Skip to main content

Security, Privacy & Compliance

HIPAA, Canadian privacy legislation, SOC 2, data residency and network requirements.

Yes. SeamlessMD complies with HIPAA and executes Business Associate Agreements with U.S. covered entities. SeamlessMD also maintains SOC 2 Type II compliance, audited annually by an independent CPA firm, with no exceptions across three consecutive audits.

Yes. SeamlessMD complies with PHIPA, PIPEDA, FIPPA, PHIA, the Connecting Care Act and Ontario Health interoperability specifications. It has completed Privacy Impact Assessments with numerous Canadian health organizations including Ontario Health/OTN, conducted by qualified third-party assessors holding CIPP/C credentials following guidance from Ontario’s Information and Privacy Commissioner.

Yes. SeamlessMD maintains SOC 2 Type II compliance, audited annually by an independent CPA firm, with no exceptions across three consecutive audits. A copy of the current SOC 2 Type II report is available to prospective and existing customers on request under NDA.

Patient data is stored in the country of the health system it belongs to: Canadian customer data is hosted and backed up in Microsoft Azure Canada and never leaves the country; U.S. customer data is hosted and backed up in the United States. SeamlessMD holds a signed BAA with Microsoft Azure, whose data centres are ISO 27001 compliant and HITRUST certified. Customer data is logically segregated so no customer can access another’s data.

No. SeamlessMD is 100% cloud-hosted SaaS on Microsoft Azure with no on-premise servers, virtual machines or local software required. SeamlessMD does not require remote connectivity into the health system’s network for support, administration or deployment. The only network requirement is standard outbound HTTPS/TLS access, plus a site-to-site VPN or interface engine if HL7v2 integration is in scope.

Still have questions?

Our team is happy to answer questions, walk you through the platform, or set up a demo.