PHIPA Compliance
Last updated: July 2026
This page is a drafted template pending review by qualified legal and compliance counsel. It should not be treated as a final compliance attestation until reviewed and approved.
Luna Health AI is built to handle calls for Ontario healthcare clinics, which means the platform is designed and operated with Ontario's Personal Health Information Protection Act, 2004 ("PHIPA") in mind for any personal health information ("PHI") it processes on a clinic's behalf.
Our Commitment to PHIPA Compliance
Every plan includes a written agreement that establishes Luna's obligations as an agent of the clinic under PHIPA when we handle patient calls and related scheduling information for that clinic.
Role Under PHIPA
The clinic remains the health information custodian responsible for PHI. Luna acts as an agent of the custodian, collecting, using, and disclosing PHI only as authorized by the clinic and as permitted or required by PHIPA.
Written Agreements with Clinics
Before any call data is processed, we enter into a written agreement with the clinic that defines how PHI may be collected, used, disclosed, retained, and safeguarded, consistent with PHIPA and the clinic's instructions.
Safeguards for Personal Health Information
Call data and appointment details are encrypted in transit and at rest, access is restricted to personnel who need it to operate the Service, and infrastructure is hosted with providers that support healthcare-appropriate security controls.
Limiting Collection, Use, and Disclosure
Luna is configured to collect, use, and disclose only the information reasonably necessary to answer a call, verify an appointment, and complete scheduling actions on the clinic's behalf.
Breach Notification
If a privacy breach involving PHI occurs, we will notify the affected clinic without unreasonable delay so the clinic can meet its obligations under PHIPA, including any required notices to individuals and the Information and Privacy Commissioner of Ontario.
Individual Rights
Requests from patients to access or correct their own health information are directed to the clinic, which remains the health information custodian responsible for responding under PHIPA.
Service Providers and Subcontractors
Where subcontractors process PHI on our behalf (for example, cloud hosting), we require contractual commitments that they protect PHI consistently with our obligations to the clinic under PHIPA.
Training and Accountability
Personnel with access to systems that may contain PHI receive privacy and security training, and access is reviewed on an ongoing basis.
Contact Our Compliance Team
For PHIPA-related agreements or compliance questions, contact us at contact@lunahealthai.ca.