Privacy Policy
How Medibrio collects, protects and uses information, including personal health information held on behalf of clinics.
Version 2026.1
Our role
The clinic is the custodian of the health record. Medibrio acts on the clinic's written instructions: as an information manager / health information network provider in Canada, and as a business associate under HIPAA in the United States. We do not use health information for our own purposes.
What we collect
Account information (name, work email, role, clinic), clinical content entered or imported by the clinic, communications sent through the platform (texts, fax, video, phone calls), billing records, and technical logs needed for security and auditing.
Artificial intelligence and your clinical data
Medibrio's AI features (transcription, note drafting, summaries, chart questions, phone reception) process clinical content only to produce the result you requested, in memory, for the duration of the request.
Patient information is never used to train public or foundation AI models, is never sold, and is never shared for advertising. Model providers operate under zero-retention terms.
AI output is a draft and clinical decision support only. A licensed clinician must review, correct and sign every note, letter, order or report before it becomes part of the legal record.
Security
Encryption in transit and at rest, per-clinic data isolation enforced at the database level, role-based access, mandatory two-step verification options, automatic sign-out after inactivity, immutable audit logs of every access to a chart, and break-glass emergency access that is always recorded.
Canada — Law 25, PHIPA, PIPEDA
For Canadian clinics, consent must be free, informed and given for specific purposes; checkboxes are never pre-ticked. Patients may ask their clinic for access to, or correction of, their record. Any transfer of information outside the province or country is disclosed to the clinic before it happens. Privacy incidents are reported to the clinic without delay so it can notify the Commission d'accès à l'information, the Information and Privacy Commissioner or the affected individuals as required.
United States — HIPAA and HITECH
Protected health information is used and disclosed only as permitted by the Business Associate Agreement and required by law. We maintain administrative, physical and technical safeguards under the HIPAA Security Rule, and report any breach of unsecured PHI to the clinic without unreasonable delay so notification deadlines can be met.
Retention and deletion
Records are kept according to the retention period configured by the clinic and the minimum required by its jurisdiction (typically 10 years in Canada, 7 years in the United States, longer for minors). A clinic may export its complete data at any time and request deletion when the legal retention period ends and no legal hold applies.
Contact
Privacy questions and access requests: info@medibrio.com. Patients should contact their clinic first, since the clinic holds the record.
