ORRCA · LEGAL
Terms & Privacy
Version 2026-08-12-v2 · Governed by PIPEDA and BC PIPA · Privacy Officer: privacy@orrca.ca
Terms of Service
1. Acceptance of Terms
By accessing or using the ORRCA platform ("Service"), you agree to be bound by these Terms of Service. If you do not agree, you may not use the Service. ORRCA is a medical referral coordination platform designed for use by licensed healthcare professionals in British Columbia, Canada.
2. Eligibility & Registration
The Service is available only to licensed physicians, medical office assistants, and authorized healthcare professionals. By registering, you confirm that you are a licensed healthcare professional or authorized delegate, and that your registration information is accurate and complete.
3. Use of the Service
You agree to use ORRCA solely for the purpose of managing medical referrals and on-call coordination. You shall not: (a) share your login credentials; (b) access patient data you are not authorized to view; (c) use the platform for any unlawful purpose; (d) attempt to reverse-engineer or compromise the Service.
4. Patient Data & PHI
ORRCA processes Protected Health Information (PHI) as defined under the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (BC PIPA). The custodianship of patient records remains with the treating physician(s); ORRCA acts as a service provider handling PHI solely for the purpose of clinical referral coordination, inpatient handoff, and on-call communication.
4.1 PHI Security — In Transit
All PHI transmitted between your device and ORRCA servers is encrypted in transit using current industry-standard protocols. Outbound notification channels (SMS, voice, email, push) are content-minimized — notifications carry a reference code and an authenticated deep link, never the full clinical record.
4.2 PHI Security — At Rest (Primary Storage)
Primary PHI storage is located in Canada and is encrypted at rest. Access rules enforced at the database layer ensure that authenticated users can only read records their role and group membership permit. Audit logs capture every PHI access with immutable, timestamped, user-attributed entries.
4.3 Data Held on Your Device
ORRCA does not keep an offline copy of clinical records on your device. The authoritative record always remains in the primary database, and the applications read it over an encrypted connection. The following is what is held locally.
- Web browser: a short-lived working copy of your current workspace, which may include patient identifiers, is held in the browser's session storage so that screens paint without re-fetching. It is scoped to the signed-in user, is discarded when the browser tab closes, is not kept longer than 24 hours, and is erased on sign-out.
- Mobile applications: no clinical records are stored on the device. Only your display preferences and the list of rows you have pinned or hidden are kept locally.
- Sign-in credentials and session tokens are held in the device's protected credential store, encrypted by the operating system.
- Automatic session timeouts lock the application after inactivity, and re-authentication is required to resume.
- Biometric or PIN lock is supported on devices that provide it.
4.4 Access Controls
- Role-based access (physician, delegate/MOA, group lead, group admin, platform admin) enforced at both the application and database layers
- Multi-factor authentication (TOTP) available for all accounts
- Remote sign-out and multi-device session management
- Delegate (MOA) actions are logged under the physician's audit trail with explicit delegate attribution
4.5 Immutable Access Logs
Every access to PHI — every read, write, export, and delegate action — is recorded in an immutable audit log. Log entries capture the authenticated user identity, the action type, the affected record, and a server-side timestamp. Audit records cannot be edited or deleted by any user, including administrators, and are retained in accordance with CPSBC record-keeping guidelines (minimum 10 years). These logs support regulatory audits, patient access requests, and investigation of any unauthorized-access concern under BC PIPA section 34 and PIPEDA Principle 7.
4.6 Your Responsibilities
You are responsible for: (a) keeping your credentials confidential; (b) using a device that is itself reasonably secured (screen lock, up-to-date OS, no unauthorized third-party access); (c) ensuring appropriate consent or authority exists for any patient information you enter; (d) signing out on shared or public devices; (e) reporting any suspected compromise of your account to the ORRCA Privacy Officer at privacy@orrca.ca without delay.
5. Data Security
ORRCA implements a defence-in-depth security program aligned with recognized Canadian standards for the handling of sensitive personal and health information. Our program follows the principles of the Government of Canada's IT Security Risk Management Framework (CSE ITSG-33), targeting the Protected B sensitivity classification — the level used by the Government of Canada for personal and health information.
5.1 Encryption
- Encryption at rest for all stored data and backups
- Encryption in transit for all client-server communication
- Secrets managed via an encrypted vault — never stored in source code or configuration files
5.2 Data Residency
All primary data is stored in Canadian data centres, consistent with BC PIPA section 33.1 and federal data-sovereignty guidance. Database backups are encrypted and remain within Canada.
5.3 Access Controls
- Row-level security (RLS) enforced at the database layer — users can only access data they are authorized to view
- Role-based access controls (physician, delegate/MOA, group lead, group admin, platform admin)
- Multi-factor authentication (MFA/TOTP) available; biometric device lock supported on mobile
- Configurable automatic session timeouts (default 30 minutes of inactivity)
- Multi-device session management with remote sign-out
5.4 Audit Logging
Every access to Protected Health Information (PHI) is logged with timestamps, user identity, and action type. Audit entries are immutable and retained in accordance with CPSBC record-keeping guidelines and BC health authority requirements. These logs support investigation of any unauthorized access and enable compliance audits.
5.5 Operational Security
- Formal security incident response plan: identification, containment, eradication, recovery, post-incident review
- Breach notification procedures under BC PIPA section 29.1 and PIPEDA section 10.1
- Continuous dependency and vulnerability monitoring
- Third-party processors bound by contractual data-protection obligations comparable to BC PIPA
5.6 Data Minimization
Outbound notifications (SMS, voice, email, push) are content-minimized to reduce PHI exposure. Full clinical details are accessed only within the authenticated ORRCA application, never in external notification payloads.
These controls are designed to meet or exceed the requirements of BC PIPA, PIPEDA, and the College of Physicians and Surgeons of British Columbia. Despite these measures, no system is completely secure, and you acknowledge inherent risks in electronic data transmission.
6. Intellectual Property
The ORRCA platform, including its software, design, and content, is the intellectual property of ORRCA Healthcare Solutions Corp. You are granted a limited, non-exclusive, non-transferable licence to use the Service for its intended purpose.
7. Limitation of Liability
ORRCA is a coordination tool and does not provide medical advice. Clinical decisions remain the sole responsibility of the treating physician. ORRCA shall not be liable for any clinical outcomes resulting from the use or failure of the Service. The Service is provided "as is" without warranty of any kind.
8. Termination
We may suspend or terminate your access at any time for violation of these Terms, security concerns, or at our discretion. Upon termination, your access to patient data through the platform will cease. Audit logs are retained as required by law.
9. Governing Law
These Terms are governed by the laws of British Columbia, Canada. Any disputes shall be resolved in the courts of British Columbia.
10. Changes to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated via the platform. Continued use after changes constitutes acceptance.
Privacy Policy
1. Introduction
ORRCA Healthcare Solutions Corp. ("ORRCA", "we", "our", "us") is committed to protecting the privacy and security of personal information and protected health information ("PHI") entrusted to us through the ORRCA platform (the "Service"). ORRCA is a medical on-call referral management platform designed for licensed physicians and authorized healthcare professionals in British Columbia, Canada.
This Privacy Policy explains how we collect, use, disclose, store, and safeguard personal information and PHI in accordance with the British Columbia Personal Information Protection Act ("BC PIPA", SBC 2003, c. 63) and the Personal Information Protection and Electronic Documents Act ("PIPEDA", SC 2000, c. 5). Where BC PIPA and PIPEDA overlap, we apply the higher standard of protection.
Effective Date: April 12, 2026
Last Updated: August 12, 2026
2. Privacy Officer & Contact
ORRCA has designated a Privacy Officer who is accountable for our compliance with this Policy and applicable privacy legislation. For any privacy-related inquiries, access requests, complaints, or to exercise your rights under this Policy, contact:
Privacy Officer
ORRCA Healthcare Solutions Corp.
Vancouver, British Columbia, Canada
Email: privacy@orrca.ca
We will acknowledge receipt of your inquiry within five (5) business days and provide a substantive response within thirty (30) days, as required under BC PIPA section 28.
3. Applicable Legislation
ORRCA operates in compliance with the following privacy legislation and standards:
- British Columbia Personal Information Protection Act (BC PIPA, SBC 2003, c. 63) — governs private-sector collection, use, and disclosure of personal information in BC
- Personal Information Protection and Electronic Documents Act (PIPEDA, SC 2000, c. 5) — federal legislation governing commercial activities involving personal information
- British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA) — applicable where ORRCA processes data on behalf of a public body (e.g., a health authority)
- College of Physicians and Surgeons of British Columbia guidelines on electronic medical records and patient privacy
- British Columbia health authorities' information management policies
Under BC PIPA section 3, "personal information" means information about an identifiable individual, including health information. ORRCA treats all patient data as sensitive personal information warranting the highest level of protection.
4. Information We Collect
4.1 Physician & Healthcare Professional Personal Information
We collect the following information from registered healthcare professionals:
- Full name, professional credentials, and specialty
- Medical Services Plan (MSP) practitioner number
- Contact information: email address, telephone/cell phone number
- Group/practice affiliations and on-call schedules
- Shift preferences, availability windows, and scheduling constraints
- Medical school and graduation year
- Delegate designations (MOA/office staff authorized to act on the physician's behalf)
4.2 Patient Health Information (PHI)
When physicians use ORRCA to coordinate referrals, the following patient information may be processed:
- Patient full name
- Personal Health Number (PHN)
- Date of birth
- Clinical summaries and referral details
- Urgency classifications
- Attached medical images and documents (processed via OCR for data extraction)
- Inpatient tracking information (admission status, post-operative notes, discharge summaries)
ORRCA processes PHI as a service provider on behalf of the referring and receiving healthcare providers. The custodianship of patient records remains with the treating physician(s) as defined under BC PIPA.
4.3 Technical & Usage Information
We automatically collect the following for security, audit, and service improvement purposes:
- Device type, operating system, and browser information
- IP address and approximate geolocation (country/region level)
- Session timestamps, login/logout events, and access logs
- Push notification tokens (for delivery of clinical alerts)
- Feature usage analytics (aggregated, non-identifying)
5. Purpose of Collection & Legal Basis
Under BC PIPA section 11 and PIPEDA Principle 2, we collect personal information only for purposes that a reasonable person would consider appropriate in the circumstances. We use information for the following purposes:
5.1 Core Service Delivery
- Facilitating medical referrals between healthcare providers
- Managing on-call schedules, shift swaps, and physician coordination
- Tracking inpatient cases and enabling surgeon-to-surgeon handoff notifications
- Sending time-sensitive notifications about referral status changes, on-call assignments, and clinical alerts via push notification, SMS, voice call, and email
5.2 Compliance & Audit
- Maintaining comprehensive audit trails for regulatory compliance
- Logging all access to PHI in accordance with CPSO and health authority requirements
- Supporting MSP billing verification and call-volume reporting
5.3 Security & Platform Integrity
- Authenticating users and enforcing role-based access controls
- Detecting unauthorized access attempts and potential security incidents
- Enabling automatic session timeouts and device management
5.4 Service Improvement
- Analyzing aggregated, de-identified usage patterns to improve platform functionality
- We do NOT use personal information or PHI for marketing, advertising, or any purpose unrelated to healthcare delivery
6. Consent
Under BC PIPA sections 6-8 and PIPEDA Principle 3, we obtain meaningful consent before collecting, using, or disclosing personal information.
6.1 Physician Consent
By creating an account and accepting these terms, healthcare professionals consent to the collection and use of their professional information as described in this Policy. Continued use of the Service constitutes ongoing consent.
6.2 Patient Consent
Patient information is entered by authorized healthcare professionals in the course of providing medical care. The referring physician is responsible for ensuring appropriate consent or authority exists for sharing patient information through the referral process, consistent with their obligations under BC PIPA and the College of Physicians and Surgeons of British Columbia standards.
6.3 Withdrawal of Consent
You may withdraw consent for certain uses of your personal information by contacting privacy@orrca.ca. However, withdrawal of consent may limit your ability to use the Service. Certain information (such as audit logs) must be retained regardless of consent withdrawal, as required by law (BC PIPA section 35).
7. Data Storage & Security Measures
ORRCA implements administrative, technical, and physical safeguards commensurate with the sensitivity of the information, as required under BC PIPA section 34 and PIPEDA Principle 7.
7.1 Data Residency
All primary data is stored in Canadian data centres. Database backups are encrypted and stored within Canada.
7.2 Encryption
- Encryption at rest: all stored data is encrypted
- Encryption in transit: all data transmitted between client applications and servers is encrypted
- Database-level encryption for all backup copies
7.3 Access Controls
- Row-level security (RLS) policies ensuring users can only access data they are authorized to view
- Role-based access controls (physician, group lead, group admin, platform admin, delegate/MOA)
- Mandatory email-based authentication with optional biometric lock
- Configurable automatic session timeouts (default 30 minutes of inactivity)
- Multi-device session management with remote sign-out capability
7.4 Audit Logging
All access to PHI is logged with timestamps, user identity, and action type. Audit logs are immutable and retained for the full retention period. These logs enable investigation of any unauthorized access and support compliance audits.
7.5 Incident Response
ORRCA maintains a documented security incident response plan including identification, containment, eradication, recovery, and post-incident review procedures.
8. Service Providers
ORRCA engages service providers to operate the platform. Each is bound by contract to protect personal information and PHI, to use it only for the purposes ORRCA specifies, and to maintain safeguards comparable to ORRCA's own. Providers are engaged for the following purposes.
- Hosting and storage of the primary database, authentication, and uploaded files. All primary data is stored in Canada.
- Delivery of SMS and voice notifications for on-call alerts, referral updates, and emergency escalation. Recipient phone numbers and minimized notification content are processed. Delivery may occur outside Canada.
- Delivery of transactional email for referral notifications, account verification, and system alerts. Recipient email addresses and minimized notification content are processed. Delivery may occur outside Canada.
- Extraction of text from uploaded documents and images, which may contain PHI. Content is processed transiently and is not retained by the provider. Processing may occur outside Canada.
- Delivery of push notifications to mobile devices. Device tokens and minimized notification content are processed. Delivery may occur outside Canada.
Notification content is minimized in every channel: a notification carries a reference code and an authenticated link, never the full clinical record. Full clinical detail is available only inside the authenticated ORRCA application.
8.1 Data Held on Your Device
ORRCA does not keep an offline copy of clinical records on your device. When you use the web application, a short-lived working copy of your current workspace — which may include patient identifiers — is held in your browser's session storage so that screens paint without re-fetching. It is scoped to the signed-in user, is discarded when the browser tab closes, is not kept longer than 24 hours, and is erased on sign-out. The mobile applications store no clinical records on the device. Sign-in credentials are held in the device's protected credential store.
9. Cross-Border Data Transfers
ORRCA stores all primary data in Canada. Certain service providers may process data through infrastructure located in the United States or other jurisdictions in the course of delivering notifications and processing uploaded documents. While outside Canada, information is subject to the laws of that jurisdiction, which may permit access by its courts and government authorities.
In accordance with BC PIPA section 33.1, before personal information is disclosed or stored outside Canada, ORRCA ensures that:
- Contractual obligations require the foreign service provider to protect the information to a standard comparable to BC PIPA
- Data transmitted to foreign processors is minimized to the extent necessary for the specific service (e.g., notification delivery)
- Full PHI records (patient names, PHNs, clinical summaries) are NOT transmitted to third-party processors. Only minimal notification metadata is shared.
- Users are notified of cross-border data flows through this Policy
Under PIPEDA, personal information transferred to a third party for processing remains the responsibility of ORRCA (PIPEDA Principle 1, Accountability). We remain liable for the protection of personal information in the hands of our processors.
10. Data Sharing & Disclosure
ORRCA does not sell, rent, or trade personal information or PHI to any third party. Information may be disclosed in the following circumstances:
- Between healthcare providers involved in a patient's referral, as necessary for clinical coordination
- To authorized delegates (MOAs) acting on behalf of a physician, within the scope of their delegated authority
- To group leads and group administrators for scheduling and operational management within their group
- To platform administrators for system administration, support, and security purposes
- As required by law, court order, subpoena, or lawful authority (BC PIPA section 18)
- To law enforcement if there is a reasonable belief that disclosure is necessary to prevent a serious threat to health or safety (BC PIPA section 18(1)(j))
- To our third-party service providers as described in Section 8, solely for the purposes of operating the Service
11. Data Retention
ORRCA retains personal information and PHI in accordance with applicable legal requirements and the principle of limiting retention to the period necessary for the identified purposes (BC PIPA section 35, PIPEDA Principle 5).
11.1 Retention Periods
- Referral records and associated PHI: minimum 10 years from the date of the last entry, in accordance with BC health records retention requirements and CPSBC guidelines
- Audit logs (PHI access, authentication events): minimum 10 years, immutable
- On-call schedules and shift records: minimum 7 years for billing verification and operational records
- MSP billing data: minimum 7 years in accordance with CRA requirements
- User account profiles: retained for the duration of the account, plus 2 years after deactivation, unless longer retention is required by law
- Technical/security logs: 2 years
11.2 Account Deactivation
Upon request, user accounts may be deactivated, which removes access to the platform. However, associated audit records, referral data, and any information required to be retained by law will be preserved for the applicable retention period. De-identification of personal information may be applied where feasible after the retention period expires.
12. Your Rights Under BC PIPA & PIPEDA
Under BC PIPA (Part 5) and PIPEDA (Principle 9), you have the following rights with respect to your personal information:
12.1 Right of Access
You have the right to request access to your personal information held by ORRCA. Submit a written request to privacy@orrca.ca. We will respond within 30 business days (BC PIPA section 28). A reasonable fee may be charged for access requests that require significant effort to fulfill, and you will be notified in advance.
12.2 Right of Correction
You have the right to request correction of inaccurate or incomplete personal information. If we refuse to make a correction, we will annotate the record with your requested correction (BC PIPA section 29).
12.3 Right to Withdraw Consent
You may withdraw consent for the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions. Withdrawal may affect your ability to use the Service. Mandatory retention periods apply regardless of consent withdrawal.
12.4 Right to Complain
If you are not satisfied with our response to a privacy concern, you have the right to file a complaint with:
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC): www.oipc.bc.ca
- Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca
12.5 Patient Rights
Patients whose information is processed through ORRCA retain all rights under BC PIPA and PIPEDA. Patient access requests and complaints should be directed to the treating physician (as custodian of the health record) or to ORRCA's Privacy Officer. ORRCA will cooperate with treating physicians to respond to patient access requests in a timely manner.
13. Breach Notification
In the event of a security breach involving personal information or PHI, ORRCA will:
- 1. Contain the breach and assess the scope of affected data
- 2. Notify affected individuals as soon as practicable if the breach creates a real risk of significant harm (as required under BC PIPA section 29.1 and PIPEDA section 10.1)
- 3. Report the breach to the Office of the Information and Privacy Commissioner for British Columbia and/or the Privacy Commissioner of Canada, as applicable
- 4. Notify relevant health authorities and the College of Physicians and Surgeons of British Columbia if PHI is involved
- 5. Document the breach, remediation steps, and outcomes in our breach register
Breach notifications will include: a description of the incident, the types of information involved, the measures taken to mitigate harm, and recommended steps affected individuals can take to protect themselves.
"Significant harm" includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, and negative effects on credit rating, as defined under PIPEDA.
14. Cookies & Local Storage
ORRCA uses essential cookies and local storage strictly necessary for the operation of the Service. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
- Authentication tokens: stored securely in device storage to maintain your session
- User preferences: stored locally to remember your display and notification settings
- Session working copy (web only): a short-lived copy of your current workspace, which may include patient identifiers, held in the browser's session storage. It is scoped to you, discarded when the tab closes, not kept longer than 24 hours, and erased on sign-out. See Section 4.3 of the Terms of Service and Section 8.1 above.
15. Children's Information
ORRCA is designed for use by licensed healthcare professionals and is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. Patient information for minor patients is entered and managed by authorized healthcare professionals in accordance with their professional obligations.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated through the ORRCA platform and users will be required to review and re-accept the updated terms. The "Last Updated" date at the top of this Policy indicates the most recent revision.
Continued use of the Service after changes are communicated constitutes acceptance of the revised Policy, unless re-acceptance is explicitly required.
17. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of British Columbia, Canada, and the laws of Canada applicable therein. Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts of British Columbia.
18. Patient Self-Serve Intake
ORRCA offers patients a token-authenticated web portal (https://appts.orrca.ca) where, ahead of a clinical visit, patients may review their appointment details and complete a structured intake form covering demographics, medical history, medications, allergies, surgical history, implants, and contact consents.
18.1 Information Collected Through Intake
- Demographics: preferred name, Personal Health Number (PHN), mobile phone, email, home address, preferred contact method and language, interpreter requirement, emergency contact
- Presenting complaint and laterality (affected side, where applicable)
- Past medical history including chronic conditions, bleeding disorders, anaesthetic history, height/weight, smoking and alcohol use
- Current medications and supplements, including peri-operative safety flags (anticoagulants, GLP-1 agonists)
- Allergies with reaction and severity
- Past surgical history and implanted devices
- Lifestyle context relevant to post-op planning (occupation, household composition, mobility)
- Patient consent choices for contact channels, voicemail content, family physician communication, and clinical/teaching/marketing photography (each captured as a separate append-only consent record)
18.2 Where Intake Data Is Stored
All intake data is stored exclusively in ORRCA's Canadian database infrastructure. Intake content is NOT transmitted to any service provider. The only external involvement in the intake flow is delivery of the appointment link by SMS and by email; neither delivery provider receives the intake content itself.
18.3 Token-Based Access
Access to the intake portal is authenticated by a short alphanumeric token embedded in the appointment link delivered to the patient. The token is cryptographically random, single-appointment-scoped, and expires 72 hours after the scheduled visit time. Token-based access is rate-limited to prevent enumeration. Every read and write through the token is recorded in an immutable access log.
18.4 Consent Records
Consent responses are stored as append-only records. Withdrawing a consent results in a new record with the updated choice; the prior response is preserved for medico-legal audit. Consent records are retained for the appointment's full retention period (see Section 11).
18.5 Use of Intake Data
Intake data is made available only to the clinic staff responsible for the patient's visit (the physician, their authorized delegates or MOAs, and the clinic's group administrators), accessed through the authenticated ORRCA application with row-level security enforcement. Intake data is not used for marketing, not sold, not shared with third parties, and not used for any purpose unrelated to the direct clinical care of the patient.
19. Contact Information
For all privacy-related matters:
ORRCA Healthcare Solutions Corp.
Privacy Officer
Vancouver, British Columbia, Canada
Email: privacy@orrca.ca
This Privacy Policy was last reviewed and updated on August 12, 2026.
Revision History
12 August 2026 — authorized by the Privacy Officer
- Corrected the description of data held on your device. Earlier versions described an encrypted offline copy of clinical records kept on the device and erasable by an administrator. That capability was part of a mobile framework ORRCA no longer uses, and no such copy is kept. Sections 4.3 of the Terms and 8.1 of this Policy now state what is actually held: a short-lived working copy in the web browser's session storage, and no clinical records on mobile devices.
- Removed the names of individual service providers and the specific technologies used to run the platform, in favour of describing what each provider is engaged to do, what categories of information it handles, and whether that information may leave Canada. Naming a provider is not required disclosure and becomes inaccurate whenever a provider changes; the purposes, the categories, the cross-border position and the safeguards are unchanged.
- Added an explicit statement that information processed outside Canada is subject to the laws of that jurisdiction, which may permit access by its courts and government authorities.
- Made the Terms of Service and this Privacy Policy reachable from the Account page of every ORRCA application, in addition to the sign-in screen.
No change was made to what ORRCA collects, why it is collected, who it is shared with, how long it is kept, or your rights under it. This revision was made before the platform opened to its first users, so no earlier version of this document has been in force for anyone.