Our Compliance Framework
MyKidzHealth is built on a foundation of regulatory compliance, clinical integrity, and data security — so Ontario families can trust us with their most important asset.
Last reviewed: April 20, 2026
MyKidzHealth is a virtual care supplement — not an emergency service. In any medical emergency, call 911 or visit the nearest emergency department immediately. This compliance page is for informational purposes and does not constitute legal or regulatory advice.
PHIPA Compliance
Personal Health Information Protection Act (Ontario)
- All personal health information (PHI) is collected, used, and disclosed only for purposes of providing or facilitating care, or as otherwise permitted under PHIPA.
- We have appointed a Privacy Officer responsible for overseeing PHI governance and responding to access and correction requests.
- PHI is stored exclusively on servers located within Canada, using AES-256 encryption at rest and TLS 1.3 in transit.
- Breach notification procedures are in place in accordance with PHIPA requirements, including reporting to the IPC and affected individuals where required.
PIPEDA Compliance
Personal Information Protection and Electronic Documents Act
- We collect only the personal information necessary for the purposes identified at the time of collection. Consent is obtained before or at the time of collection.
- Users may withdraw consent for non-essential uses at any time without penalty, subject to legal and contractual obligations.
- We provide individuals with access to their personal information upon request, subject to limited exceptions permitted by law.
- Our accountability framework includes internal policies, staff training, and third-party vendor management to ensure PIPEDA principles are upheld throughout our operations.
Clinical Licensing
Ontario Regulated Health Professions
- All clinicians providing care through MyKidzHealth hold active, unrestricted licences with their respective Ontario regulatory colleges — including the College of Physicians and Surgeons of Ontario (CPSO) and the College of Nurses of Ontario (CNO).
- Clinicians are verified prior to onboarding and subject to ongoing credential monitoring.
- Our clinical protocols align with the Regulated Health Professions Act (RHPA) and applicable college standards for virtual care delivery.
- Prescriptions issued through our platform comply with Ontario's Drug and Pharmacies Regulation Act and applicable CPSO prescribing guidelines for telemedicine.
Health Records
Ontario's Health Records Standard
- Clinical records are maintained in accordance with the Health Records Act of Ontario, with minimum retention periods of 10 years or until a patient reaches age 28, whichever is longer.
- Records are stored in structured formats enabling accurate retrieval, and are accessible to patients upon request in compliance with PHIPA.
- We support continuity of care by providing consultation summaries to patients and, with consent, to their primary care providers.
Data Security
Technical & Organizational Safeguards
- Our platform infrastructure is hosted on SOC 2 Type II certified cloud infrastructure within Canada.
- Access controls enforce the principle of least privilege. Multi-factor authentication (MFA) is required for all clinical staff and administrative accounts.
- Automated vulnerability scanning, intrusion detection, and regular third-party penetration testing are part of our security program.
- A formal Incident Response Plan is maintained and tested annually, with defined escalation procedures for security and privacy events.
Telehealth Standards
Virtual Care Best Practices
- Our telehealth practices align with the CPSO's Policy for Telemedicine and guidance from the Ontario Telemedicine Network (OTN).
- Clinicians obtain informed consent for virtual care at the start of each encounter and document this in the clinical record.
- We maintain clear scope-of-practice boundaries — escalating to in-person or emergency care when the virtual setting is insufficient for safe assessment.
- Patient identity verification is performed at each consultation to ensure care is delivered to the correct individual.
Compliance questions? Contact us at info@mykidzhealth.ca