Compliance & Security

Enterprise Security. Canadian Compliance.

Your patients' data is protected by the same security standards used by banks and government agencies. PIPEDA, PHIPA, and HIPAA compliant from day one.

PIPEDA
Personal Information Protection and Electronic Documents Act
PHIPA
Personal Health Information Protection Act (Ontario)
HIPAA
Health Insurance Portability and Accountability Act
SOC 2 Type II
Service Organization Control 2 Type II Certified

Compliance Built Into Every Feature

Security and compliance aren't afterthoughts—they're foundational to SPRx

PIPEDA Compliance

Full compliance with Canada's Personal Information Protection and Electronic Documents Act. We handle patient data according to the highest Canadian privacy standards.

Privacy policies
Consent management
Data handling

PHIPA Compliance

For Ontario pharmacies, we ensure compliance with the Personal Health Information Protection Act. Health custodian responsibilities are built into our platform.

Health custodian support
Access controls
Breach protocols

Canadian Data Residency

All patient data is stored exclusively in Canadian data centers (AWS ca-central-1). Your patients' information never leaves Canada.

AWS ca-central-1
Data sovereignty
Canadian SLA

AES-256 Encryption

Bank-level AES-256-GCM encryption for all data at rest and in transit. Your patients' health information is protected with the strongest available encryption.

Encryption at rest
TLS 1.3 in transit
Key rotation

Complete Audit Trail

Every action in SPRx is logged with timestamp, user, and details. Meet regulatory requirements with comprehensive, searchable audit logs.

Full action logging
Searchable history
Export capability

Compliance Reports

Generate ready-to-submit compliance reports for regulators, insurers, and auditors. Automated report scheduling keeps you always prepared.

Auto-generated
Scheduled delivery
Custom formats

Security Measures

We implement comprehensive security controls that exceed industry standards. Our security posture is independently verified through annual SOC 2 Type II audits and regular penetration testing.

AES-256-GCM encryption for all stored data
TLS 1.3 encryption for all data in transit
Multi-factor authentication (MFA) for all users
Role-based access control (RBAC)
Regular penetration testing by third parties
Annual SOC 2 Type II audits
Automatic security patches and updates
DDoS protection and WAF
Encrypted database backups with point-in-time recovery
All Systems Operational
Data EncryptionAES-256-GCM
Data CenterAWS ca-central-1
Uptime SLA99.9%
Last Security AuditOct 2024
Backup FrequencyEvery 6 hours

Canadian Data Residency

All patient data is stored exclusively in AWS's Canadian data center (ca-central-1) in Montreal. Your patients' protected health information never leaves Canada, ensuring full compliance with Canadian data sovereignty requirements.

All data stored in Montreal, Canada
No data transfer outside Canadian borders
Compliant with provincial health data laws
Canadian support team handles all data requests
Data backup and disaster recovery in Canada
Canadian Servers
Encrypted Storage
99.9% Uptime
SOC 2 Certified

Incident Response & Support

We're prepared for anything—and we keep you informed every step of the way

Incident Detection

Automated monitoring detects anomalies in real-time. Our security team is alerted immediately.

Rapid Response

Documented incident response procedures ensure fast containment and resolution.

Full Transparency

Affected parties are notified promptly with clear communication about impact and remediation.

Ready for Enterprise-Grade Security?

Learn how SPRx protects your patients' data while simplifying compliance