Vero Scribe is used by clinicians who handle personal health information. For Ontario-based clinicians and organizations, that means workflows may need to align with the Personal Health Information Protection Act, 2004 (PHIPA).
This article summarizes Vero's privacy and security controls for Ontario healthcare settings. It is not legal advice, and organizations should confirm their own obligations with privacy or legal counsel.
How Vero Supports PHIPA-Aligned Workflows
Vero is designed to help healthcare providers protect personal health information throughout the documentation workflow.
Regional data localization: Canadian customer data is stored in Canada.
Access controls: Users authenticate before accessing clinical data, and row-level security helps ensure users can only access records associated with their account or organization.
Encryption: Data is encrypted in transit and at rest using industry-standard controls.
Data minimization: Vero processes the information needed to generate notes, answer clinical questions, and support the clinician's workflow.
No model training on patient data: Patient data and sensitive health information are not used to train, develop, or improve Vero's proprietary AI models.
Retention controls: Clinicians can delete encounters manually or configure automatic deletion from 1 to 365 days.
PHIPA Roles
In typical use, the healthcare provider or clinic remains responsible for how patient information is collected, used, disclosed, retained, and documented in their clinical setting. Vero acts as a technology service provider that processes information to support the clinician's use of the platform.
Clinicians should continue to follow their organization's privacy policies, consent workflows, documentation standards, and retention requirements.
Patient Data Controls
Manual deletion: Delete individual encounters, days of encounters, notes, patients, and associated uploaded files when they are no longer needed.
Automatic deletion: Open Account → Security → Data retention and configure automatic encounter deletion.
Account requests: Contact Vero for account deletion or privacy requests that require identity verification.
AI and Patient Data
Vero uses AI to help generate notes, answer clinical questions, and support documentation workflows. Patient data is handled under strict controls:
Patient data is not sold.
Patient data is not used to train Vero's proprietary AI models.
Third-party service providers are governed by contractual data protection obligations.
Clinicians remain responsible for reviewing and approving generated content before it is used in the medical record.
