Legal
Privacy Policy
Effective August 11, 2026
Running a health plan means being trusted with sensitive information. This policy explains, in plain language, what we collect through this website and the Medallion client portal, why we collect it, who can see it, and the choices you have.
Who this policy covers
Medallion Health Corporation (“Medallion”, “we”) administers cost-plus Private Health Services Plans (PHSPs) for incorporated Canadian businesses. This policy applies to visitors to this website, businesses that apply for a plan, corporate administrators, plan members and their dependents, and anyone who contacts us.
We handle personal information in accordance with Alberta's Personal Information Protection Act (PIPA) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
What we collect
We collect only what we need to set up and run your plan:
- Contact and identity information: your name, email address, phone number, role or title, and company details, provided when you apply, sign up, or request a consultation.
- Plan and employment information: the participant roster, how each participant is paid (the employment attestation on the application), and each member's coverage limits and elections.
- Dependent information: names, dates of birth, relationship, and post-secondary enrolment or disability/infirmity status where relevant to eligibility.
- Health and claims information: the claims you submit, expense categories, amounts, and the receipts and supporting documents you upload, which can include health information about you and your dependents. We collect this only to adjudicate and administer claims.
- Banking information: your corporation's pre-authorized debit (PAD) account details and each member's personal direct-deposit details, together with the void cheque or bank form you upload so we can verify them. Referral agents who receive commission payouts also provide a payout account and the tax-reporting details the Income Tax Act requires for T4A slips: the payee's legal name, mailing address, and Social Insurance Number (or a corporation's legal name and CRA Business Number). Tax identifiers are encrypted at rest and visible only to Medallion staff.
- Electronic-signature records: described in the next section.
- Account and technical information: sign-in and two-factor authentication enrolment data, an audit log of actions taken in the portal, and the essential cookies described below.
Electronic signatures: what we record
When you sign an agreement electronically (the Plan & Administration Agreement on the application, the pre-authorized debit agreement, or the direct-deposit authorization), we create a signing record so both sides can prove what was agreed. That record includes your typed signature, the exact version of the agreement and a cryptographic fingerprint (hash) of its wording, the date and time on our servers, the IP address and browser identification (user-agent) of the device you signed from, and a signed PDF copy of the agreement.
These records exist to establish that the agreement was made, by whom, and that it has not been altered since. They form part of our legal records, are protected against tampering, and are retained with your plan records for the retention period below. A copy of each signed agreement is also emailed to you at the time of signing.
How we use your information
- Administering your plan: setting up the company and its members, managing coverage limits, and adjudicating claims.
- Processing payments: debiting the corporate funding account by pre-authorized debit and reimbursing members by direct deposit, through our bank.
- Verifying banking details: a member of our staff reviews every funding and deposit account (including the signed authorization and bank document) before any money moves.
- Communicating with you: transactional emails such as claim status updates, portal invitations, and copies of signed agreements, plus responses to your inquiries.
- Keeping records: audit trails and signing records that support the integrity of the plan, and records we are required to keep under tax law.
We do not sell personal information, and we do not use it for advertising.
What your employer can see
Health information is sensitive, so the portal separates what employers and Medallion can see, and enforces it at the database layer, not just on screen.
- On an employee's claim, the company's administrators see only: the employee's name, the claim date, a generic expense category, the total amount, and the claim's status.
- They never see patient names (for example, which family member the expense was for), individual line-item descriptions, or receipts.
- Medallion staff see full claim details, because we adjudicate the claims.
- A corporate administrator's own claims skip employer review entirely and go straight to Medallion staff.
Where your information is stored
Your primary records (the database and every uploaded document, including receipts and bank documents) are stored in Canada, in Amazon Web Services' ca-central-1 (Montreal) region. Supporting services such as website delivery and email may process limited information outside Canada; while information is outside Canada it is subject to the laws of those jurisdictions.
How long we keep it
Plan, claim, payment, and signing records, including receipts, are kept for seven calendar years, in line with Canada Revenue Agency record-keeping requirements plus a margin, and are then securely destroyed. Consultation requests and applications that do not become plans are kept only as long as reasonably needed.
How we protect it
- Encryption in transit (TLS) and at rest.
- Mandatory two-factor authentication on every portal login, clients and staff alike.
- Role-based access enforced at the database layer (row-level security), including the employer-visibility limits described above.
- Receipts, bank documents, and signed agreements live in private storage accessible only through short-lived, authenticated links.
- A tamper-evident, append-only audit log of significant actions.
- Human review before any bank account is used to move money.
Your choices and rights
You may ask to see the personal information we hold about you, ask us to correct it, or ask questions about how it has been used or shared. You may also withdraw consent, though that can limit our ability to administer your plan, and some records must be retained by law even after a plan ends.
To exercise any of these rights, contact our Privacy Officer using the details below. If we cannot resolve a concern, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
Contact us
Our designated Privacy Officer is Chris Burylo. Write to: Chris Burylo, Privacy Officer, Medallion Health Corporation, 204 – 2333 18 Ave NE, Calgary, AB T2E 8T6 · admin@medallionhealth.ca · 403-452-2755.
If we change this policy, we will post the updated version here with a new effective date.
Questions about anything here? Get in touch. We would rather explain it than have you wonder.