Built to the strictest Canadian bar
Medical records deserve a straight answer
Here is where your case data lives, which laws apply, which models may read it, and what we log. No badges we have not earned.
The regime
Three laws, and we build to the strictest
Which law applies depends on who the client is. Rather than switch behaviour per client, IMECore meets the FOIPPA residency requirement for everyone.
PIPEDA
Federal
The baseline for private-sector personal data in Canada. It always applies to us.
BC PIPA
Provincial, private sector
Governs how we handle claimant and examiner data for private clients: insurers, law firms, and employers.
FOIPPA (BC)
Provincial, public sector
Applies when the client is a public body. WorkSafeBC is one. ICBC is a Crown corporation and we treat its work the same way. FOIPPA requires personal information to be stored and accessed in Canada.
Controls
What that means in practice
Case data is handled to keep it in Canada
The database and file storage are created with a Western North America location hint. There is no Canada-only choice for this storage today, so the hint is best-effort. No personal health information goes to a United States model, replica, log sink, or analytics tool. Inference that carries health information runs only in Canada and is verified on every request.
The code refuses the wrong model
Personal health information may only reach a model that runs in Canada. That rule is built into the system, not just written in a policy. A request carrying health information is refused unless the model runs in Canada, and no setting can override it.
Every access is logged
Who, what, when, and why. The audit log records the user or agent, the case, the record or field, and the time. You can export it and put it in a claim file or a grievance response.
A person approves what leaves
Human review is a named control, not a courtesy. A coordinator accepts the intake. A coordinator approves the booking. A named reviewer signs off the report. AI never releases anything on its own.
Access follows the role
Workspace tenancy plus role-based permissions. The examiner portal cannot see the instructing letter. The employer view shows capability and restriction, not diagnosis. The examinee sees the record sources, not their contents.
Retention has an end date
Each data class carries a retention period and a deletion trigger. Deletion is real deletion, not a hidden flag.
AI
Which model may read a case
If a payload carries a claimant name, a claim number, or record content, it goes only to a provider that runs in Canada.
| Provider | Runs in Canada | Health information | What it is used for |
|---|---|---|---|
| Cloudflare Workers AI | No Canada-only guarantee | Refused in code | In use today for referral extraction and attachment text recognition, on non-identifying data only. |
| Azure OpenAI, Canada Central | Yes | Approved | Approved for case content and enabled per deployment. Not on by default. |
| Cohere | Yes | Approved | Approved for embeddings and classification, enabled per deployment. Removed from the default pipeline in August 2026. |
| OpenAI or Anthropic, direct | No | Never | De-identified text and development prompts only. |
| OpenRouter | No | Never | Development use only. |
See the subprocessor list for every third party that can touch customer data.
FAQ
Questions security teams ask
Where is our case data stored?
Case data lives on Cloudflare with a Western North America location hint. There is no Canada-only choice for this storage today, so the hint is best-effort. Model inference that carries health information runs only in Canada and is verified on every request. We apply the residency intent to every client, not only to public bodies.
What security documentation do you share?
We provide our security and privacy documentation on request: the Privacy Impact Assessment, records of processing, data processing agreement, subprocessor list, and breach-response runbook.
Does our data train your models?
No. Customer case data is never sold and is never used to train a general model.
Which third parties can see our data?
The list is on the subprocessors page and we keep it current. Every subprocessor that can touch case data has a data processing agreement with the Canada commitments written in.
What happens in a breach?
BC PIPA has mandatory breach notification. We detect through the audit and access logs, contain by revoking access and rotating keys, assess the risk of significant harm, and notify you and the regulator as the law requires.
Can examiners use their personal email for records?
No. Examiner agreements bind them to work inside the system. That is the point of the examiner portal: one link, no attachments, no second copy of the file.
How do we report a security problem?
Email security@imecore.com. We will acknowledge within one business day. Please give us a reasonable window to fix an issue before you publish it.
Send us your security questionnaire
We answer them properly, and we tell you which rows we cannot tick yet.