necessary to carry out its activities, in particular:
- With his patients,
- The date the file was opened;
- The patient's name at birth, address, telephone number, date of birth and gender;
- A summary description of the reasons for each consultation;
- X-rays, if applicable, and the results of all other examinations of the patient carried out or requested by the treating professional;
- v Diagnosis of the patient’s condition;
- A description of the professional services rendered and their date;
- Recommendations made to the patient;
- Annotations, correspondence and other documents relating to professional services rendered to the patient;
- Financial information relating to the payment of fees.
- With its employees, suppliers and business relations,
- First name;
- The name;
- The professional title;
- The business telephone number;
- Cell phone number, if applicable (if provided by the data subject);
- Professional email address;
- Personal email address, if applicable (if provided by the data subject);
- Professional postal address;
- Financial information relating to the payment of salaries or fees.
- The Clinic's professionals may collect any other personal information transmitted by a person using their contact form on its website or an email address of the clinic or the treating professional.
- With his patients,
- Professionals at the Clinic use the services of Go Rendez Vous and Acuity Scheduling to host patient files. This software stores, discloses and protects personal information in accordance with the most recent version of its confidentiality policy and in accordance with the terms and conditions provided for in the contract concluded with the professionals using their platform. This personal information may include your full name, as well as your email, as well as any information mentioned in section 2a. of this policy. You have the right at any time to request the rectification and removal of your personal information stored in accordance with the terms of its confidentiality policy.
- Method and source of collection. Personal information is generally collected by the Clinic's professionals directly from the people concerned and with their consent. The Professionals may collect personal information without the knowledge and consent of the person concerned in limited circumstances authorized by the Act respecting the protection of personal information in the private sector.
- General. The Clinic's professionals do not communicate any personal information they hold to a third party without the consent of the person to whom the personal information relates except if :
- These are business contact details whose communication is reasonable in the context of its activities;
- The transmission of information without notifying the person concerned is required for the Clinic’s professionals to comply with its legal obligations;
- The transmission of information without notifying the person concerned is required to avoid serious harm to the person targeted by the information.
- Communication to a provider of the Clinic. The Clinic professionals may not communicate personal information to a service provider unless the processing of personal information is governed by an appropriate approved contract.
- Communication outside Quebec. The Clinic professionals generally do not communicate personal information outside of Quebec. If this is the case, and before communicating personal information outside Quebec (including in another Canadian province), the Clinic's professionals must ensure that the personal information communicated will benefit from adequate protection.
Conservation and destruction
- Computerized personal information held by the the Clinic's professionals are kept using a database protected by organizational security measures.
- The Clinic's professionals keep the personal information they hold for a period of seven years after their last use except when a different retention period is provided for by law.
- After the expiration of their retention period, personal information is destroyed unless IT limitations force its retention or unless it is transmitted to a person or organization who will use it under denominalized form for study, research or statistical purposes.
Security of personal information
The Clinic's professionals take reasonable security measures to protect the personal information under its responsibility.
- Limited access. The Clinic's professionals can only access the personal information they need to carry out their duties.
- Physical Security Measures. The Clinic's professionals take the necessary measures to protect physical documents that contain personal information.
- Technological Security Measures. The Clinic's professionals must, in particular, comply with the following security measures:
- Encrypt documents that contain lists of personal information;
- Use a password to access databases containing personal information and;
- Change passwords on a regular basis.
- Administrative security measures. The Clinic's professionals implement the following security measures:
- Any person with access to personal information held by the Clinic's professionals must sign a confidentiality agreement;
Access to personal information and rectification
- Personal information collected by the Clinic’s professionals is accessible at its main place of business. The person concerned by this information can access it on request online at firstname.lastname@example.org or by post.
- The Clinic's professionals respond to requests from people who wish to access the personal information that the Clinic's professionals hold about them, by giving them access to this information, by rectifying it when it is inaccurate or incomplete, by ensuring their portability if necessary, by destroying them when their conservation is no longer necessary, or by deindexing them.
- A person concerned by personal information held by the Clinic's professionals may ask them to:
- Confirm the existence of the information and send a copy to her or any person she authorizes;
- Rectify inaccurate, incomplete, equivocal information or information that is collected, communicated or stored in a manner that is not authorized by this policy or by law;
- Delete outdated or irrelevant information.
Responsible for the protection of personal information
Dr Thanh-My Patricia Ho, chiropractor is responsible for the protection of personal information among the Clinic's professionals. She can be contacted at the email address email@example.com or at the following postal address 4823 Sherbrooke Ouest, bureau 115 Westmount Qc H4M2K9.
Roles and responsibilities of staff members
All Clinic professionals are required to respect this policy, as well as applicable laws, regulations and contractual obligations when they process, use or communicate personal information.
- Any person may file a complaint regarding the protection of personal information held by the Clinic's professionals by contacting the person responsible for the protection of personal information at the email address or postal address mentioned in paragraph 21 of this policy. .
- The person responsible for the protection of personal information must respond to the complainant within 30 days of receipt of a complaint.
- Privacy Incidents
Confidentiality incident management procedure
In the event of a confidentiality incident, the Clinic’s professionals undertake toidentify the cause of the incident;
- remedy the incident;
- reduce the risks of harm being caused and;
- prevent new incidents of the same nature from occurring.
Privacy Incident Log
The person responsible for the protection of personal information keeps a register of confidentiality incidents.
Any questions relating to this policy should be sent to the Privacy Officer of the Clinic, at the email address firstname.lastname@example.org or at the following postal address 4823 Sherbrooke Ouest, bureau 115 Westmount Qc H4M2K9 .
Policy Date: September 22, 2023
Call 514.937.6550 today to make your appointment.