Canadian-region hosting
Patient data systems are hosted through Supabase Canadian Region and AWS Canadian Region.
How TrueCare protects personal information and personal health information for Canadian patients receiving virtual care.
Patient data systems are hosted through Supabase Canadian Region and AWS Canadian Region.
TrueCare is a U.S.-based company serving Canadian patients through U.S.-based physicians licensed, registered, or otherwise authorized in applicable Canadian provinces or territories.
Our program is designed around PIPEDA, HIPAA, PHIPA, HIA, and other applicable privacy and health privacy requirements.
Privacy questions and requests can be sent to Slaven Savic at slaven@truecarecanada.com.
This Privacy Policy and Notice of Privacy Practices explains how True Care Health Services LLC, doing business as TrueCare, collects, uses, discloses, stores, protects, and manages personal information and personal health information when you use our website, patient portal, virtual care services, intake forms, communications, and related services.
This Notice also describes how medical information about you may be used and disclosed and how you can access that information.
Please review it carefully.
TrueCare is a U.S.-based digital health company providing virtual family medicine services to patients in Canada.
TrueCare works with U.S.-based physicians who are licensed, registered, or otherwise authorized to provide care in the applicable Canadian province or territory where the patient is located.
In this Policy, “TrueCare,” “we,” “us,” and “our” means:
True Care Health Services LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
Because of our operating model, your information may be handled under multiple privacy and health privacy frameworks, including:
Where more than one privacy law applies, TrueCare aims to follow the requirement that provides appropriate protection for your information.
TrueCare has designated a Privacy Officer responsible for privacy oversight, patient privacy requests, privacy complaints, breach response, vendor privacy review, and compliance monitoring.
Privacy Officer
Slaven Savic
True Care Health Services LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
This Policy applies to information collected through:
This Policy applies to patients, prospective patients, website visitors, authorized caregivers, substitute decision-makers, parents or guardians where applicable, and other individuals who interact with TrueCare.
We collect only the information we reasonably need to provide care, operate our services, meet legal obligations, protect patients, and maintain secure systems.
We may collect:
We may collect information needed to verify your identity, determine whether we can provide services in your province or territory, and satisfy professional, legal, or regulatory requirements.
This may include:
We do not ask for a Social Insurance Number unless it is legally required for a specific purpose.
We may collect personal health information, including:
When you use our virtual care services, we may collect:
TrueCare does not record virtual visits unless we have obtained consent or authorization where required by law and explained the purpose of the recording.
We may collect billing-related information, such as:
We may use third-party payment processors. TrueCare does not intentionally store full credit card numbers unless specifically required and protected through approved systems.
When you visit our website or use our portal, we may collect:
This information helps us secure our systems, understand site performance, prevent fraud or abuse, and improve the user experience.
We use personal information and personal health information for purposes that a reasonable person would consider appropriate in the context of virtual health care.
We may use your information to:
We may also use de-identified or aggregated information that does not reasonably identify you for analytics, reporting, quality improvement, service planning, and compliance review.
Because health information is sensitive, we use clear consent and authorization processes.
We may ask for your express consent or written authorization when required, including for:
In some care-related situations, applicable law may allow implied consent or permitted use and disclosure without new consent, such as sharing information with another provider involved in your care.
You may withdraw consent or revoke an authorization, subject to legal, clinical, regulatory, and recordkeeping obligations. Withdrawal does not affect actions we already took based on your previous consent or authorization.
To withdraw consent or ask questions about consent, contact:
Privacy Officer
Slaven Savic
We do not sell your personal health information.
We may share information only as permitted or required by law, with appropriate safeguards, and only for legitimate purposes.
We share information with TrueCare physicians and authorized care team members so they can provide care, document visits, coordinate treatment, and support your health needs.
With your consent or where permitted by law, we may share relevant information with other providers involved in your care, such as family physicians, specialists, laboratories, pharmacies, hospitals, or other care providers.
We may use vendors and technology providers to support services such as:
These providers may only use your information to provide services to TrueCare and must protect it through contracts and safeguards.
For U.S. health information subject to HIPAA, vendors that handle protected health information must sign appropriate Business Associate Agreements where required.
We may share information with a parent, guardian, substitute decision-maker, caregiver, or other representative when you authorize it or when applicable law allows or requires it.
Some minors may have independent privacy rights depending on capacity, province or territory, and applicable health law.
We may disclose information when required or permitted by law, including to:
If TrueCare is involved in a merger, financing, acquisition, corporate reorganization, or sale of assets, information may be disclosed as part of that transaction, subject to confidentiality protections and applicable law.
Patient data systems are hosted through Supabase Canadian Region and AWS Canadian Region.
Canadian Region
Supabase
Canadian Region
AWS
TrueCare's goal is to use Canadian-region hosting for patient information where practical and appropriate.
However, TrueCare is a U.S.-based company, and our physicians, workforce members, contractors, or support personnel may access information from the United States or other approved locations when needed to provide care, operate services, support systems, or meet legal obligations.
This means your personal information and personal health information may be accessed, processed, or handled from outside Canada, including from the United States.
When information is accessed or processed outside Canada, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement, national security authorities, regulators, or professional oversight bodies.
TrueCare uses contractual, administrative, technical, and physical safeguards designed to protect information involved in cross-border processing. These may include:
For patients in provinces with additional cross-border requirements, TrueCare will take steps designed to comply with applicable provincial rules before transferring, accessing, or processing information outside that province where required.
We use safeguards appropriate to the sensitivity of health information.
No system can be guaranteed to be completely secure, but we work to protect your information using safeguards designed for sensitive health information.
We keep personal information and personal health information only as long as necessary for:
Clinical records may need to be kept for several years depending on the applicable province, professional rules, and legal requirements. HIPAA-related documentation may also need to be retained according to U.S. requirements.
When information is no longer required, we securely destroy, delete, de-identify, or archive it in accordance with our retention schedule and applicable law.
Depending on your location and the laws that apply, you may have rights to:
We may need to verify your identity before processing a request.
TrueCare generally aims to acknowledge access and correction requests within 5 business days and respond within 30 days unless a different timeline is required or permitted by law.
To make a request, contact:
Privacy Officer
Slaven Savic
True Care Health Services LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
For information subject to HIPAA, TrueCare follows HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule.
Under HIPAA, TrueCare may use or disclose protected health information for treatment, payment, and health care operations, as well as other purposes permitted or required by law.
We may use and disclose your information to provide, coordinate, or manage your care.
Example:A TrueCare physician reviews your intake form and documents your virtual consultation.
We may use and disclose information to bill and collect payment for services.
Example:We process payment information or confirm subscription status.
We may use and disclose information to operate and improve our health care services.
Example:We may use information for quality review, compliance audits, provider support, training, security, or administrative operations.
We may use or disclose information when required or permitted by law, including for health oversight, regulatory reporting, legal proceedings, public health activities, or to prevent serious harm.
We will obtain written authorization where required by HIPAA, including for most uses or disclosures not related to treatment, payment, health care operations, or another legally permitted purpose.
You may revoke an authorization in writing, except to the extent we already relied on it.
For information subject to HIPAA, TrueCare is required to:
For Ontario patients and Ontario-related services, TrueCare follows Ontario's Personal Health Information Protection Act where applicable.
For Ontario personal health information, TrueCare aims to:
For Alberta patients and Alberta-related services, TrueCare follows Alberta's Health Information Act where applicable.
For Alberta health information, TrueCare aims to:
If we discover a privacy or security incident involving personal information or personal health information, we will:
Contain
Stop the incident from continuing or expanding.
Investigate
Determine what happened, when, and what was involved.
Assess the risk of harm
Evaluate the potential impact on affected individuals.
Notify where required
Inform affected individuals and regulators as required by law.
Document
Record the incident, response, and lessons learned.
Reduce the risk of recurrence
Update safeguards, processes, training, or vendors.
Depending on the circumstances and applicable law, reports may be made to Canadian privacy regulators, provincial health privacy regulators, the U.S. Department of Health and Human Services Office for Civil Rights, professional colleges, or other authorities.
TrueCare maintains internal breach response procedures and requires workforce members, physicians, contractors, and vendors to report suspected privacy or security incidents promptly.
We may use cookies and similar technologies to:
You can adjust cookie settings in your browser. Some website or portal features may not work properly if cookies are disabled.
We do not use cookies to sell personal health information.
We may send service-related communications, such as:
Email and text messages may not be fully secure. For sensitive health information, we encourage you to use the secure patient portal whenever possible.
You may opt out of non-essential marketing communications, but we may still send service, care, safety, legal, or administrative messages.
TrueCare may provide care to minors where permitted by law and professional requirements.
A parent, guardian, substitute decision-maker, or authorized representative may exercise privacy rights on behalf of a patient where legally permitted.
Depending on the province or territory, a minor who is capable of making certain health decisions may have independent privacy rights. We will handle minor patient information according to applicable law, clinical obligations, and professional standards.
Our website or portal may link to third-party websites or services. We are not responsible for the privacy practices of third parties that we do not control. Please review their privacy policies before providing information to them.
We may update this Policy from time to time to reflect changes in our services, laws, technology, or privacy practices.
When we make material changes, we will update the “Last Updated” date and provide notice where required.
For questions, access requests, correction requests, consent withdrawal, complaints, or privacy concerns, contact:
TrueCare Privacy Officer
Slaven Savic
True Care Health Services LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
You may also have the right to contact a privacy regulator, including:
TrueCare will not retaliate against you for filing a privacy complaint.
Contact TrueCare's Privacy Officer for privacy questions, access requests, correction requests, consent withdrawal, or complaints.
Email Privacy OfficerSlaven Savic
slaven@truecarecanada.comTrue Care Health Services LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States