Legal
Last updated: August 31, 2026 · Version 1.0
Medical Access Corp (“MAC,” “we,” “us”) operates a healthcare case-management platform that coordinates patient referrals and care between referring healthcare professionals, allied-health clinics, and specialists across Canada. Protecting the personal information and personal health information entrusted to us is fundamental to that role. This policy explains what we collect, why, how we use and disclose it, and the choices you have.
This policy applies to information we handle through our website, referral portal, and related services (together, the “Services”). It applies to referring professionals, clinic staff, and patients whose referrals move through the network.
In many cases MAC acts as a service provider / information manager to the healthcare providers who use our Services. Where we handle personal health information on behalf of a custodian (for example, a clinic or physician) under Ontario’s Personal Health Information Protection Act (PHIPA) or comparable provincial legislation, we do so under that custodian’s instructions and applicable agreements. Where we handle personal information as our own (for example, marketing contacts or account administration), we act under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy laws.
We use information to match referrals to appropriate clinics; to book appointments and coordinate care; to keep referring providers, clinics, and patients informed of progress; to operate, secure, and improve the Services; to meet legal, regulatory, and compliance obligations; and to communicate with you about your account or a referral. We do not sell personal information or personal health information.
We collect, use, and disclose personal health information for the purpose of providing and coordinating care, consistent with the consent obtained by the referring provider and the expectations of the patient’s circle of care, and as permitted or required by PHIPA and comparable laws. For personal information governed by PIPEDA, we rely on your consent (express or implied, depending on sensitivity) and other lawful bases. You may withdraw consent subject to legal and contractual limits, though doing so may prevent us from routing a referral.
We share information only as needed to deliver the Services:
PHI receives heightened protection. Access is restricted to personnel and systems that need it to perform a specific function, on a least-privilege basis, and access is logged. When we handle PHI as an information manager for a custodian, we use and disclose it only for the purposes the custodian authorizes and as permitted by PHIPA and comparable legislation.
We keep information only as long as necessary for the purposes described here, to meet legal, professional, and regulatory retention requirements, and to resolve disputes and enforce agreements. Retention of PHI follows the requirements applicable to the relevant custodian. When information is no longer required, we securely delete or de-identify it.
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, access controls, logging and monitoring, and vendor due diligence. See our Security overview for detail. No system is perfectly secure, but we work continuously to reduce risk.
Subject to applicable law, you may request access to the personal information we hold about you, ask us to correct inaccuracies, and ask questions about our handling of your information. Patient requests relating to a health record are often best directed to the custodian (your provider or clinic); we will help route such requests appropriately. To exercise a right, contact our Privacy Officer below. We will respond within the timelines required by law.
We aim to store and process personal health information on infrastructure located in Canada. Where any processing occurs outside Canada, we put appropriate contractual and technical safeguards in place and disclose this as required by applicable law.
The public website uses only what is necessary to function and, where enabled, privacy-respecting analytics to understand aggregate usage. We do not use the website to track patients across unrelated sites. Fonts are self-hosted, so viewing the site does not send your browser to third-party font servers. If we introduce analytics or cookies that require consent, we will present a consent mechanism.
We may update this policy to reflect changes to the Services or the law. We will revise the “Last updated” date and, for material changes, provide additional notice.
Questions, access requests, or complaints can be directed to our Privacy Officer at privacy@medaccesscorp.com, or via our contact page. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.