Privacy Policy & Notice of Information Practices

Aria MD Sleep Centre
Last Updated: July 15, 2026

1. Purpose of This Notice

This Privacy Policy and Notice of Information Practices explains how Aria MD Sleep Centre (“Aria MD,” “we,” “us,” or “our”) collects, uses, discloses, stores, retains, and protects personal information and personal health information in the course of providing sleep-medicine services, diagnostic sleep testing, PAP therapy support, billing, referral management, and related administrative services.

This notice is intended to comply with applicable Canadian and Alberta privacy laws, including Alberta’s Health Information Act (“HIA”), Alberta’s Personal Information Protection Act (“PIPA”), and the Personal Information Protection and Electronic Documents Act (“PIPEDA”) where applicable. It is also intended to reflect recognized healthcare privacy and security best practices.

2. Scope of This Policy

This policy applies to all interactions with Aria MD Sleep Centre, including but not limited to:

  • In-clinic services at any Aria MD location;
  • Diagnostic sleep testing, including home sleep apnea testing and in-lab testing where applicable;
  • PAP therapy, PAP device support, compliance monitoring, and device-data review;
  • Website, online forms, patient portals, appointment booking, and digital communications;
  • Phone, email, SMS/text message, fax, mail, and written communications;
  • Referrals, physician communications, billing, insurance processing, and payment administration;
  • Quality assurance, risk management, staff training, complaint handling, and operational review; and
  • Security practices, including call review/recording and video surveillance where used and permitted by law.

This policy is primarily intended for patients, caregivers, referral sources, website users, and other individuals who interact with Aria MD in relation to patient care or clinic services.

Employee and contractor personal information may be addressed through separate internal policies, employment agreements, confidentiality agreements, workplace notices, or applicable employment-related privacy practices.

3. Definitions

  • Personal Information: Information that identifies or can reasonably be linked to an individual, such as name, address, contact details, date of birth, payment information, or insurance information.
  • Personal Health Information / Health Information: Information about an individual’s physical or mental health, healthcare services, diagnosis, testing, treatment, physician reports, PAP therapy, device data, or payment for care. In this policy, “personal health information” is used broadly and includes health information and individually identifying health information where applicable under Alberta law.
  • Custodian: A person or organization that has duties under Alberta’s Health Information Act, where applicable. This may include physicians and certain other health professionals or health organizations.
  • Affiliate: A person or organization that performs services for or on behalf of a custodian, where applicable, and may include employees, contractors, administrative staff, clinical staff, or service providers.
  • Service Providers: Third parties that perform services for Aria MD or for healthcare providers involved in care, under confidentiality and privacy obligations, such as EMR vendors, device platforms, billing processors, IT providers, communications providers, and cloud/hosting providers.
  • Privacy Breach: The loss of, unauthorized access to, or unauthorized disclosure of personal information or personal health information.

4. Role Under Alberta Privacy Law

Aria MD Sleep Centre may collect, use, disclose, store, and retain personal information and personal health information to provide sleep-medicine and related healthcare services. Depending on the service, Aria MD may handle information on its own behalf, on behalf of a physician or other health custodian, or through authorized service providers.

Where Aria MD works with physician custodians, regulated health professionals, or other custodians under Alberta’s Health Information Act, Aria MD staff, contractors, and service providers are expected to handle health information in accordance with applicable HIA obligations, confidentiality requirements, professional obligations, and internal privacy policies.

Nothing in this policy limits any duty that may apply under law, professional standards, a court order, a regulatory requirement, or a valid request from an authorized public body or health authority.

5. Information We Collect

We collect only the information that is reasonably necessary to provide safe, effective, and lawful healthcare services and to operate our clinic responsibly.

a) Personal Information

Personal information may include:

  • Name, address, email address, phone number, and preferred communication method;
  • Date of birth and demographic information required for care or identification;
  • Health card number, insurance details, claim information, and payment information;
  • Emergency contact information and authorized caregiver or representative details; and
  • Identity-verification information required to protect patient privacy.

b) Personal Health Information

Personal health information may include:

  • Medical history, referrals, consultation requests, and clinical intake information;
  • Sleep study results, including HSAT, PSG, oximetry, and related diagnostic information;
  • PAP therapy information, including usage, compliance, mask leak, pressure, efficacy, troubleshooting notes, and device downloads;
  • Clinical notes, diagnoses, treatment plans, physician reports, prescriptions, and correspondence;
  • Information exchanged with physicians, caregivers, insurers, or other healthcare providers involved in care; and
  • Information needed for billing, insurance claims, medical-legal purposes, or regulatory obligations.

c) Technical, Website, and Communications Information

Technical and communications information may include:

  • Website usage data, IP address, browser type, device information, cookies, and online form submissions;
  • Secure portal access logs, audit logs, and authentication information;
  • Email, SMS/text, fax, phone, voicemail, and written communications;
  • Telephone call recordings or call-review notes where calls are recorded or reviewed for quality assurance, training, patient safety, documentation, complaint resolution, or operational purposes; and
  • Video surveillance footage in clinic areas where used for safety, security, and loss-prevention purposes and where appropriate notice is provided.

6. How We Use Information

We may use personal information and personal health information for the following purposes:

  • Providing, managing, documenting, and coordinating healthcare services;
  • Assessing, diagnosing, treating, and supporting sleep-related conditions;
  • Reviewing sleep study results, PAP therapy data, and ongoing compliance or therapy effectiveness;
  • Communicating with patients, physicians, caregivers, substitute decision-makers, and healthcare providers involved in care;
  • Scheduling appointments, sending reminders, managing accounts, and responding to inquiries;
  • Processing billing, payment, insurance claims, third-party payer requests, and refunds;
  • Supporting quality assurance, staff training, audit, complaint handling, risk management, and patient-safety review;
  • Maintaining clinic security, preventing loss or misuse of property, and investigating incidents where appropriate;
  • Meeting legal, regulatory, professional, insurance, accreditation, and record-keeping obligations; and
  • Improving our website, services, workflows, and patient experience.

We do not use personal health information for unrelated advertising or third-party marketing without explicit consent. We do not sell, rent, trade, or broker patient information.

7. Disclosure of Information

We disclose information only as permitted or required by law and only to the extent reasonably necessary for the purpose of the disclosure.

We may disclose information:

  • To physicians, respiratory therapists, nurses, and other healthcare providers involved in the patient’s care;
  • To laboratories, diagnostic partners, PAP manufacturers, PAP device platforms, and therapy-monitoring platforms as required for testing, treatment, or device support;
  • To service providers who support our operations, such as EMR systems, IT providers, communications providers, appointment-booking systems, billing providers, payment processors, secure document storage, cloud services, and professional advisors, under confidentiality and privacy obligations;
  • To insurers, benefits providers, third-party payers, or government programs for billing, claims, preauthorization, or payment purposes;
  • To a parent, guardian, caregiver, substitute decision-maker, or authorized representative where permitted by law and appropriate in the circumstances;
  • When required by law, court order, subpoena, warrant, regulatory authority, professional college, public health authority, or other lawful authority;
  • To prevent or respond to a serious threat to the health or safety of the patient or another person, where permitted by law; and
  • For legal, insurance, audit, investigation, or risk-management purposes where authorized or required.

We do not sell, rent, trade, or share patient information for data brokerage or third-party advertising.

8. Consent

Consent may be obtained verbally, in writing, electronically, or implied through the provision of care where permitted by law. The type of consent required may depend on the nature of the information, the purpose of the collection/use/disclosure, the urgency of care, and applicable legal or professional requirements.

Patients may withdraw or limit consent at any time, subject to legal, clinical, billing, insurance, regulatory, and record-keeping limitations. A withdrawal of consent may affect our ability to provide services, communicate with other healthcare providers, complete insurance processing, or support ongoing therapy.

Where a patient authorizes Aria MD to communicate with a family member, caregiver, employer, insurer, or other third party, we may require written or documented authorization before disclosing health information.

9. Safeguards and Security

We use reasonable administrative, technical, and physical safeguards to protect personal information and personal health information against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks. Safeguards may include:

  • Secure electronic medical record systems and access controls;
  • Role-based access to patient information based on job duties;
  • User authentication, password controls, audit logs, and access monitoring;
  • Encryption or secure transmission methods where appropriate;
  • Staff confidentiality training and privacy-policy review;
  • Confidentiality obligations for employees, contractors, and service providers;
  • Staff and contractors may access patient information only where required for assigned duties, patient care, billing, administration, quality assurance, complaint handling, or another authorized purpose;
  • Reasonable safeguards for remote access, laptops, mobile devices, portable storage, and reporting of lost or stolen devices where applicable;
  • Secure storage of paper records, prescriptions, forms, and reports;
  • Secure disposal or destruction of records when retention is no longer required;
  • Physical security controls in clinic areas; and
  • Incident response, privacy-breach assessment, and corrective-action processes.

While we take reasonable steps to protect information, no system, device, email platform, SMS system, website, portal, or storage method can be guaranteed to be 100% secure.

10. Privacy Breaches

If we become aware of a privacy breach involving personal information or personal health information, we will take reasonable steps to contain the breach, assess the risk, notify affected individuals and regulators where required by law, and take corrective action to reduce the risk of recurrence.

Employees, contractors, and service providers must report suspected or confirmed privacy breaches to the Privacy Officer or responsible custodian as soon as possible. Where Aria MD is acting on behalf of a physician or other custodian, Aria MD will coordinate with the responsible custodian to assess and respond to the breach in accordance with applicable legal requirements.

Where a breach involves health information handled under Alberta’s Health Information Act, notification may be required to affected individuals, the Office of the Information and Privacy Commissioner of Alberta, and the Minister of Health where the applicable legal threshold is met. Where a breach involves personal information under Alberta’s Personal Information Protection Act, notification may be required to the Office of the Information and Privacy Commissioner of Alberta where there is a real risk of significant harm.

11. Retention of Information

We retain personal information and personal health information only as long as required to provide care, manage patient accounts, meet professional and legal record-keeping obligations, comply with regulatory requirements, resolve disputes, support insurance or audit obligations, and protect legal rights.

Clinical records are retained in accordance with applicable legal and professional requirements. In Alberta, physician patient records are generally retained for at least 10 years from the date of the last record entry for an adult patient. For a minor patient, records are generally retained for at least 10 years after the date of the last record entry, or two years after the patient reaches or would have reached 18 years of age, whichever is longer.

Operational records such as call recordings, video surveillance footage, website logs, access logs, electronic communication records, and similar administrative records are retained only as long as reasonably necessary for the purpose for which they were collected, unless longer retention is required for patient care, quality assurance, complaint handling, investigation, insurance, legal, regulatory, audit, or other legitimate purposes.

Records are securely destroyed, deleted, or anonymized when they are no longer required, unless continued retention is required or permitted by law, professional standards, litigation hold, audit, insurance requirement, or another legitimate purpose.

12. Patient Rights

Subject to applicable law and identity verification, patients may have the right to:

  • Request access to their personal information or personal health information;
  • Request correction of inaccurate or incomplete information;
  • Receive information about certain disclosures where required by law;
  • Ask questions about how information is collected, used, disclosed, stored, or retained;
  • Request limits on certain uses or disclosures where feasible and legally permitted;
  • Withdraw or modify consent, subject to legal and clinical limitations; and
  • File a privacy complaint with Aria MD or, where applicable, with the Office of the Information and Privacy Commissioner of Alberta.

Requests must be made in writing and may require identity verification. We may refuse, limit, or delay access or correction requests where permitted or required by law, including where disclosure could affect another person’s privacy, interfere with an investigation, or be otherwise restricted by law.

We will respond to access and correction requests within the timelines required by applicable law. Requests involving health information under Alberta’s Health Information Act are generally responded to within 30 days, subject to permitted extensions. Requests involving personal information under Alberta’s Personal Information Protection Act are generally responded to within 45 calendar days, subject to permitted extensions.

13. Children, Minors, Guardians, and Substitute Decision-Makers

We collect, use, and disclose information about minors only as reasonably necessary for care, administration, billing, and other lawful purposes. Consent, access, and privacy rights for minors are handled in accordance with applicable legislation and professional standards.

A parent, legal guardian, or substitute decision-maker may exercise rights on behalf of a minor or incapable patient where legally authorized. In some circumstances, a minor may be capable of making their own healthcare or privacy decisions. Aria MD may assess capacity, guardian authority, and the nature of the information before disclosing records or accepting instructions.

Where there is uncertainty about authority, consent, access, or disclosure involving a minor or substitute decision-maker, we may request documentation or seek guidance before releasing information.

14. Electronic Communications

Aria MD may communicate by phone, voicemail, email, SMS/text message, fax, website form, secure portal, or other electronic means for appointment reminders, clinical communication, administrative purposes, billing, therapy follow-up, and patient support.

Electronic communication can carry risks, including interception, misdirection, delayed delivery, unauthorized access, or storage by third-party service providers. By providing contact information or communicating electronically with Aria MD, patients acknowledge these risks unless they request an alternate method of communication.

Patients who do not wish to communicate by email or SMS/text may request an alternate communication method, although this may affect the speed or convenience of communication.

Patients may opt out of certain non-essential electronic communications at any time. However, opting out may affect appointment reminders, therapy support, administrative communication, or other service-related notices.

Email and SMS/text messaging should not be used for urgent medical concerns. Patients requiring urgent medical attention should call 911 or seek emergency care.

15. Telephone Calls and Quality Assurance

Telephone calls may be recorded or reviewed for quality assurance, staff training, patient safety, documentation, complaint handling, operational review, and dispute-resolution purposes where permitted by law. Call recordings, call notes, and related records may be stored, accessed, retained, and disclosed in accordance with this policy and applicable legal requirements.

Where call recording is used, Aria MD will make reasonable efforts to provide notice, such as through phone-system messaging, signage, forms, or other appropriate methods.

16. Video Surveillance and Site Security

Where video surveillance is used at Aria MD locations, it is used for safety, security, loss prevention, incident review, and operational purposes. Surveillance will be limited to areas and purposes that are reasonable in the circumstances and will not be used in washrooms or other areas where a person has a reasonable expectation of complete privacy.

Cameras will be positioned, where reasonably possible, to avoid capturing clinical discussions, private health information, computer screens, treatment details, or other sensitive information that is not necessary for safety, security, or loss-prevention purposes.

Video footage may be accessed by authorized personnel and may be disclosed to law enforcement, insurers, regulatory authorities, or legal advisors where permitted or required by law. Surveillance footage is retained only as long as reasonably necessary unless required for an investigation, legal matter, insurance claim, or other legitimate purpose.

17. Third-Party Service Providers and Cross-Border Processing

Aria MD may use service providers and technology platforms to support healthcare delivery, diagnostic testing, PAP therapy monitoring, electronic records, billing, payment processing, secure communication, appointment booking, website hosting, data storage, IT support, backup, and other operations.

Some service providers or technology platforms may store or process information outside Alberta or outside Canada. Where this occurs, information may be subject to the laws of the jurisdiction where it is stored or processed. We use reasonable contractual, administrative, technical, and physical safeguards to protect information handled by service providers.

Service providers are expected to use information only for the purposes of providing services to Aria MD or to healthcare providers involved in the patient’s care, and to protect information in accordance with confidentiality, privacy, and security obligations.

18. Website, Cookies, Analytics, and Online Forms

Our website may collect limited technical information such as IP address, browser type, device information, pages visited, date/time of access, cookies, online form submissions, and related website-usage information. This information may be used to operate the website, respond to inquiries, improve services, maintain security, troubleshoot issues, and understand general website performance.

If website analytics, advertising tools, or similar technologies are used, they will be handled in accordance with applicable privacy laws. We do not sell patient information or use personal health information for third-party advertising.

Patients should avoid submitting urgent medical concerns through website forms. Website forms and general email may not be appropriate for urgent or highly sensitive health information unless a secure process is specifically provided.

19. Third-Party Websites and Platforms

Our website, communications, portals, or device-support processes may reference third-party websites, platforms, manufacturers, payment processors, or patient tools. We are not responsible for the privacy practices, security, or content of external services that are not controlled by Aria MD. Patients should review the privacy policies and terms of any third-party platform they use.

20. Accuracy and Updates

Patients are responsible for informing Aria MD of changes to contact information, physician information, insurance details, caregiver authorization, or other information needed to provide care and communicate appropriately. We take reasonable steps to maintain accurate and complete information for the purposes for which it is used.

21. Changes to This Policy

We may update this Privacy Policy and Notice of Information Practices from time to time. The most current version will be available upon request or on our website. Material changes will be communicated where required by law or where appropriate in the circumstances.

22. Contact Information and Privacy Officer

Questions, access requests, correction requests, consent changes, concerns, or privacy complaints may be directed to:

Privacy Officer
Aria MD Sleep Centre
10202 111 Street NW
Edmonton, AB T5K 1K9
Phone: 1-780-784-1353
Email: [email protected]
Website: www.ariasleep.com

Privacy complaints will be reviewed by the Privacy Officer or designate. Aria MD may investigate the concern, request additional information, provide a written response where appropriate, and take corrective action if required. If a concern is not resolved, individuals may have the right to contact the Office of the Information and Privacy Commissioner of Alberta or another applicable regulator.

We’re excited to welcome you to our brand-new East Edmonton Sleep Clinic!

Appointments are now available starting February 2, 2026. Book your visit and take the first step toward better sleep with expert diagnostic testing and personalized care tailored to you.