Compliance
Coordinating patient care means living inside Canadian health-privacy law every day. Compliance isn't a certificate we frame on the wall — it's the shape of how the network is designed.
Frameworks
PHIPA
Where MAC handles personal health information on behalf of a health-information custodian, we act as an information manager under the Personal Health Information Protection Act and comparable provincial legislation — using and disclosing PHI only as authorized.
PIPEDA
For personal information we handle as our own, we follow the Personal Information Protection and Electronic Documents Act and applicable provincial private-sector laws — consent, purpose limitation, accountability.
SOC 2
We structure our controls around the SOC 2 Trust Services Criteria — security, availability, and confidentiality — to give partners independent assurance over how we operate.
HIPAA-aligned
While Canadian law governs the network, our safeguards are aligned with HIPAA principles so U.S.-familiar partners recognize the bar we hold ourselves to.
In Canadian health-privacy law, the custodian (a clinic, physician, or other provider) is accountable for the personal health information in its care. MAC typically operates as a service provider / information manager to those custodians: we process referral and health information under their instructions and under written agreements that constrain how we may use and disclose it. This model keeps accountability clear and keeps patients within their circle of care.
The network runs on Clinicmaster, the practice-management platform many Canadian clinics already use for scheduling, billing, and records. Building on Clinicmaster means referral coordination, appointment booking, and outcome tracking live in a system clinics already trust — reducing the number of places sensitive data has to travel, and keeping data-protection terms consolidated with a partner subject to written agreements.
We aim to keep personal health information on Canadian infrastructure. Where any processing would occur outside Canada, we assess the transfer, apply appropriate contractual and technical safeguards, and disclose it as required.
We maintain an incident-response process for detecting, containing, and investigating security incidents. In the event of a privacy breach involving personal health information, we support the relevant custodian in meeting notification obligations to affected individuals and regulators as required by PHIPA, PIPEDA, and applicable provincial law.
Clinics, partners, and prospective customers can request our security and compliance documentation — including our data-protection terms and current control summaries — through their MAC contact or at privacy@medaccesscorp.com. For personal information requests, see our Privacy Policy; for technical safeguards, see our Security overview.