MedMonitor: Data Security by Design
Data security protocols

From consent to insight, every step is secure. Employees provide explicit consent, and employers share de‑identified data. As a dedicated data processor, we operate on a strict least‑privilege, right‑access, right‑time model, so only the right people see the right data for the right purpose. Every touchpoint, collection, transmission, storage, and analysis is protected by industry‑standard encryption, role‑based access controls, audit trails, and privacy‑by‑design. Our environment is supported by continuous monitoring and logging, vulnerability management, penetration testing, secure backup and recovery processes, and business continuity and disaster recovery planning.
Privacy and Regulatory Alignment
- Our privacy and security program is designed to support compliance with PIPEDA and applicable provincial health privacy requirements in Canada.
- As a best practice, we have also adopted elements of GDPR and emerging AI governance requirements (EU AI Act) to help prepare for evolving privacy expectations.
Data Governance and Frameworks
- Our security and privacy practices are aligned with recognized frameworks such as ISO/IEC 27001/27002 and the NIST Risk Management Framework (RMF).
- All client data is hosted and stored exclusively on Canadian servers. We do not permit PI/PHI data to be transferred or stored outside of Canada.
- We continuously review and improve our privacy, security, and governance practices to support secure operations across our services.
Assurance and Testing
We conduct ongoing risk and compliance activities, including:
- business continuity and disaster recovery exercises
- maintaining secure, regularly tested backup and recovery processes to support business continuity and operational resilience, including immutable backups where appropriate.
- privacy impact assessments
- security threat and risk assessments
- vulnerability assessments
- penetration testing
- third-party validation activities to support our compliance program
Data handling practices

Data Ownership and Retention
The employee is the owner of their data. They provide consent for us to process their data as a first step to using our services, either through their employer or insurer. If they withdraw their consent, the data is removed from the MedMonitor platform. HumanisRx retains the data only in accordance with regulatory retention requirements. At the end of the retention period, any data that is no longer required for the purposes for which it was collected will be destroyed, or rendered anonymous.
Data Minimization and De-identification
- Our automated data integration processes are designed to accept de-identified data at the point of intake/collection.
- Access to sensitive data is limited to authorized personnel only, and identifiable information is only accessed where clinically required and permitted (for example, by licensed pharmacists providing medication consultation services).
Encryption and Secure Transmission
- Data is protected in transit and at rest.
- Encryption in transit is provided via TLS 1.2 using strong cryptographic controls.
- Data at rest is encrypted using AES-256.
Access Controls and Network Monitoring
- We use role-based access controls to restrict data access based on job function.
- Access is governed through monitoring, logging, and auditing.
- Our environment is supported by layered security controls, including endpoint protection and managed detection and response capabilities.