Secure. Private. Canadian.
Privacy-first virtual care

Privacy & Compliance

How TrueCare protects personal information and personal health information for Canadian patients receiving virtual care.

  • Effective DateMay 28, 2026
  • Last UpdatedMay 28, 2026
  • Legal EntityTrue Care Health Services LLC

Canadian-region hosting

Patient data systems are hosted through Supabase Canadian Region and AWS Canadian Region.

Cross-border care model

TrueCare is a U.S.-based company serving Canadian patients through U.S.-based physicians licensed, registered, or otherwise authorized in applicable Canadian provinces or territories.

Privacy frameworks

Our program is designed around PIPEDA, HIPAA, PHIPA, HIA, and other applicable privacy and health privacy requirements.

Privacy Officer

Privacy questions and requests can be sent to Slaven Savic at slaven@truecarecanada.com.

Privacy Policy & Notice of Privacy Practices

This Privacy Policy and Notice of Privacy Practices explains how True Care Health Services LLC, doing business as TrueCare, collects, uses, discloses, stores, protects, and manages personal information and personal health information when you use our website, patient portal, virtual care services, intake forms, communications, and related services.

This Notice also describes how medical information about you may be used and disclosed and how you can access that information.

Please review it carefully.

01

Who We Are

TrueCare is a U.S.-based digital health company providing virtual family medicine services to patients in Canada.

TrueCare works with U.S.-based physicians who are licensed, registered, or otherwise authorized to provide care in the applicable Canadian province or territory where the patient is located.

In this Policy, “TrueCare,” “we,” “us,” and “our” means:

True Care Health Services LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

United States

Because of our operating model, your information may be handled under multiple privacy and health privacy frameworks, including:

  • Canadian federal privacy law, including PIPEDA
  • Applicable provincial health privacy laws, including Ontario’s PHIPA and Alberta’s HIA where applicable
  • U.S. health privacy law, including HIPAA, for our U.S. operations and U.S.-based physicians
  • Other applicable provincial, territorial, state, professional, or regulatory requirements

Where more than one privacy law applies, TrueCare aims to follow the requirement that provides appropriate protection for your information.

02

Privacy Officer

TrueCare has designated a Privacy Officer responsible for privacy oversight, patient privacy requests, privacy complaints, breach response, vendor privacy review, and compliance monitoring.

Privacy Officer

Slaven Savic

slaven@truecarecanada.com

Mailing Address

True Care Health Services LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

United States

03

Scope of This Policy

This Policy applies to information collected through:

  • The TrueCare website
  • The TrueCare patient portal
  • Patient registration and waitlist forms
  • Virtual consultations
  • Secure messages, emails, texts, phone calls, and support requests
  • Billing, payment, and administrative workflows
  • Physician notes, clinical documentation, and medical records
  • Interactions with our care team, support team, contractors, vendors, and authorized representatives

This Policy applies to patients, prospective patients, website visitors, authorized caregivers, substitute decision-makers, parents or guardians where applicable, and other individuals who interact with TrueCare.

04

Information We Collect

We collect only the information we reasonably need to provide care, operate our services, meet legal obligations, protect patients, and maintain secure systems.

Account and Contact Information

We may collect:

  • Name
  • Date of birth
  • Email address
  • Phone number
  • Mailing address
  • Province or territory of residence
  • Login credentials
  • Patient portal account information
  • Emergency contact information where appropriate

Identity and Eligibility Information

We may collect information needed to verify your identity, determine whether we can provide services in your province or territory, and satisfy professional, legal, or regulatory requirements.

This may include:

  • Government-issued identification information where required
  • Provincial health card or health number where applicable
  • Residency or location information
  • Information needed to verify your age, identity, or authority to act for another person

We do not ask for a Social Insurance Number unless it is legally required for a specific purpose.

Health and Medical Information

We may collect personal health information, including:

  • Symptoms
  • Medical history
  • Medications
  • Allergies
  • Family history
  • Mental health information where relevant to care
  • Lab results or diagnostic information you provide
  • Care plans
  • Physician notes
  • Consultation notes
  • Treatment recommendations
  • Referrals
  • Secure messages with clinicians
  • Virtual visit information
  • Documents you upload to the portal

Virtual Care Information

When you use our virtual care services, we may collect:

  • Appointment details
  • Consultation notes
  • Secure messages exchanged with providers
  • Technical information needed to connect you to a visit
  • Audio, video, or chat information if required for the service

TrueCare does not record virtual visits unless we have obtained consent or authorization where required by law and explained the purpose of the recording.

Payment and Billing Information

We may collect billing-related information, such as:

  • Payment status
  • Transaction details
  • Invoices
  • Subscription or membership information
  • Limited payment information processed through our payment provider

We may use third-party payment processors. TrueCare does not intentionally store full credit card numbers unless specifically required and protected through approved systems.

Website and Technical Information

When you visit our website or use our portal, we may collect:

  • IP address
  • Browser type
  • Device type
  • Pages visited
  • Referral source
  • Approximate location derived from device or browser data
  • Cookies and similar technologies
  • Security logs
  • Usage data

This information helps us secure our systems, understand site performance, prevent fraud or abuse, and improve the user experience.

05

How We Use Your Information

We use personal information and personal health information for purposes that a reasonable person would consider appropriate in the context of virtual health care.

We may use your information to:

  • Register you as a patient or prospective patient
  • Determine whether TrueCare services are available in your province or territory
  • Schedule and manage appointments
  • Verify your identity
  • Provide virtual consultations and clinical care
  • Maintain medical records
  • Coordinate care with physicians and other providers
  • Respond to your questions and support requests
  • Process payments and billing
  • Send service-related messages, appointment reminders, and portal notifications
  • Obtain and manage consent
  • Operate, secure, audit, and improve our systems
  • Train workforce members on privacy, security, and service quality using appropriate safeguards
  • Detect, investigate, and prevent privacy or security incidents
  • Comply with legal, regulatory, professional, licensing, and reporting obligations
  • Respond to patient access, correction, amendment, or complaint requests

We may also use de-identified or aggregated information that does not reasonably identify you for analytics, reporting, quality improvement, service planning, and compliance review.

07

How We Share Information

We do not sell your personal health information.

We may share information only as permitted or required by law, with appropriate safeguards, and only for legitimate purposes.

Physicians and Care Team Members

We share information with TrueCare physicians and authorized care team members so they can provide care, document visits, coordinate treatment, and support your health needs.

Other Health Care Providers

With your consent or where permitted by law, we may share relevant information with other providers involved in your care, such as family physicians, specialists, laboratories, pharmacies, hospitals, or other care providers.

Service Providers and Vendors

We may use vendors and technology providers to support services such as:

  • Secure cloud hosting
  • Patient portal technology
  • Encrypted video visits
  • Appointment scheduling
  • Payment processing
  • Customer support
  • Security monitoring
  • Analytics
  • Communications

These providers may only use your information to provide services to TrueCare and must protect it through contracts and safeguards.

For U.S. health information subject to HIPAA, vendors that handle protected health information must sign appropriate Business Associate Agreements where required.

Family Members, Caregivers, or Authorized Representatives

We may share information with a parent, guardian, substitute decision-maker, caregiver, or other representative when you authorize it or when applicable law allows or requires it.

Some minors may have independent privacy rights depending on capacity, province or territory, and applicable health law.

Legal, Regulatory, Licensing, or Safety Reasons

We may disclose information when required or permitted by law, including to:

  • Comply with a court order, subpoena, warrant, or legal process
  • Respond to regulators, privacy commissioners, medical boards, colleges, or oversight bodies
  • Report certain privacy or security incidents
  • Report public health or safety matters where required
  • Prevent or respond to a serious threat to health or safety
  • Defend legal claims or enforce agreements

Business Transactions

If TrueCare is involved in a merger, financing, acquisition, corporate reorganization, or sale of assets, information may be disclosed as part of that transaction, subject to confidentiality protections and applicable law.

08

Data Hosting, Storage, and Cross-Border Processing

Patient data systems are hosted through Supabase Canadian Region and AWS Canadian Region.

Canadian Region

Supabase

Canadian Region

AWS

TrueCare's goal is to use Canadian-region hosting for patient information where practical and appropriate.

However, TrueCare is a U.S.-based company, and our physicians, workforce members, contractors, or support personnel may access information from the United States or other approved locations when needed to provide care, operate services, support systems, or meet legal obligations.

This means your personal information and personal health information may be accessed, processed, or handled from outside Canada, including from the United States.

When information is accessed or processed outside Canada, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement, national security authorities, regulators, or professional oversight bodies.

TrueCare uses contractual, administrative, technical, and physical safeguards designed to protect information involved in cross-border processing. These may include:

  • Vendor due diligence
  • Written agreements
  • Business Associate Agreements where required by HIPAA
  • Privacy impact assessments where required
  • Access controls
  • Multi-factor authentication
  • Encryption in transit and at rest
  • Audit logging
  • Breach notification obligations
  • Secure deletion requirements
  • Workforce confidentiality and privacy training

For patients in provinces with additional cross-border requirements, TrueCare will take steps designed to comply with applicable provincial rules before transferring, accessing, or processing information outside that province where required.

09

How We Protect Information

We use safeguards appropriate to the sensitivity of health information.

  • Secure patient portal access
  • Approved encrypted telehealth platforms
  • Encryption in transit and at rest
  • Multi-factor authentication
  • Role-based access controls
  • Audit logs
  • Secure cloud environments
  • Workforce privacy and security training
  • Confidentiality obligations
  • Vendor privacy and security review
  • Privacy impact assessments where required
  • Incident response procedures
  • Secure disposal and certified deletion where appropriate

No system can be guaranteed to be completely secure, but we work to protect your information using safeguards designed for sensitive health information.

10

Retention and Secure Destruction

We keep personal information and personal health information only as long as necessary for:

  • Providing care
  • Maintaining medical records
  • Legal and professional obligations
  • Billing and accounting
  • Audits and compliance
  • Privacy, security, and dispute resolution
  • Regulatory requirements

Clinical records may need to be kept for several years depending on the applicable province, professional rules, and legal requirements. HIPAA-related documentation may also need to be retained according to U.S. requirements.

When information is no longer required, we securely destroy, delete, de-identify, or archive it in accordance with our retention schedule and applicable law.

11

Your Privacy Rights

Depending on your location and the laws that apply, you may have rights to:

  • Access your personal information or personal health information
  • Request a copy of your health record
  • Request correction or amendment of inaccurate or incomplete information
  • Withdraw consent or revoke authorization, subject to legal limits
  • Request restrictions on certain uses or disclosures
  • Request confidential communications
  • Receive an accounting of certain disclosures where required by law
  • Ask questions about our privacy practices
  • File a privacy complaint without retaliation
  • Opt out of marketing communications
  • Request deletion or de-identification of certain non-clinical information where legally available

We may need to verify your identity before processing a request.

TrueCare generally aims to acknowledge access and correction requests within 5 business days and respond within 30 days unless a different timeline is required or permitted by law.

To make a request, contact:

Privacy Officer

Slaven Savic

slaven@truecarecanada.com

Mailing Address

True Care Health Services LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

United States

12

HIPAA Notice of Privacy Practices

For information subject to HIPAA, TrueCare follows HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule.

Under HIPAA, TrueCare may use or disclose protected health information for treatment, payment, and health care operations, as well as other purposes permitted or required by law.

Treatment

We may use and disclose your information to provide, coordinate, or manage your care.

Example:A TrueCare physician reviews your intake form and documents your virtual consultation.

Payment

We may use and disclose information to bill and collect payment for services.

Example:We process payment information or confirm subscription status.

Health Care Operations

We may use and disclose information to operate and improve our health care services.

Example:We may use information for quality review, compliance audits, provider support, training, security, or administrative operations.

As Required or Permitted by Law

We may use or disclose information when required or permitted by law, including for health oversight, regulatory reporting, legal proceedings, public health activities, or to prevent serious harm.

Uses Requiring Authorization

We will obtain written authorization where required by HIPAA, including for most uses or disclosures not related to treatment, payment, health care operations, or another legally permitted purpose.

You may revoke an authorization in writing, except to the extent we already relied on it.

Our HIPAA Duties

For information subject to HIPAA, TrueCare is required to:

  • Maintain the privacy and security of protected health information
  • Provide this Notice of Privacy Practices
  • Follow the terms of the Notice currently in effect
  • Notify affected individuals following certain breaches of unsecured protected health information
  • Protect patients from retaliation for filing privacy complaints
13

Ontario PHIPA Notice

For Ontario patients and Ontario-related services, TrueCare follows Ontario's Personal Health Information Protection Act where applicable.

For Ontario personal health information, TrueCare aims to:

  • Collect, use, and disclose personal health information only with consent or as otherwise permitted or required by PHIPA
  • Use implied consent only where permitted, such as within the circle of care
  • Obtain express consent for recordings, marketing, or non-routine disclosures where required
  • Make our information practices available to patients
  • Protect personal health information with reasonable safeguards
  • Respond to access and correction requests within applicable timelines
  • Notify affected individuals and the Information and Privacy Commissioner of Ontario where required
14

Alberta HIA Notice

For Alberta patients and Alberta-related services, TrueCare follows Alberta's Health Information Act where applicable.

For Alberta health information, TrueCare aims to:

  • Collect, use, and disclose health information only as authorized by the HIA
  • Obtain consent where required
  • Collect only the health information reasonably necessary for care or permitted purposes
  • Protect health information with reasonable administrative, technical, and physical safeguards
  • Complete privacy impact assessments where required
  • Respond to access and correction requests as required
  • Notify affected individuals, the Alberta Information and Privacy Commissioner, and the Minister of Health where required following certain breaches
15

Privacy Breaches and Incident Response

If we discover a privacy or security incident involving personal information or personal health information, we will:

  1. 01

    Contain

    Stop the incident from continuing or expanding.

  2. 02

    Investigate

    Determine what happened, when, and what was involved.

  3. 03

    Assess the risk of harm

    Evaluate the potential impact on affected individuals.

  4. 04

    Notify where required

    Inform affected individuals and regulators as required by law.

  5. 05

    Document

    Record the incident, response, and lessons learned.

  6. 06

    Reduce the risk of recurrence

    Update safeguards, processes, training, or vendors.

Depending on the circumstances and applicable law, reports may be made to Canadian privacy regulators, provincial health privacy regulators, the U.S. Department of Health and Human Services Office for Civil Rights, professional colleges, or other authorities.

TrueCare maintains internal breach response procedures and requires workforce members, physicians, contractors, and vendors to report suspected privacy or security incidents promptly.

16

Cookies and Website Analytics

We may use cookies and similar technologies to:

  • Keep the website functioning
  • Remember preferences
  • Improve performance
  • Understand traffic patterns
  • Secure our website and portal
  • Prevent fraud or abuse

You can adjust cookie settings in your browser. Some website or portal features may not work properly if cookies are disabled.

We do not use cookies to sell personal health information.

17

Email, Text, and Communications

We may send service-related communications, such as:

  • Appointment reminders
  • Portal notifications
  • Registration updates
  • Billing notices
  • Security alerts
  • Administrative messages

Email and text messages may not be fully secure. For sensitive health information, we encourage you to use the secure patient portal whenever possible.

You may opt out of non-essential marketing communications, but we may still send service, care, safety, legal, or administrative messages.

18

Children, Minors, Parents, and Representatives

TrueCare may provide care to minors where permitted by law and professional requirements.

A parent, guardian, substitute decision-maker, or authorized representative may exercise privacy rights on behalf of a patient where legally permitted.

Depending on the province or territory, a minor who is capable of making certain health decisions may have independent privacy rights. We will handle minor patient information according to applicable law, clinical obligations, and professional standards.

19

Third-Party Links

Our website or portal may link to third-party websites or services. We are not responsible for the privacy practices of third parties that we do not control. Please review their privacy policies before providing information to them.

20

Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, laws, technology, or privacy practices.

When we make material changes, we will update the “Last Updated” date and provide notice where required.

21

Contact Us

For questions, access requests, correction requests, consent withdrawal, complaints, or privacy concerns, contact:

TrueCare Privacy Officer

Slaven Savic

slaven@truecarecanada.com

Mailing Address

True Care Health Services LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

United States

You may also have the right to contact a privacy regulator, including:

  • The Office of the Privacy Commissioner of Canada
  • The Information and Privacy Commissioner of Ontario, for Ontario PHIPA matters
  • The Office of the Information and Privacy Commissioner of Alberta, for Alberta HIA matters
  • Your applicable provincial or territorial privacy regulator
  • The U.S. Department of Health and Human Services Office for Civil Rights, for HIPAA matters

TrueCare will not retaliate against you for filing a privacy complaint.

Questions about privacy or compliance?

Contact TrueCare's Privacy Officer for privacy questions, access requests, correction requests, consent withdrawal, or complaints.

Email Privacy Officer
Privacy Officer

Slaven Savic

slaven@truecarecanada.com

True Care Health Services LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

United States