TELUS Health Care Centres Privacy Commitment
Effective October 13, 2023
TELUS Health Care Centres is a national provider of healthcare services to corporations, insurance companies, and individuals. Consistent with our obligations as healthcare professionals, we are dedicated to maintaining high standards of confidentiality with respect to all information that has been provided to us, with a particular focus on the privacy and security of health information.
We are passionate about the protection of your Personal Information and Personal Health Information and committed to respecting your privacy.
TELUS Health Care Centres policy to protect your privacy
Here’s the summary:
By using the Services provided by TELUS Health Care Centres, you understand that your information will be treated in accordance with this TELUS Health Care Centres Privacy Commitment (“Privacy Commitment”). Our Privacy Commitment and practices are consistent with the 10 Fair Information Principles and we strive to apply the principles of Privacy by Design in the development and review of our products and Services.
If you do not want us to collect, use or disclose your Personal Information or Personal Health Information in the ways identified in this Privacy Commitment, you may choose not to use Services from TELUS Health Care Centres.
Here’s the detail:
We have developed this TELUS Health Care Centres Privacy Commitment to provide you with specific details about how TELUS Health Care Centres collects, uses, and discloses your Personal Information, which includes your Personal Health Information, when you use our Services (“Services”), visit our website available at www.telus.com/health/care-centres, or otherwise interact with us.
- The Privacy Commitment reflects the requirements of applicable Canadian privacy legislation, including provincial and federal privacy laws, and our own continuing commitment to privacy.
- TELUS Health Care Centres, provides you with supporting applications, such as the patient portal, to facilitate and/or support the Services we provide to you. When you use applications and portals related to the services provided by TELUS Health Care Centres, your Personal Information will be used in accordance with this Privacy Commitment and the privacy policy presented to you at registration. In the event of inconsistencies between this Privacy Commitment and the privacy policy presented to you upon registration, the privacy policy will prevail.
Please read this Privacy Commitment carefully. By using Services provided by TELUS Health Care Centres, you consent to the collection, use, disclosure and storage of Personal Information in accordance with this Privacy Commitment.
Definitions
The following definitions apply to this Privacy Commitment. Where there are definitions of the same term in both the TELUS Health Care Centres Privacy Commitment and the TELUS Privacy Code, the terms in this Privacy Commitment will take precedence.
You - An individual whouses Services at TELUS Health Care Centres, visits our website or otherwise interacts with us.
Medical Record - a record of your Personal Health Information. This may include but is not limited to:
- the name(s) of your Healthcare Practitioner(s) at each visit;
- patient identification (i.e., name, address, phone number, personal health number, contact person in case of emergencies) and a medical history;
- records of exams carried out by Healthcare Practitioners and clinical notes for each patient encounter;
- requisitions for treatment or investigation;
- consents to treatment obtained in writing;
- records of treatment you receive from Healthcare Practitioners through TELUS Health Care Centres;
- reports of investigative procedures and reports of the results of laboratory, pathology, consultations, diagnostic imaging examinations or tests;
- diagnoses;
- health card number; and
- a record of missed and/or cancelled appointments.
Your Medical Record excludes your TELUS Health Care Centres profile.
Healthcare Practitioners – Practitioners that provide or assist in the provision of healthcare through TELUS Health Care Centres, which may include physicians, nurses, nurse practitioners, psychologists, dietitians, physiotherapists, and mental health therapists.
Non-healthcare Professional(s) - Personal trainers, wellness coaches, and other non-Healthcare Practitioners who provide non-healthcare Services at TELUS Health Care Centres.
Personal Health Information - Any Personal Information regulated under applicable health privacy legislation in the provinces in which we operate, including information that relates to an individual’s physical or mental health and healthcare including health history, the provision of healthcare to the individual, payments or eligibility for healthcare, healthcare provider, substitute decision-maker, health card number or other healthcare-related personal identification numbers, or any other information that is collected in the course of providing health services to the individual, including information contained in your Medical Record.
Personal Information - Any information about an identifiable individual, other than business contact information (including business email address) used to contact the individual in their business or professional capacity. For the purposes of this policy, references to Personal Information also includes Personal Health Information.This may include but is not limited to:
- Name
- Gender
- Mailing Address
- Email Address
- Telephone Number
- Fax Number
- Health Insurance Number
- Date of Birth
- Place of Employment
- Payment information
- Benefits and claims information
Your TELUS Health Care Centres profile includes identifiers described above as well as the service(s) you receive. Personal Information does not include de-identified or aggregated information that cannot reasonably be associated with a specific individual.
Services: Services offered by TELUS Health Care Centres include personal care services, corporate care services, occupational health services, virtual care services, wellness services and mental health services. Some of these services are considered healthcare services and some are non-healthcare services. Healthcare Services include preventative health assessments, medical imaging such as MRI, CT, x-ray, ultrasound, travel health such as vaccinations and medical consultations, digital health, and mental health such as neuropsychology, psychopharmacology, individual and group mental health programs. Non-healthcare Services are those services that don’t involve the provision of healthcare and include pre-placement examinations, periodic medical examinations (under occupational health services) and independent medical evaluations (IME), disability management services, personalized fitness testing, fitness training, health monitoring, and medical aesthetics services.
TELUS Health Care Centres - In this TELUS Health Care Centres Privacy Commitment, the words "we", "us", "our" or "TELUS" refer to TELUS Health Care Centres Inc.
TELUS Family – In this TELUS Health Care Centres Privacy Commitment, “TELUS Family” means TELUS Communications Inc., and its subsidiary companies and corporate affiliates, as they may exist from time to time.
Accountability
Here’s the summary:
In most provinces, TELUS Health Care Centres has overall responsibility for protecting the privacy of your Medical Records and other Personal Information and we are directly accountable to you.
Here’s the detail:
Healthcare Services: Wherever we provide Healthcare Services to you, with the exception of Alberta, TELUS Health Care Centres has overall responsibility for protecting your Personal Health Information, including your Medical Record, and we are directly accountable to you.
In Alberta, your Healthcare Practitioners, who are designated as ‘custodians’ under applicable legislation (Alberta’s Health Information Act), have overall responsibility for the privacy of your Medical Records and TELUS Health Care Centres collects, uses, and discloses Personal Health Information on their behalf and otherwise assists them with their responsibilities under the applicable legislation.
Non-healthcare Services: For all other Personal Information collected by TELUS Health Care Centres, where applicable provincial health privacy legislation does not apply, TELUS Health Care Centres will handle information in compliance with applicable federal and provincial private sector privacy laws including the Personal Information Protection and Electronic Documents Act (“PIPEDA”).
Consent
Here’s the summary:
When you use Services provided by TELUS Health Care Centres, you consent to our collection, use, disclosure, and storage of your Personal Information as described in this Privacy Commitment.
You can withdraw your consent at any time, subject to limited restrictions.
Here’s the detail:
When you use Services at TELUS Health Care Centres, you consent to our collection, use, disclosure, and storage of your Personal Information in accordance with this Privacy Commitment.
You can withdraw your consent to the collection, use and disclosure of your Personal Information, subject to our legal or contractual restrictions. However, if you refuse to provide certain information or withdraw your consent, this may limit our ability to provide you with certain Services, and products and functionalities.
If you request deletion of your Personal Information, we may retain certain information to meet our legal or regulatory obligations; for example, Personal Information that forms part of your Medical Record must be retained for a period of time to meet legal and regulatory obligations. Please review the ‘Retention’ section below for more information on our retention practices.
To collect, use or disclose Personal Information outside of the purposes contemplated in this Privacy Commitment, we will seek additional consent from you.
Individuals under the age of majority in their jurisdiction of residence may use Services from TELUS Health Care Centres with the consent of parent or legal guardian.
Collection and Use of Personal Information
Here’s the summary:
We collect only the Personal Information required for us to establish and maintain a responsible healthcare and service relationship with you, to provide Services and products of TELUS Health Care Centres, to develop, enhance or market our products and Services (including to send you relevant information about products and Services that may be of interest to you).
We may use Personal Information to send you newsletters. You can opt out of receiving them at any time.
Here’s the detail:
We only collect and use Personal Information for the following purposes:
To establish our relationship with you
Eligibility for Corporate Services: We may provide Services to you through your employer under their corporate account. Where this is the case your employer will provide us with your name, business phone number, business email address, job title, and in some cases certain additional information, such as employee identification number or date of birth, so that we may contact and authenticate you to schedule an appointment to receive Services.
Registration for Services: Individuals may also contract with us directly to receive Services such as mental health services, preventative health assessments, and certain of our wellness services. When you register for such Services, we will create a profile for you in our records by collecting your first and last name, email address and mailing address. For Healthcare Services we also collect your date of birth (for identification purposes) and provincial health card number if the Service is to be covered under your provincial health care insurance plan. Your health card number will be maintained on file for future visits (unless you choose to remove it from your profile). We do not use this information for any other purposes. At some clinics, you may be asked to take a photograph so that Healthcare Practitioners can easily recognize you; this is voluntary and not required to provide you with services.
Identity and Verification: When you visit a clinic in person, you will be required to verify your identity by presenting your government-issued identification (either provincial health card, driver’s license, passport, or government-issued photo identification card). We verify your identity in order to prevent someone from receiving Services in your name and to help prevent fraud, including public healthcare fraud. We do not use this information for any other purposes. In addition, on each audio or video visit with a Healthcare Practitioner, you will be asked questions to verify your identity using information from your profile (for example, date of birth) or your Healthcare Practitioner may ask you to show your government-issued ID so that we can compare the photo on your ID to you.
Payments: If you choose to purchase any Services from us that are not covered under a provincial or private health plan, we and/or our third party payment processor will collect your payment information such as your name, address, phone number, email address, billing address, payment method, payment card number and CVV. This information is used to process your payments. We use a third-party service provider who is Payment Card Industry Data Security Standard (PCI DSS) compliant to facilitate secure payment processing.
Contacting Us: If you speak to a TELUS Health Care Centre call centre agent, all audio conversations are recorded to ensure quality of service to you and for training purposes. If you complete an online form to contact us for a consultation or further information, we collect your name, contact information, area(s) of interest, preferred contact method and any other information you provide in order to respond to your inquiry or request.
To provide health-related and well-being services to you
Healthcare Service: You will need to provide information about your current health condition and health history to Healthcare Practitioners in order to enable them to provide you with healthcare, to assist in providing you healthcare, and to complete and update your Medical Record.
Non-Healthcare Services: If you wish to book an occupational health service, wellness service or other non-healthcare service, you will be asked for information necessary to schedule your appointment where applicable and to provide the Service. The type of information we collect will vary depending on the Service and you may be asked to complete intake forms to collect information about your areas of interest or concern (which may become part of your Medical Record). We will not request information beyond what is necessary to provide you with the Service you have requested.
Real-Time Video and Audio Conversations: Where you wish to consult with a Healthcare Practitioner virtually, we connect you through a real-time video or audio call. We may sometimes use this feature to verify your identity; for example, your Healthcare Practitioner may ask you to show your government-issued ID so that we can compare the photo on your ID to you. All video and audio calls conducted through TELUS Health Care Centres are confidential. Video recordings of a virtual visit are never made.
Audio Recordings at the time of Care: Audio recordings of your consultations may be recorded for the purposes of dictation and form part of your Medical Record; if they are to be used for any other purpose we will obtain your express consent.
Service Messages: Where you receive Services through your employer, we use your email address and phone number to provide you with service messages related to the Services such as how to prepare for your appointment, reminders, and other important updates.You may opt out of receiving these by contacting the
Call Centre.
Where you contract with us directly for Services, we will request your express consent to contact you by email or other electronic means, including to send you service messages. You may revoke your consent at any time by
contacting the clinic
or site where you receive Services.In the event the message is sensitive or related to an emergency, we will call you and may leave a voicemail if we are unable to get in touch with you. You can indicate your preference to leave a voicemail at any time by
contacting the clinic
or site where you receive Services.Quality of Care: The Medical Directors of our TELUS Health Care Centre clinics may review Healthcare Practitioners’ work to ensure they are meeting the high standard and quality of care expected of them.
To develop, enhance or market our products and services
Developing and enhancing our Services: We analyze Personal Information in our systems to better understand use of our Services and what care programs or Services to provide. Where practicable, we use de-identified or aggregated information for these purposes. For example, we may use your postal code and aggregate it with all other TELUS Health Care Centre patient postal codes to determine the best location to open a new physical clinic.
Sending newsletters and marketing communications: Your name and email address, province, clinic location may be used so that we can provide you with newsletters by SMS, email or mail about TELUS Health Care Centres, the TELUS Family, and our third-party partners.
Your contact details, including your name and email address, may be used so that TELUS Health Care Centres can provide you with health-related news and offers. These communications may be tailored based on data in your profile (such as your location and Services used and last appointment date), but not information contained in your Medical Record.
You can opt out of receiving newsletter and marketing messages from us at any time by following the unsubscribe instructions included in each of our newsletter and marketing messages. If you request to opt out, we will share your contact information with the TELUS Family to opt you out of all TELUS Health newsletter and marketing communications. You may continue to receive transactional and servicing emails.
Satisfaction and experience surveys and questionnaires: Your contact details, including your name and email address, phone number, clinic location and time and date of appointment may be used by us to contact you regarding your experience when using our Services. TELUS Health Care Centre staff may further contact you to address an issue or concern and to improve our service offerings.
To maintain the security and/or functionality of the TELUS Health Website
Visiting the TELUS Health Care Centres Website: In general, you can visit our website without telling us who you are or submitting any Personal Information. However, we collect the IP (Internet protocol) addresses of all visitors to our website and other related information such as device type, page requests, browser type, operating system and average time spent on our website. We use this information to help us understand our website activity and to monitor and improve our website. We also use your Internet protocol address (IP address) and device type to help ensure a secure experience and detect anomalous behaviour.
Cookies: Please see our
Cookies Notice
for information on our use of Cookies.De-Identification and Aggregation
De-Identifying and Aggregating Information: We may de-identify or aggregate your Personal Information including information in your Medical Record, such that it cannot reasonably be associated with you, for the following purposes:
(i) To protect your privacy and the security of your Personal Information;
(ii) To conduct analytics and/or research in a privacy protective manner to:
a) better understand and improve our Services;
b) To operate and expand our business opportunities.
c) To improve health outcomes.
We may share such aggregated de-identified information or insights with the TELUS Family to assist in research, planning, or product and service development.
Our electronic medical record provider may de-identify and use data to assist in health care research, planning, or product and service development. For example, our electronic medical record provider may de-identify Personal Information so that it may be used to support clinic data quality, improve the platform or to analyze and recommend clinical outcomes for treatment.
Sharing and Disclosure of Personal Information
Here’s the summary:
For continuity of care purposes, we may share Personal Information among your Healthcare Practitioners and others who assist in the provision of healthcare to you.
We will not disclose your Personal Information for any purpose other than what has been outlined in this Privacy Commitment or as permitted under applicable law, unless we obtain your express consent. We disclose only the limited amount of Personal Information necessary to meet these purposes.
We do not sell your Personal Information to any third parties.
We may share your Personal Information with our service providers who are contracted to perform services or functions on our behalf where they require the information to assist us in serving you. We use contractual controls to protect this information and limit its use to what is necessary for the service provider to perform the Service.
Here’s the detail:
We may share or disclose Personal Information for the following purposes:
Provision of Healthcare: If you receive healthcare through TELUS Health Care Centres, we may disclose your Personal Information to and among your TELUS Health Care Centres Healthcare Practitioners for the purpose of providing or assisting in the provision of healthcare to you. We may also disclose your Personal Information to third parties such as other health professionals, specialists, pharmacists, pharmacies and laboratories for the purpose of providing or assisting in the provision of healthcare to you – this includes, but is not limited to, providing medically appropriate referrals, prescriptions, or lab and imaging requisitions to you. Information will be shared with your family doctor, hospital or specialist with your consent (unless we are required to do so under applicable laws).
Your Medical Record will be stored in our electronic medical record systems and will be accessible to Healthcare practitioners who provide or assist in the provision of healthcare Services to you from our clinics.
Employers/Benefits Providers: If Services provided by TELUS Health Care Centres are facilitated through your employer or benefits provider, we may provide general information about the non-medical status of your account to them. We will not disclose any Personal Health Information to your employer or benefits provider without your express consent, with the exception of services you received for tax and billing purposes. De-identified information may be shared with your employer at an aggregated level. For example, we may provide your employer with aggregated information about reason for consultation, trending diagnoses such as an increase in mental health consultations overall, or the overall number of referrals to specialists made over a particular reporting period by gender or job category or the results of a satisfaction survey. We will use best efforts to ensure this information is not individually identifiable. There is a possibility your employer may link this information to you.
Service Providers: We may share Personal Information with the TELUS Family, our suppliers, agents or other organizations or individuals who are contracted to perform services or functions on our behalf where they require the information to assist us in serving you. For example, we may use service providers to verify identification, process payments, host our website,and store and dispose of information on our behalf. We strive to minimize the amount of Personal Information that we share with our service providers and partners and require that it not be used for any other purpose.
Provincial Billing: If a Service is to be covered under your provincial health care insurance plan, we share Personal Information with the jurisdictional organization or agency for billing purposes for provincially-covered services (to OHIP, RAMQ, etc).
Participating in Provincial Health Initiatives: We may participate in provincial health initiatives that require the disclosure of deidentified information to inform government health strategy, policy and initiatives.
Disclosures required or permitted by law or regulation: We may disclose Personal Information to the extent necessary where we are required or permitted under applicable law, such as in the event of an emergency that threatens the life, health or security of an individual. We or our service providers will also share Personal Information with law enforcement, courts, other government agencies or other parties if we are required to do so to meet our legal and regulatory requirements in the jurisdictions in which we or our service providers operate; for example, we are required to provide records to law enforcement in response to a valid court order.
Access, Corrections, and Accuracy of your Personal Information
Here’s the summary:
You can request access to or correction of your Personal Information by contacting us at the
clinic
in which you receive care.We rely on you to keep your Personal Information up to date and accurate so that we can serve you.
Here’s the detail:
You may request access and corrections to the Personal Information we hold about you at any time, subject to limited exceptions.
For a copy of your Personal Information, please contact the
clinic
in which you receive care. We will take reasonable steps to verify your identity before granting access or making corrections. You may also authorize another person to receive a copy of your Personal Information. In addition, your right to access or correct your Personal Information is subject to certain legal restrictions. Depending on the volume of records requested, we may provide you with informal access to your Personal Information, such as turning the screen at the time of receiving care, otherwise the request for access to information should be formally made in writing.Upon written request, we will also provide you with a list of individuals or entities (e.g. third party service providers) with whom we have shared or disclosed your Personal Information, if applicable. Please contact the
clinic
in which you receive care for additional information.We rely on you to ensure that the Personal Information we have about you is accurate, complete and up-to-date. You are welcome to make changes or request deletions or corrections to Personal Information in writing at any time by the
clinic
in which you receive care.Storage and Location of your Personal Information
Here’s the summary:
Your Personal Information, including your Medical Record, is stored in Canada and may be accessed from outside Canada in limited circumstances.
Here’s the detail:
Your Medical Record is securely stored in data centers physically located in Canada. Your profile and other Personal Information is also securely stored in data centres physically located in Canada. Any profile information stored at these data centers is encrypted in transit and at rest.
Any physical copies of Personal Information are stored at TELUS Health Care Centre Clinics or at secured off-site storage within Canada.
Certain Services may be provided on-site at your employer location, in which case TELUS Health Care Centre Clinics may store physical copies of records at that on-site location to which only TELUS Health Care Centre authorized personnel have access.
We also use service providers who may access or store Personal Information, including Personal Health Information, however, excluding your Medical Record, in the United States or other jurisdictions. For example, application providers, such as our marketing/communications platform provider and analytics platform provider, are responsible for safeguarding your Personal Information and may store information in their own systems. We do not have control over what systems they use and where this data may be stored but we have contractual controls in place to protect this information and limit its use to what is necessary for them to perform the service.
For billing and collections purposes, our service provider may operate outside of Canada and may have access to limited Personal Health Information, such as the type of Service received and your healthcare provider. Our call centre agents may also be located outside of Canada.
Retention
Here’s the summary:
We retain Personal Information only for as long as necessary to fulfill the purposes described in this Privacy Commitment or as required to meet legal or regulatory requirements.
Personal information that forms part of your Medical Record must be retained for a period of time mandated by law.
Here’s the detail:
We retain Personal Information only for as long as necessary to fulfill the purposes described in this Privacy Commitment or as required to meet legal or regulatory requirements. We may also create and retain de-identified information and continue to use this information in accordance with this Privacy Commitment.
At your request, we will delete your Personal Information unless we are required to retain it to meet our legal or regulatory obligations.
Medical Records must be retained in accordance with provincial retention guidelines. In general, for Medical Records, we will follow a retention of 16 years from either the date of last entry or from the age of 19 (nineteen) of the individual to whom the information relates, whichever is later. Audio recordings of healthcare consultations and/or transcriptions of the recordings are retained as part of your Medical Record.
Safeguards
Here’s the summary:
We have implemented a comprehensive information security program.
Here’s the detail:
We understand that data security is a critical issue and we are committed to safeguarding the Personal Information in our custody and control. We have implemented a comprehensive information security program that includes written policies and procedures, and security controls, as well as reasonable administrative, technical and physical safeguards in an effort to protect against unauthorized access, use, loss, modification, and disclosure of Personal Information in our custody or control.
Our team members must complete privacy and security training before they have access to any Personal Information, and must complete annual privacy and security training for ongoing access to Personal Information.
TELUS Health Care Centres ensures that the security policies, procedures, and controls meet industry and TELUS best practices and are regularly tested.
Electronic client files are kept in a secured environment with restricted access. Paper-based files are stored in locked fire-resistant filing cabinets or filing rooms equipped with sprinkler systems. Access to these areas is also highly restricted.
We may communicate with you through electronic means. Please keep in mind that no internet or email transmission is ever fully secure or error free and no security system is impenetrable. We cannot fully guarantee the confidentiality of any information that you provide to us but we can assure you that we will use reasonable and appropriate security controls, reflective of the sensitive nature of Personal Health Information.
It is important for you to play an active role in the protection and safeguarding of your Personal Information. It’s important to guard your privacy when you are online. If TELUS Health Care Centres provides you with links to other websites, this Privacy Commitment does not govern those websites. You should read their privacy policies and make an informed decision about whether you want to use those websites or their services.
Changes to this Privacy Commitment
Here’s the summary:
We may make changes to this notice and we will notify you of the changes to our information practices.
Here’s the detail:
This Privacy Commitment may be updated from time to time to reflect changes to our practices. Any notices regarding modifications to this Privacy Commitment will be in written form on our website and/or in the clinic, as applicable.
If any changes to this Privacy Commitment are significant, we will provide a more prominent notice (including email notification, if appropriate).
We encourage you to periodically review our Privacy Commitment for the latest information on our privacy practices and to contact us if you have any questions or concerns.
Questions, Complaints, and Contact
Here’s the summary:
You can always reach us at [email protected] if you have privacy questions, concerns or complaints.
Here’s the detail:
Please contact us at [email protected] or the address below if:
- you have any questions related to the collection, use and disclosure of your Personal Information;
- you need to report any privacy or security violations, including any suspected or actual unauthorized access, use, disclosure or loss of Personal Information; or
- you have any questions or comments about this Privacy Commitment or the manner in which we or our service providers treat your Personal Information, including our policies and practices with respect to the use of service providers outside Canada.
Contact Address:
TELUS Health Care Centres
c/o Privacy Officer
25 York Street; Floor 22
Toronto, ON
M5J 2V5
If you wish to withdraw your consent to the collection, use or disclosure of Personal Information or access, update, and/or correct inaccuracies in your Personal Information, please contact the clinic in which you receive care.
If you have concerns with our Privacy Commitment or privacy practices, we encourage you to first bring your concerns to us at [email protected]. You may also seek advice from the Office of the Privacy Commissioner of Canada or the provincial Privacy Commissioner having jurisdiction, and, if appropriate, file a written complaint with the Commissioner's office.
To contact the applicable privacy commissioner, please visit the following websites:
Alberta:
www.oipc.ab.ca
British Columbia:
www.oipc.bc.ca
Manitoba:
www.ombudsman.mb.ca
New Brunswick:
https://oic-bci.ca/
Newfoundland and Labrador:
www.oipc.nl.ca
Northwest Territories:
https://atipp-nt.ca/
Nova Scotia:
https://oipc.novascotia.ca/
Nunavut:
https://atipp-nu.ca/
Ontario:
www.ipc.on.ca
Prince Edward Island:
https://www.assembly.pe.ca/
Québec:
www.cai.gouv.qc.ca
Saskatchewan:
https://oipc.sk.ca/
Yukon:
https://www.ombudsman.yk.ca/
Federal:
https://www.priv.gc.ca/