Skip to content
IMECore

Built to the strictest Canadian bar

Medical records deserve a straight answer

Here is where your case data lives, which laws apply, which models may read it, and what we log. No badges we have not earned.

The regime

Three laws, and we build to the strictest

Which law applies depends on who the client is. Rather than switch behaviour per client, IMECore meets the FOIPPA residency requirement for everyone.

  • PIPEDA

    Federal

    The baseline for private-sector personal data in Canada. It always applies to us.

  • BC PIPA

    Provincial, private sector

    Governs how we handle claimant and examiner data for private clients: insurers, law firms, and employers.

  • FOIPPA (BC)

    Provincial, public sector

    Applies when the client is a public body. WorkSafeBC is one. ICBC is a Crown corporation and we treat its work the same way. FOIPPA requires personal information to be stored and accessed in Canada.

Controls

What that means in practice

  • Case data is handled to keep it in Canada

    The database and file storage are created with a Western North America location hint. There is no Canada-only choice for this storage today, so the hint is best-effort. No personal health information goes to a United States model, replica, log sink, or analytics tool. Inference that carries health information runs only in Canada and is verified on every request.

  • The code refuses the wrong model

    Personal health information may only reach a model that runs in Canada. That rule is built into the system, not just written in a policy. A request carrying health information is refused unless the model runs in Canada, and no setting can override it.

  • Every access is logged

    Who, what, when, and why. The audit log records the user or agent, the case, the record or field, and the time. You can export it and put it in a claim file or a grievance response.

  • A person approves what leaves

    Human review is a named control, not a courtesy. A coordinator accepts the intake. A coordinator approves the booking. A named reviewer signs off the report. AI never releases anything on its own.

  • Access follows the role

    Workspace tenancy plus role-based permissions. The examiner portal cannot see the instructing letter. The employer view shows capability and restriction, not diagnosis. The examinee sees the record sources, not their contents.

  • Retention has an end date

    Each data class carries a retention period and a deletion trigger. Deletion is real deletion, not a hidden flag.

AI

Which model may read a case

If a payload carries a claimant name, a claim number, or record content, it goes only to a provider that runs in Canada.

Model providers, whether they run in Canada, and whether personal health information may reach them
ProviderRuns in CanadaHealth informationWhat it is used for
Cloudflare Workers AINo Canada-only guaranteeRefused in codeIn use today for referral extraction and attachment text recognition, on non-identifying data only.
Azure OpenAI, Canada CentralYesApprovedApproved for case content and enabled per deployment. Not on by default.
CohereYesApprovedApproved for embeddings and classification, enabled per deployment. Removed from the default pipeline in August 2026.
OpenAI or Anthropic, directNoNeverDe-identified text and development prompts only.
OpenRouterNoNeverDevelopment use only.

See the subprocessor list for every third party that can touch customer data.

FAQ

Questions security teams ask

Where is our case data stored?

Case data lives on Cloudflare with a Western North America location hint. There is no Canada-only choice for this storage today, so the hint is best-effort. Model inference that carries health information runs only in Canada and is verified on every request. We apply the residency intent to every client, not only to public bodies.

What security documentation do you share?

We provide our security and privacy documentation on request: the Privacy Impact Assessment, records of processing, data processing agreement, subprocessor list, and breach-response runbook.

Does our data train your models?

No. Customer case data is never sold and is never used to train a general model.

Which third parties can see our data?

The list is on the subprocessors page and we keep it current. Every subprocessor that can touch case data has a data processing agreement with the Canada commitments written in.

What happens in a breach?

BC PIPA has mandatory breach notification. We detect through the audit and access logs, contain by revoking access and rotating keys, assess the risk of significant harm, and notify you and the regulator as the law requires.

Can examiners use their personal email for records?

No. Examiner agreements bind them to work inside the system. That is the point of the examiner portal: one link, no attachments, no second copy of the file.

How do we report a security problem?

Email security@imecore.com. We will acknowledge within one business day. Please give us a reasonable window to fix an issue before you publish it.

Send us your security questionnaire

We answer them properly, and we tell you which rows we cannot tick yet.