Med Copilot
Back

Security Overview

This is a working draft prepared to support legal review. It is not legal advice. Have counsel experienced in Ontario health privacy law review before use.

Last updated: 7 September 2026. A summary for clinic managers and privacy officers. For the full detail see the Privacy Policy.

At a glance

HostingAmazon Web Services, Canada (Central) region
Where patient data is storedCanada only
Encryption in transitTLS 1.2 or higher, every connection
Encryption at restAmazon-managed encryption for the database and stored files
Sign-inMicrosoft or Google only, via AWS Cognito — no Med Copilot passwords
Data isolationEvery account sees only its own data, enforced at the database-query level and covered by automated tests
AudioStreamed for transcription, then discarded — never stored
AI model training on your dataNever
Selling or advertising with your dataNever
Payment card dataNever touches Med Copilot — handled by Stripe's hosted checkout

Hosting and data residency

Med Copilot runs on Amazon Web Services in the Canada (Central) region. The application, database, website hosting, sign-in, speech-to-text and transactional email are all in Canada.

One cross-border step: the large-language model that drafts the clinical note and billing suggestions (Anthropic Claude on Amazon Bedrock) is currently routed to Amazon regions in the United States for the few seconds it takes to generate a response. Per Amazon, that content is stored only in Canada, is not retained by Bedrock, and is not used to train any model. A model that runs entirely within Canada is available and can be enabled for a clinic that requires it.

Encryption

  • In transit: TLS 1.2 or higher on every hop — browser to Med Copilot, browser to the transcription service, Med Copilot to the AI models, and Med Copilot to the database.
  • At rest: the database and stored files are encrypted using Amazon-managed keys.

Access control

  • Sign-in is federated through AWS Cognito to Microsoft or Google. Med Copilot does not store or manage passwords. Multi-factor authentication is governed by the physician's Microsoft or Google account, so a clinic can require it organisation-wide.
  • Every API request is authenticated with a signed token checked on the server.
  • Each database query is scoped to the signed-in account; a record with no valid owner is visible to no one. This is verified by an automated test suite.
  • Administrative access to production is limited to Med Copilot's operator. Production secrets are stored only as protected environment variables, never in code.
  • Because sign-in already federates to Microsoft Entra ID and Google Workspace, a clinic that uses either can have staff sign in with their existing organisational account.

What is and isn't stored

Stored, in Canada: the AI-drafted clinical note and its highlights; OHIP billing and diagnostic codes and claim data; referral letters; encounter metadata entered by the clinician; the physician's practice profile and referral address book; subscription status.

Not stored by Med Copilot: the encounter audio (discarded after transcription); the word-for-word transcript (kept only in the clinician's browser); payment card details.

Backups and availability

The database has automated backups managed by Amazon. The application runs as a managed, auto-scaling service behind Amazon's content delivery network.

No secondary use

Personal health information is used only to provide and support the service. It is never sold, never used for advertising, and never used to build, train or evaluate AI models. Only de-identified, aggregate operational metrics that identify no patient are used to run the service.

Breach response

If Med Copilot becomes aware of a security incident affecting a clinic's personal health information, it will notify that clinic at the first reasonable opportunity, provide the information the clinic needs for its own PHIPA obligations, and cooperate with containment and investigation.

Deletion on request

A physician can delete any individual encounter — along with its claim and referral letters — from within the application. On a documented request, or when an account is closed, Med Copilot returns or securely destroys all personal health information it holds for that clinic, including from backups on the backup cycle.

Subprocessors

SubprocessorRolePatient data?
Amazon Web ServicesHosting, database, storage, sign-in, speech-to-text, AI models, emailYes — stored in Canada; AI text generation processed transiently in the United States
AnthropicClaude AI model, running inside Amazon Bedrock (no access to customer content)No direct access
StripeSubscription billing (hosted)No — billing data only
Microsoft, GoogleSign-in identity providersNo — authentication only
Google AnalyticsVisit statistics for the public website onlyNo

Compliance programme

Med Copilot is an early-stage product completing its formal compliance programme, including independent legal review of this documentation, a documented retention schedule, and a written incident-response runbook. A clinic assessing Med Copilot should request the current status of these items.

Contact

Security and privacy questions: privacy@medcopilot.ca