This is a working draft prepared to support legal review. It is not legal advice. Have counsel experienced in Ontario health privacy law review before use.
Last updated: 7 September 2026. A summary for clinic managers and privacy officers. For the full detail see the Privacy Policy.
| Hosting | Amazon Web Services, Canada (Central) region |
| Where patient data is stored | Canada only |
| Encryption in transit | TLS 1.2 or higher, every connection |
| Encryption at rest | Amazon-managed encryption for the database and stored files |
| Sign-in | Microsoft or Google only, via AWS Cognito — no Med Copilot passwords |
| Data isolation | Every account sees only its own data, enforced at the database-query level and covered by automated tests |
| Audio | Streamed for transcription, then discarded — never stored |
| AI model training on your data | Never |
| Selling or advertising with your data | Never |
| Payment card data | Never touches Med Copilot — handled by Stripe's hosted checkout |
Med Copilot runs on Amazon Web Services in the Canada (Central) region. The application, database, website hosting, sign-in, speech-to-text and transactional email are all in Canada.
One cross-border step: the large-language model that drafts the clinical note and billing suggestions (Anthropic Claude on Amazon Bedrock) is currently routed to Amazon regions in the United States for the few seconds it takes to generate a response. Per Amazon, that content is stored only in Canada, is not retained by Bedrock, and is not used to train any model. A model that runs entirely within Canada is available and can be enabled for a clinic that requires it.
Stored, in Canada: the AI-drafted clinical note and its highlights; OHIP billing and diagnostic codes and claim data; referral letters; encounter metadata entered by the clinician; the physician's practice profile and referral address book; subscription status.
Not stored by Med Copilot: the encounter audio (discarded after transcription); the word-for-word transcript (kept only in the clinician's browser); payment card details.
The database has automated backups managed by Amazon. The application runs as a managed, auto-scaling service behind Amazon's content delivery network.
Personal health information is used only to provide and support the service. It is never sold, never used for advertising, and never used to build, train or evaluate AI models. Only de-identified, aggregate operational metrics that identify no patient are used to run the service.
If Med Copilot becomes aware of a security incident affecting a clinic's personal health information, it will notify that clinic at the first reasonable opportunity, provide the information the clinic needs for its own PHIPA obligations, and cooperate with containment and investigation.
A physician can delete any individual encounter — along with its claim and referral letters — from within the application. On a documented request, or when an account is closed, Med Copilot returns or securely destroys all personal health information it holds for that clinic, including from backups on the backup cycle.
| Subprocessor | Role | Patient data? |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, sign-in, speech-to-text, AI models, email | Yes — stored in Canada; AI text generation processed transiently in the United States |
| Anthropic | Claude AI model, running inside Amazon Bedrock (no access to customer content) | No direct access |
| Stripe | Subscription billing (hosted) | No — billing data only |
| Microsoft, Google | Sign-in identity providers | No — authentication only |
| Google Analytics | Visit statistics for the public website only | No |
Med Copilot is an early-stage product completing its formal compliance programme, including independent legal review of this documentation, a documented retention schedule, and a written incident-response runbook. A clinic assessing Med Copilot should request the current status of these items.
Security and privacy questions: privacy@medcopilot.ca