Security & Trust

How we protect patient health information

PharmaGuide handles personal health information on behalf of pharmacies across Canada. This page is the short version; the live trust centre carries the current control status and the documentation your security review will ask for.

Visit the trust centre
A pharmacist reviewing patient records on a tablet behind the dispensary counter
  • SOC 2 Type IISecurity criterion, independently examined
  • Data resident in CanadaToronto region, never replicated abroad
  • PIPEDA & PHIPA alignedFederal and provincial health privacy
  • Penetration testedIndependent, with remediation retests

Attestations

SOC 2 Type II

PharmaGuide maintains a SOC 2 Type II report covering the Security trust services criterion, issued following an independent examination by a licensed CPA firm. The current report is available under NDA on request.

Request it through thetrust centre, which handles the NDA before release.

Independent penetration testing

PharmaGuide commissions independent penetration testing, with retest reports covering remediation. Available under NDA alongside the SOC 2 report.

Data residency

All personal health information is stored and processed in Canada.

Production data is hosted on Google Cloud Platform in thenorthamerica-northeast2 region, in Toronto. Patient data does not leave the country in the course of normal operation — it is not replicated to US regions, and it is not processed outside Canada.

This matters in a privacy review. Wherever personal health information crosses the border, the review has to reason about cross-border disclosure and, depending on the province, justify it. Data that never leaves Canada removes that question instead of answering it.

A pharmacist consulting with a patient at the prescription counter

Privacy

PharmaGuide's privacy programme is aligned to PIPEDA, Canada's federal private-sector privacy legislation, and to provincial health privacy legislation includingPHIPA in Ontario.

Pharmacies are regulated provincially, so the operative legislation depends on where you practise. If your review needs the specifics for a particular province, ask and we will answer against that province's legislation rather than a general statement.

See also our privacy policy andterms of service.

Controls

Monitored continuously and published live, not asserted once a year.

Infrastructure security

Unique production database authentication, restricted encryption-key access, enforced account authentication.

Organizational security

Anti-malware coverage, employee background checks, an acknowledged and enforced code of conduct.

Product security

Data encryption, vulnerability and system monitoring, recurring control self-assessments.

Internal security procedures

Continuity and disaster-recovery plans, established and tested, with configuration management.

Data and privacy

Data retention and classification procedures, and customer data deleted on departure.

Current status for every control is on thetrust centre — including the ones not summarised here.

Report a vulnerability

If you believe you have found a security vulnerability in a PharmaGuide product, emailsupport@pharmaguide.ca. Please include enough detail to reproduce it. We will acknowledge your report and keep you informed while we investigate, and we will not pursue action against good-faith research.

Loading available times…