Frequently Asked Questions

Is MAPflow PHIPA and PIPEDA compliant?

Yes. MAPflow is fully compliant with Ontario's Personal Health Information Protection Act (PHIPA) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). We also comply with additional provincial health privacy legislation, including Alberta's Health Information Act (HIA) and BC's Personal Information Protection Act (PIPA). Our security practices align with ISO 27001 standards, and we are in the process of achieving SOC 2 Type II certification. You can read our full security commitment on our blog.

Privacy and Security

How does MAPflow manage privacy compliance?

MAPflow is fully compliant with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) requirements. We are fully compliant with Ontario's Personal Health Information Protection Act (PHIPA), ensuring the highest standards for personal health information protection. We comply with additional provincial health information protection legislation (such as Alberta's HIA and BC's PIPA). Our security requirements are powered by DuploCloud, a leading privacy compliance platform built specifically for the needs of the digital health industry. Our application environment has been wrapped with all of the technical controls and safeguards required by today’s healthcare enterprise systems. Each element of our security architecture ties back to a specific policy of ISO 27001. These policies are then mapped to the corresponding privacy frameworks and industry standards where we operate. We maintain compliance with evolving regulations through continuous monitoring and adaptation. All compliance procedures and controls are thoroughly documented.

Privacy and Security

I’m the MAPflow administrator for my pharmacy, can I control who has access to my pharmacy-level data?

The MAPflow Administrator is responsible for adding and removing pharmacists. As soon as you remove a pharmacist, that pharmacist will no longer have access to the pharmacy in MAPflow. However, all assessments performed by that pharmacist are still available in the pharmacy.

Privacy and Security

I am automatically logged out of MAPflow after a certain amount of time?

If you are inactive for 30 minutes on MAPflow, you will automatically be logged off. Further, if you have been active for 3 hours on MAPflow, you will be asked to log back in; you will return to where you were after logging back in.

Privacy and Security

How is patient informed consent documented?

It is a legal requirement for each patient to provide informed consent to the in-person or virtual minor ailment service. Patient consent to minor ailment assessment is documented at the beginning of each assessment algorithm through a check box.Patients must also give verbal consent to MAPflow’s privacy policy. Each pharmacist should print out a paper copy of the Privacy Policy as well as the patient-facing one page information sheet of the privacy policy, found at https://mapflow.ca/privacy. Display the information sheet where the patients can see it. If the patient would like to read the full privacy policy, they can use the QR code on the information sheet or the pharmacist can provide a paper copy for them to read. For a virtual visit, the pharmacist can provide the url to the privacy policy (https://mapflow.ca/privacy). Patient consent to MAPflow’s Privacy Policy is documented at the beginning of each assessment algorithm through a check box.

Privacy and Security

Will my data or patient data be reported to the College?

The privacy and security of all identifiable data about you and your patients is our top priority. No third party will receive any identifiable information about you or your patients. This includes the College.

Privacy and Security