Privacy and data
Prototype only. Do not send medical documents, and do not enter a patient name, identifier, or clinical detail. Answers are for criticizing the project.
The production system would be launched only after a formal privacy and legal review. This page describes a target architecture. It claims no current compliance.
Explicit consent
No record is sent without the patient’s clear authorization.
Minimal collection
Only what the requested coordination requires.
Encrypted storage
Planned for a real system. Absent from this prototype, which stores no records.
Encrypted transmission
Clinical transfers would not go by ordinary email.
Access logging
Who opened what, and when.
Role-based permissions
Administrative coordination sees no more than necessary.
Retention
A duration written in advance, not an open-ended archive.
Deletion
A deletion request would have a procedure, subject to legal duties.
Breach response
Whom to notify, on what timeline, and how to limit harm.
Cross-border transfer
A specific Québec–Brazil assessment before any real transfer.
Québec privacy law
Compliance will not be claimed before a formal review.
Brazilian privacy law, where applicable
To be examined with the institutions and local counsel.
Technology supports coordination
- Multilingual intake
- Appointment reminders
- Document classification
- Translation assistance
- Administrative follow-up
- Communication routing
- Status tracking
It never has clinical autonomy
- Diagnose
- Prescribe
- Decide on surgery
- Determine medical urgency on its own
- Override a healthcare professional