Terms of use and Privacy policy
Last updated: September 12, 2024 - version 1.0
Stéphanie Thibault-Gagnon physiotherapist (pht) is committed to protecting the right to privacy of all people about whom personal information is collected.
The protection of the privacy of individuals and personal information is included in provincial and federal legislation. The company and all those who work there undertake to comply with its obligations and directives by complying with the various legal modalities regarding the protection of personal information.
By providing personal information to us (through our website or patient portal, by email, in person or by telephone), you agree that it will be treated as set out in this policy on the protection of personal information, and you authorize Stéphanie Thibault-Gagnon physiotherapist to process your personal information for the purposes set out below.
What personal information do we collect?
We only collect personal information that is necessary for the creation of your file and your follow-up such as:
Contact information, such as name, address, email address and telephone number;
-
Medical observations, a summary of any communications and diagnoses;
-
Requests for consultations, reports, orders, reports and requests for examinations;
-
A summary of your medical history (medications, allergies, etc.)
-
Where applicable, evidence of consent given to us in circumstances where such consent is necessary for the processing of personal information;
Who can see your personal information?
Access to personal information will be limited to Stéphanie Thibault-Gagnon pht. Stéphanie Thibault-Gagnon pht will treat the information strictly confidentially and will not give access to this information to any unauthorized person.
Stéphanie Thibault-Gagnon pht uses the “Datedechoix” platform to make appointments at the Rosemont Clinic, at the Homatherapy center and virtually. Thus, the information you enter when making an appointment will be recorded in the Datedechoix servers located in Canada. See their privacy policy here: https://www.datedechoix.com/modalites.php
Regarding the new provisions of Law 25 on the protection of user data, we would like to provide you with information on the servers where Datedechoix data is hosted:
-
The servers are in Canada and will remain there;
-
Very limited access is assigned to servers and this access is always recorded;
-
A recent change now places a layer of security in front of the servers that prevents users from knowing the address of the servers and checks each access for attempts to bypass security
-
All servers use a secure and limited operating system to limit vulnerabilities;
-
Access to servers is recorded by IP address and per request.
Roles within the company
We are responsible for protecting the confidentiality of the personal information we have under the internal confidentiality policy, from the collection of the information to its destruction.
We have an obligation of confidentiality arising from the patient-professional relationship with regard to the protection of this information. They are subject to the law on the protection of personal information and constantly ensure compliance in their practice.
Stéphanie Thibault-Gagnon pht is responsible for the protection of personal information in the company, she must:
-
Ensure compliance and implementation of Law 25;
-
Respond to requests for access, rectification, cessation of dissemination, deindexing;
-
Approve governance rules regarding personal information;
-
Keep records of communications of personal information without the consent of the person concerned, including in the event of a confidentiality incident;
-
Be notified in the event of any confidentiality incident;
-
Be consulted when assessing the risk of harm being caused to a person whose personal information is affected by a confidentiality incident;
How do we protect your personal information?
From the collection of information to the destruction of collected information, we have implemented appropriate administrative, technical and physical measures to protect personal information against loss or theft, access, use or disclosure. unauthorized modification, modification or destruction.
We are committed to collecting only necessary and useful data, and to limiting the use, disclosure and retention of personal information. We have implemented protective measures and limited access in order to comply with the law.
Consent
The information must be collected or disclosed with the knowledge and consent of the person in question. Consent is a thought-out act that meets these characteristics:
-
It must be manifest, that is to say obvious, without doubt, indisputable;
-
It must be free, that is to say without constraint;
-
It must be enlightened, that is to say specific, precise and rigorous;
-
It is also given for specific purposes for a specific period of time;
We will not use your personal information without your consent, unless it is to be used for the same purposes for which the information was originally collected or compiled, if the use is compatible with that purpose or if it is to be used for a purpose set out in subsection 8(2) of the Privacy Act.
Complaint procedure
If you believe that your personal information is not secure in our clinic or that a confidentiality incident involving personal information may have occurred, you can contact Stéphanie Thibault-Gagnon, pht at 514-992-2905, or at physioperineale@gmail.com. A complaint form will be completed and analyzed by management.
In the event of a real confidentiality incident involving personal information, Stéphanie Thibault-Gagnon pht undertakes to:
-
Take reasonable measures to reduce the risk of harm being caused to the persons concerned and prevent new incidents of the same nature from recurring;
-
Notify the "Commission d'accès à l'information";
-
Enter all confidentiality incidents in the incident register.