Skip to content

Security White Paper

Version 1.0 · September 1, 2026

1. Introduction

EMERGE Healthcare Co. provides cloud-based clinical infrastructure for healthcare organizations and patients.

Our Platform supports workflows that may include scheduling, patient intake, clinical documentation, patient communication, virtual care, billing, electronic faxing, referrals, prescriptions, forms and artificial-intelligence-assisted functionality.

Because the Platform processes sensitive health information, security and privacy are core design requirements.

This document provides a high-level description of EMERGE’s security program.

It is not intended to disclose information that could compromise the security of EMERGE or its customers.

2. Security governance

EMERGE maintains an information-security program designed to protect the confidentiality, integrity and availability of information processed through the Platform.

The program includes:

  • information-security policies;
  • privacy and security training;
  • access-management processes;
  • incident response;
  • vulnerability management;
  • vendor risk management;
  • business continuity;
  • backup and recovery procedures; and
  • independent assurance activities.

EMERGE has completed a SOC 2 Type II examination.

Current assurance documentation may be made available to qualified customers subject to appropriate confidentiality requirements.

3. Privacy and healthcare compliance

EMERGE is designed to support healthcare organizations in meeting applicable Canadian privacy requirements, including PHIPA in Ontario.

Where EMERGE processes personal health information for a healthcare provider or clinic, EMERGE generally acts as a service provider to that organization.

Privacy responsibilities are described in the EMERGE Privacy Policy and PHIPA Service Provider & Data Processing Addendum.

4. Hosting and data residency

Production healthcare information for Canadian customers is hosted in Canadian cloud regions where required by the applicable customer configuration.

EMERGE evaluates cloud and infrastructure providers against security, reliability and privacy requirements.

Physical security of production infrastructure is managed by approved cloud and data-centre providers with appropriate independent assurance programs.

5. Encryption

Data transmitted between supported clients and EMERGE services is protected using modern encrypted transport protocols, such as TLS 1.2 or later.

Sensitive production data is encrypted at rest using strong industry-standard cryptography, such as AES-256 or equivalent controls.

Secrets and credentials are managed separately from application data using access-controlled security mechanisms.

EMERGE does not advertise security using generic claims such as “bank-level security”; controls are described using their technical implementation.

6. Identity and access management

The Platform uses role-based access controls designed to restrict information according to authorized user responsibilities.

Controls may include:

  • unique user accounts;
  • role-based permissions;
  • multifactor authentication;
  • session controls;
  • account lockout or risk-based controls;
  • administrative access restrictions;
  • authentication logging; and
  • processes for provisioning and revoking access.

Customers are responsible for assigning appropriate permissions to their workforce.

7. EMERGE workforce access

EMERGE workforce access to production systems is restricted according to job responsibilities and legitimate operational requirements.

Privileged access is limited and monitored.

Personnel with access to sensitive systems or information are subject to confidentiality and security obligations.

8. Logging and monitoring

EMERGE maintains logging and monitoring intended to support:

  • authentication monitoring;
  • investigation of suspicious behaviour;
  • system-health monitoring;
  • security-event investigation;
  • auditability; and
  • incident response.

Security events are reviewed and escalated according to applicable procedures.

9. Application security

EMERGE maintains controls intended to reduce vulnerabilities throughout the software lifecycle.

These may include:

  • peer code review;
  • development and production environment separation;
  • dependency scanning;
  • static application security testing;
  • dynamic application testing;
  • vulnerability scanning;
  • secrets scanning;
  • controlled production deployment;
  • change-management processes;
  • penetration testing; and
  • remediation tracking.

Security vulnerabilities are prioritized based on severity and risk.

10. Network and infrastructure security

Infrastructure controls are designed to restrict unnecessary network exposure and separate publicly accessible services from protected internal resources.

Controls may include firewalls, cloud security controls, intrusion detection or prevention, traffic filtering and monitoring.

Administrative interfaces are restricted according to business need.

11. Endpoint and workforce security

EMERGE maintains safeguards for workforce systems that access corporate or production resources.

These may include device security requirements, endpoint protection, disk encryption, access controls, patching, monitoring and security-awareness training.

12. Backups and disaster recovery

EMERGE maintains backup and recovery procedures intended to support restoration following an operational or security event.

Backups containing sensitive information are protected through security controls appropriate to the underlying information.

13. Security incident response

EMERGE maintains documented procedures for investigating and responding to suspected information-security incidents.

Incident-response activities may include:

  1. detection and triage;
  2. containment;
  3. investigation;
  4. eradication;
  5. recovery;
  6. customer/privacy notification where required; and
  7. post-incident review and corrective actions.

Customers are notified of qualifying incidents in accordance with contractual and legal requirements.

14. Artificial intelligence security and privacy

EMERGE uses AI in certain clinical and administrative workflows.

AI functionality is subject to privacy, security and access controls appropriate to the underlying information.

EMERGE evaluates AI service providers based on factors including:

  • data-use restrictions;
  • retention;
  • security;
  • privacy;
  • model-training practices;
  • residency and processing location;
  • contractual safeguards; and
  • healthcare suitability.

Identifiable Customer PHI is not used to train general-purpose AI models or models available to unrelated customers without appropriate authorization.

AI-generated clinical content is intended to be reviewed by an authorized healthcare professional before clinical reliance.

15. Subprocessor security

Third parties that process sensitive information on behalf of EMERGE are evaluated through EMERGE’s vendor-management process.

Contractual controls are used to address confidentiality, permitted use, security and privacy.

Material subprocessors and relevant processing locations may be disclosed through EMERGE’s Trust Centre.

16. Payment information

Where payment-card functionality is provided, EMERGE uses approved payment-processing services rather than intentionally storing complete payment-card credentials within the clinical record.

17. Business continuity

EMERGE maintains continuity procedures designed to support operations during significant disruptions.

Planning includes dependencies such as infrastructure, workforce availability, communications and recovery of critical services.

18. Customer security responsibilities

Security is shared between EMERGE and its customers.

Customers are responsible for:

  • appropriate account permissions;
  • secure endpoint devices;
  • protecting login credentials;
  • promptly terminating unnecessary access;
  • maintaining secure local networks;
  • workforce privacy and security training; and
  • promptly reporting suspected incidents.

19. Responsible security reporting

Security researchers or customers who believe they have identified a vulnerability should report it privately to:

security@getemerge.ca

Reports should not include unnecessary patient information.

20. Additional assurance information

Qualified customers may request additional security documentation, which may include:

  • SOC 2 documentation;
  • privacy documentation;
  • penetration-testing summaries;
  • architecture documentation;
  • business-continuity information;
  • subprocessor information; and
  • security questionnaire responses.

Some information may require a confidentiality agreement.

Contact

EMERGE Healthcare Co.
Toronto, Ontario, Canada

Security: security@getemerge.ca
Privacy: privacy@getemerge.ca
Support: support@getemerge.ca