Sapphire Digital Health Solutions Inc. is committed to the privacy and security of your personal information. All medical and personal information collected by Sapphire Digital Health Solutions Inc. is used exclusively for the benefit of the client­—for faster, safer, more effective healthcare through innovation.

Sapphire Privacy Principles

  1. Patient consent drives all data handling events.

Client consent is required for any transmission or sharing of our patients’ private medical data. Under no circumstances will a transmission of data occur without client consent and direction.

  1. Information transmission activities are solely for the enhancement of our clients’ medical care and professional service needs.

Sapphire Digital Health Solutions Inc. manages private medical data only for the purposes of enhancing client health services and outcomes. At no time will Sapphire Digital Health Solutions Inc. use client information for research, data mining, or biostatistics purposes.

  1. Sapphire Digital Health Solutions Inc. specializes in medical data management services.

Sapphire Digital Health Solutions Inc. manages medical information on behalf of our patients for the sole purpose of reducing risk for patients’ service quality and health outcomes from data which is: fragmented, inaccurate, or inaccessible when it is needed most. This is why we manage medical data using the most comprehensive and accurate physician-designed database available.

  1. Medical data disclosure & transmission is entirely client-directed.

Portal-based data transmission can only occur with the provision of a CLIENT ID and PASSWORD to a health professional. In the case on non-portal based transmission, without client instruction, no transmission of any client’s private medical information ever will occur.

  1. Transmission events of medical data are protected.

Sapphire Digital Health Solutions Inc. transmits or shares data upon patient instruction through several secure mechanisms.

Web-based Sapphire portal systems:

Data transmissions via the world wide web utilize the Sapphire Digital Health Solutions Inc. data portal found at:

https://sapphirehealth.awsapps.com/workdocs/

Information transmitted electronically through the portal is executed only with a CLIENT ID and PASSWORD – which the client must provide to the health professional or third party to complete. Transmissions are encrypted in transit and at rest, combined with identity anonymization so it contains no patient names or identifiers. Our systems keep an audit record of data access events for all accounts and robust permission models ensure that data is only seen by those for whom it is intended.

Direct data transmission:

Only under written direction by the client or his/her power of attorney will Sapphire Digital Health Solutions Inc. transmit client data. Receiving health professional license numbers are confirmed to be accurate and active if a receiving party is a physician office. Third party requests for private medical information will be provided only directly to a Sapphire client or their power of attorney.

Tertiary data transmission mechanisms:

Sapphire Digital Health Solutions Inc. is pleased to facilitate faster, safer, more effective healthcare decisions for our clients by managing their medical data through innovation. These transmission systems and technologies will only be provided to the client themselves or their power of attorney with written instruction. These mechanisms include but are not limited to Sapphire documents for use by hotkey, CD ROM, smartcard systems, and PDA/handheld devices – whichever suits our clients best.

  1. Storage systems for medical data are secure.

Sapphire-managed private medical data and systems are protected by highly secure technology provided through Amazon Web Services, the world leader in public cloud infrastructure. For more information please review the following link for this important Sapphire strategic partner: aws.amazon.com

  1. Legislative compliance.

Sapphire Digital Health Solutions Inc. complies with all Federal and Provincial legislation regarding the collection, maintenance, and disclosure of private medical information. In addition, Sapphire Digital Health Solutions complies with regulations and policies on health information management from the Royal College of Physicians and Surgeons of Canada and The Ontario College of Physicians and Surgeons. Sapphire Digital does not charge for provincially insured services.

  1. Responsivity to client privacy concerns.

Transparency of our medical data management activities is important to all of our clients. Please contact Sapphire Digital Health Solutions Inc. with questions regarding our privacy policy at 519.725.5900

Corporations Under Contract

Sapphire Digital Health Solutions’ policy on privacy and confidentiality for the individual and their medical data extends to include all organizations to which we provide contracted corporate services for medical information management and related activities.

At no time will the identity of any firm or organization serviced by Sapphire Digital Health Solutions, or the identity of those individuals serviced under such contractual arrangements, be shared with any third party for the purpose of advertising or promotion without written consent. The disclosure of any corporation or organization under contract with Sapphire Digital Health Solutions to any third party will only occur upon written instruction from said organization.