
Privacy & Consent Statement
Last updated: July 10, 2026
At NPSCSPN, we are committed to protecting your Personal Health Information (PHI) in accordance with Ontario's Personal Health Information Protection Act (PHIPA) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
PHI includes any identifying information about your health care, such as your name, date of birth, contact details, completed forms, reports, therapy notes, billing details, and referrals.
Use of Personal Health Information & Consent
We collect only the information necessary to provide you with safe, effective psychological care. Your PHI is used solely for:
-
Providing psychological services;
-
Coordinating care with other health professionals, with your consent;
-
Administrative and billing purposes;
-
Meeting legal and regulatory obligations.
By receiving services at our clinic, you will sign a Consent Form that outlines how your PHI will be collected, used, and disclosed as described above. This form will also be reviewed in person with your practitioner to ensure you understand your rights and how your information is handled.
You may withdraw your consent at any time, subject to legal or professional limitations, by contacting us directly.
Your Privacy Rights
Under PHIPA, you may have the right to:
-
Request access to your clinical records;
-
Ask for corrections to inaccurate or incomplete information;
-
Inquire how your information has been used or disclosed;
-
Withdraw or modify consent where permitted by law;
-
Ask questions about the handling of your information;
-
File a complaint with the Information and Privacy Commissioner of Ontario.
To make a request, please contact our Privacy Officer:
-
Dr. Nicolás F. Narvaez Linares
-
613-212-7659
We will respond within 30 days, as required by law.
If you are not satisfied with our response to a privacy concern, you may contact the Information and Privacy Commissioner of Ontario.
Security Safeguards
We take your privacy seriously. Your information is stored securely and accessed only by authorized personnel involved in your care or clinic operations. We do not disclose your PHI without your consent unless permitted or required by law, or where disclosure is otherwise authorized under applicable professional and legal obligations.
We use administrative, physical, and technological safeguards designed to protect PHI against loss, theft, unauthorized access, disclosure, copying, modification, or destruction. These safeguards include:
-
Restricted access to records on a need-to-know basis;
-
Password-protected and secured electronic systems;
-
Multi-Factor authentication, when available;
-
Encrypted communications where appropriate;
-
Secure cloud-based practice management systems;
-
Confidentiality agreements and privacy/security training for staff, contractors, and students with access to PHI;
-
Secure physical office environments and controlled access to clinic spaces;
-
Secure destruction of records when no longer required.
Electronic Communications & Telehealth Services
While we take reasonable precautions to protect electronic communications, email is not a fully secure method of communication. For this reason, we recommend that clients avoid sending PHI, clinical details, or other sensitive information by email whenever possible.
When confidential information must be exchanged electronically, clients may be directed to use the secure messaging feature available through their JaneApp account.
When services are provided virtually, reasonable efforts are made to use secure platforms intended for professional healthcare use. Clients are encouraged to participate from a private location and to use secure devices and internet connections whenever possible.
Recording, photographing, or sharing virtual sessions is prohibited unless all participants have provided consent.
Retention of Records
Clinical records are retained in accordance with applicable legal, regulatory, and professional requirements. When records are no longer required to be maintained, they are securely destroyed or permanently anonymized in a manner that protects confidentiality.
Breach Notification
We maintain internal procedures for identifying, investigating, documenting, and responding to privacy incidents. In the event of a privacy breach involving your PHI, we will:
-
Contain and assess the breach immediately
-
Notify you and the Information and Privacy Commissioner of Ontario (IPC), if required
-
Document the incident and take steps to prevent recurrence
-
We also report annual breach statistics to the IPC, as mandated by PHIPA.
If you have any questions about how we protect your privacy, please do not hesitate to contact us.
Your confidence and trust are vital to everything we do.