Security Center

Patient information, protected by design

MDPay handles sensitive health information. These are the safeguards, standards and commitments that protect it.

Last updated September 30, 2026 · Privacy statement

Canadian hosted

Patient data is stored in Canada.

Encrypted

Protected when stored and when sent.

Access recorded

Views in the app and every change are logged.

Ministry validated

Passed Ontario Ministry of Health conformance.

Layers of protection

Independent safeguards. No single failure exposes patient information.

Canadian hosted

Patient data is stored in Canada.

  • The database and file storage are in Canada
  • Encryption keys are held in Canada
  • Database backups are configured to stay in Montréal
  • Service providers and where they operate are listed on the Service providers tab

Encrypted everywhere

Data is unreadable without the correct encryption keys.

  • TLS encryption between the browser and MDPay
  • AES-256 encryption for all stored data
  • Encryption keys rotate automatically every 90 days
  • The database rejects any unencrypted connection

Strict access control

Access requires strong identity checks. Each practice's data is isolated.

  • Sign-in by one-time code, not a reusable password
  • Authenticator app required on every account
  • Automatic sign-out after one hour of inactivity
  • Practice data is separated inside the database, not only the app
  • MDPay staff use a separate console, limited to an approved list of staff, and their sign-in requires a second factor

Access and changes recorded

Activity involving patient data leaves a record of who and when.

  • Patient information viewed in the MDPay app is logged with the person and the time
  • Changes are logged with the person and the time
  • Downloads and exports of patient data are logged before the file is released
  • The audit trail is encrypted and stored in Canada
  • System logs are filtered to remove known patient fields before they are written

Backed up and recoverable

Data can be restored after an incident.

  • Encrypted database backups every day
  • Restore to a specific point in time, not only the last backup
  • Safeguards against accidental database deletion
  • Replaced files can be recovered for a period after they change

Isolated network

Core systems are closed to the public internet.

  • The database has no public internet address
  • The website accepts secure HTTPS connections only
  • Uploaded claim files, onboarding sample files and documents sent to the Ministry are virus-scanned inside MDPay's own environment, and a file that fails the scan is never imported or sent

Secure engineering

Changes go through a controlled release process.

  • Changes reach production only through a pull request
  • Automated tests, including tests that one practice cannot see another's data, are part of the release process
  • Passwords and keys are kept in Google Secret Manager in Canada, not in the code
  • Each service runs under its own service identity

Commitments

Standing commitments to every physician and group.

  • Patient information is handled only as the physician's or group's agent under PHIPA, under a written agreement
  • Patient information is never sold, and identifiable patient information is never used to train AI models
  • Service providers that process patient information are listed on this page and bound by written terms
  • A privacy breach is reported to the physician or group at the first reasonable opportunity
  • When an agreement ends, patient information is deleted on the timeline it sets, with written confirmation on request
  • Priority support from the MDPay team

Standards and laws

The frameworks that govern how MDPay handles health information.

PHIPA

Ontario's Personal Health Information Protection Act. MDPay acts as the custodian's agent. Patient information is handled only on the custodian's behalf.

Ontario Ministry of Health conformance

The claims (MC EDT) and health card validation connections passed Ministry conformance testing. Production access was granted on that result.

ISO/IEC 27001, 27017, 27018 and SOC 2

MDPay runs on Google Cloud, which is independently audited against these standards. The certifications belong to Google Cloud.

AES-256 and TLS encryption

Industry-standard encryption. AES-256 protects stored data. TLS protects data sent across the internet.

Information and Privacy Commissioner of Ontario

The Commissioner oversees PHIPA. Patients with an unresolved privacy concern can contact the Commissioner directly.

Shared responsibility

  • Keep sign-in codes and authenticator apps private
  • Remove access for staff as soon as they leave
  • Never share a GO Secure password, including with MDPay
  • Report anything unusual to MDPay right away

Questions or concerns?

Report a concern, or request more detail on any safeguard listed here.

hello@mdpay.ca

Privacy Officer

Privacy questions, requests and complaints go to MDPay's Privacy Officer.

privacy@mdpay.ca