Privacy Policy | Caredove Legal Home Solutions Insights Contact Create an Account Sign in Home About Our Solutions CBO Essentials CBO Advanced Community eRequest Clinician eRefer Features Appointment Booking Public Sign-Up Caredove Forms WebBuilder Integrations Integrations Careers Blog Legal and Privacy Contact Sign in Create an Account Privacy Policy Date of Last Revision: Feb 27, 2026 - View History 1. Purpose Caredove respects the privacy concerns of all users of The Platform, and is committed to protecting the Protected Health Information (PHI) / Personal Information (PI) of all referral data and Professional Information of its users with accounts. The purpose of this policy is to establish all the mandatory requirements and responsibilities for the protection of such information. 2. Scope This policy applies to all Caredove personnel and third party service providers whom it has retained to support the delivery of our services. This privacy policy should be read in conjunction with the subordinate policies, standards and procedures that are part of our comprehensive Privacy & Security Program. The policy is relevant to all Caredove customers. 3. Terms “Protected Health Information (PHI)” means information such as: Physical or mental health of the individual The individual’s family health history Eligibility for health care The individual’s giving of a body part or bodily substance Reason for receiving health care Alternate decision maker Health Card Number (e.g., OHIP card) Any identifying information that is not protected health information but that is contained in a record of protected health information Clinical information about the individual being referred for service. In Caredove, “PHI” is any patient related information contained in a health referral. “Personal Information (PI)” means identifiable information about an individual such as: Personal address, telephone number or email address Any identifying number assigned to an individual (e.g. Social Insurance Number, Social Security Number) Payment history Information relating to age, sex, disability, race, citizenship status, marital status, religion, etc. Information relating to education, employment, etc. This information is PI only if it is not associated with any health information, in which case it is also considered to be PHI. Very simple referrals may contain only “PI”. “PI” may also be found in a limited manner related to user accounts or in business processes outside of the Caredove application. In the Caredove application, “PI” data in referrals is treated the same as “PHI”. “Professional information” refers to data related to an individual’s employment, business, or professional activities, used in a Caredove user account, including: Name Business contact information (email, phone) Job title, employer Profile photo Caredove user credentials User activity in Caredove Professional information is also associated with referrals to identify who is sending, receiving or otherwise managing and observing a referral. Clarification of Terms for Our Canadian Customers: Health Information Network Provider (HINP): An entity that provides services to two or more Health Information Custodians (HIC) where the services are provided primarily to enable the custodians to use electronic means to disclose Protected Health Information (PHI) to one another. Caredove is a HINP. As a HINP, Caredove may have PHI within its systems while providing service; however the HIC remains fully accountable to the patient for the privacy practices associated with the PHI. Health Information Custodian (HIC): A person or organization that delivers health or community care services. Physicians, hospitals, pharmacies, laboratories, community care access centres and community support agencies are examples of HICs. A HIC has custody or control of PHI as a result of the work it does. The HIC has the right to deal with the PHI and create records, as well as the responsibility to maintain the confidentiality and security of the PHI. Caredove is not a HIC, but rather helps HICs. For example, Caredove provides HICs a more secure means of sharing information than traditional faxing methods. Agent: Someone acting for or on behalf of the HIC in respect of collecting, using or disclosing PHI, for the purposes of the HIC, and not the agent’s own purposes. For example, a HIC may designate Caredove as its agent to correct a specific record in Caredove. Caredove does not make any independent decisions with respect to handling PHI when acting as an agent, but acts only in accordance with the terms of its agreement with a HIC and in compliance with Canadian laws and regulations in this regard. Clarification of Terms for our United States Customers: Caredove has adopted this Official Privacy Policy in order to declare its voluntary commitment to comply with the Health Insurance Portability and Accountability Act (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health (“HITECH”) Act of 2009 (Title XIII of division A and Title IV of division B of the American Recovery and Reinvestment Act “ARRA”) and the HIPAA Omnibus Final Rule. Although Caredove does not meet the definition of a HIPAA Business Associate or Covered Entity as these are defined in the HIPAA Regulations, Caredove hereby acknowledges its obligation to protect the privacy and security of Individually Identifiable Health Information (“IIHI”) generally, and Protected Health Information (“PHI”) as defined in the HIPAA Regulations, voluntarily under the regulations implementing HIPAA, lawfully under other federal and state laws protecting the confidentiality of PHI/PI, and under principles of general and professional ethics. Caredove & HIPAA 4. Privacy Policy This Privacy Policy has been organized around the 10 principles contained in the Model Code for Protection of Personal Information (“CAN/CSA – Q830-96, Model Code for the Protection of Personal Information,” March 1996.). Principle 1: Accountability The “principle of accountability” means that an organization is responsible for the Protected Health Information (PHI) and Personal Information (PI) and under its control and has designated an individual or individuals who are accountable for the organization’s compliance with privacy principles. When confidential PHI/PI information is not in our custody, Caredove Inc supports our customers and their privacy programs. The Privacy & Security Program is overseen by the designated Chief Privacy Officer (CPO) who reports directly to Caredove Chief Executive Officer (CEO), and is the person primarily responsible for Caredove’s administering the Privacy & Security Program. The CPO is responsible for compliance with privacy practices and consistent application of sanctions for failure to comply with privacy policies for all individuals in the organization’s workforce, extended workforce, and for all business associates, in cooperation with legal counsel as applicable. Additionally, other Caredove personnel may be responsible for the day-to-day oversight of the program, acting on behalf of the CPO from time to time. The CPO will: Work with technical personnel to protect PHI/PI information from unauthorized use Administer all complaints Cooperate with officials in governmental organizations (e.g., HHS or Office of the Privacy Commissioner. ) Develop specific policies as required by relevant jurisdictions (e.g., US, Canada) Review all contracts under which access to PHI/PI data is given to outside entities, bring those contracts into compliance with relevant laws, and ensure that PHI/PI data is adequately protected when such access is granted Disseminate any notices of privacy breaches as required by law Remain up to date with relevant laws, rules, regulation and new technologies to protect data privacy Determine the optimal method for consent when PHI/PI is being transmitted between parties on the Caredove platform Oversee employee training with regard to our privacy and security regime. Caredove Inc is committed to respecting personal privacy, safeguarding PHI/PI information, and ensuring the security of information when it is in our custody. Caredove meets this commitment through our comprehensive Privacy & Security Program. Key components of this Program include: A suite of privacy policies and procedures Information, retention and disposal protocols Employee training and privacy awareness Internal and third party privacy and threat risk assessments Agreements, both with individuals and entities that provide service to Caredove and entities to which Caredove provides service Privacy incident and breach management protocols PHI/PI lifecycle management describing procedures for retention and destruction of information An inventory of all individuals with access to PHI/PI information A role-based access controls within Caredove that limits access to PHI/PI Public accountability and transparency by making this policy freely available, and demonstrating compliance with relevant legislation, including Protected Health Information Protection Act, 2004 ("PHIPA"), and HIPAA. Principle 2: Identifying Purposes The “principle of identifying purposes” means that the purposes for which PHI/PI are collected shall be identified by the organization at or before the time the information is collected. All referral forms submitted through Caredove shall clearly state the purpose of the referral before it is submitted, through a consent statement. The purpose stated in the standard Caredove consent statement for sending information is to request access to an identified service. (See “Principle 3: Consent” for more details on the consent statement). Protected Health Information (PHI) and Personal Information (PI) is stored in Caredove while providing an electronic service that allows HICs to streamline patient referrals, which is entered into Caredove by a Health Information Custodian (HIC), a patient or their representative. Such information is stored for one or more of the following purposes: Sending and tracking patient referral information. Receiving and processing patient referral information. Presenting referral information to patients and their representatives Professional Information for Caredove users with Caredove accounts, with the intention of helping users find and connect with health care and community care services, or administering that process. This information about users may be used for one or more of the following purposes: Providing user information to other Caredove users about who is referring to services, and who is providing services. Providing referrers and providers information about who has acted on a referral Sharing available appointment times of users wishing to let others book such times. Contacting users regarding requests for access to, or correction of, PHI/PI. Contacting users to provide support. Issuing a password for the password protected sections of this site. Promoting the existence of new or revised services to users. Promoting the use of Caredove. Reporting statistics on aggregate numbers on usage to funders, sponsors, users, or others in order to further the intent of Caredove, and to help evaluate the effectiveness of Caredove. Contacting users for feedback and surveying needs regarding Caredove. Providing business consulting services such as process improvement & program evaluation Principle 3: Consent The “principle of consent” means that the knowledge and consent of the individual are required for the collection, use or disclosure of PHI/PI, except when inappropriate. Acquiring referral consent is the obligation of the person collecting the PHI and using Caredove to make the referr…