Privacy & PHIPA

Your patients’ data, protected.

Healthcare data is not normal data. Here is how MedConcierge handles patient health information.

PHIPA & PIPEDA compliant

MedConcierge acts as your authorized agent under PHIPA. You remain the Health Information Custodian for your patients' records.

Hosted in Canada

All patient data is stored and processed in Canadian data centres. It never leaves Canadian borders.

Encrypted end to end

Patient data is encrypted in transit and at rest, and access is scoped to your practice.

MOH technical specifications

Every OHIP transaction follows Ministry of Health technical specifications and conformance requirements.

Privacy Policy

How MedConcierge collects, uses, and protects personal information.

Last Updated:
July 2, 2026

KEY TERMS

What Personal Information is being collected? MedConcierge may collect Personal Information from you that includes, but is not limited to, contact and identifying information, practice credentials, log-in information and transaction history.

For the full list and more information, see Types of Personal Information Collected and Processed and Methods of Collection of Personal Information below.

For what purposes? MedConcierge may process your Personal Information for purposes including but not limited to, providing our products and services and making the MedConcierge billing platform available to our users, assisting our customers improving our products and services, and generally maintaining our business and complying with applicable laws.

For more information, see Purposes for Collection and Processing of Personal Information below.

Who is MedConcierge sharing my Personal Information with? MedConcierge may share certain types of Personal Information with third parties, including but not limited to, our vendors and service providers that we use to assist us in providing our products and services and running our business and the Ontario Health Insurance Plan for claims processing purposes.

For more information, see Sharing of Personal Information with Third Parties and Request for Information About Third Party Processing below.

What are the risks? Despite the security precautions taken by MedConcierge, no organization can fully eliminate the risks associated with the Processing of Personal Information. There is always a risk that your Personal Information could be subject to a security breach or otherwise be subject to unauthorized access, use or disclosure.

For more information, see Protecting Your Personal Information below.

PRIVACY POLICY

We value the trust that you have placed in MedConcierge Inc. (“MedConcierge”, “we”, “our”, or “us”) and protecting your personal information is our priority. This Privacy Policy (“Policy”) discloses the practices of MedConcierge, regarding the collection, use, safeguard, disclosure, transfer, access, disposal and other processing (collectively, “Processing”) of Personal Information of individuals who engage with MedConcierge for our support, services or otherwise, use the MedConcierge billing platform (the “Platform”), visit our website(s), including medconcierge.ca/privacy (the “Website” and together with the Platform, our “Services”), or contribute to MedConcierge’s social media platforms.

For the purposes of this Policy, personal information (“Personal Information”) shall mean information that can identify an individual directly or indirectly through reasonably available information. In certain jurisdictions, Personal Information does not include information that is used solely for the purpose of communicating or facilitating communication with an individual in relation to their employment, business, or profession.

This Policy is MedConcierge’s way of making sure you are fully informed of MedConcierge’s Personal Information handling practices and policies relating thereto.

EFFECTIVE DATE

This Policy is effective as of the “Last Updated” date, above, and will remain in effect except with respect to any of its provisions that are changed in the future. We reserve the right to change this Policy at any time. Changes, modifications, additions, or deletions will be effective immediately upon their posting to the Services or upon you being otherwise notified. Your continued use of our Services or any other products and services after we post any such modifications will constitute your acknowledgement of the modified Policy and your agreement to abide and be bound by the modified Policy. We will also revise the “Last Updated” date found at the beginning of this Policy when we post changes to it.

Subject to certain legal and contractual limitations, you have the right to withdraw your consent from us Processing your Personal Information. This may limit our ability to provide you with our services, including access to the Platform, act on your behalf, or engage with you as you would like. To withdraw your consent to certain Processing by MedConcierge, you may declare to our designated Privacy Officer (contact information provided below) in writing, at any time, of your desire to withdraw consent. MedConcierge will inform you of the implications of such withdrawal within thirty (30) days of your written request. Any withdrawal of consent will apply thereafter and not to information handling practices that have been previously undertaken based on prior consent. We may, however, collect, use or disclose Personal Information without your knowledge or consent in exceptional circumstances where such collection, use or disclosure is permitted or required by law.

MedConcierge will not knowingly obtain consent from those individuals who are minors, seriously ill, or mentally incapacitated and we shall therefore obtain consent from a parent, legal guardian or person having power of attorney of such an individual.

If you are an individual under the age of majority, you must access or use the Services only with the permission and involvement of your parent or guardian.

COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION

Types of Personal Information Collected and Processed

The Personal Information which MedConcierge may collect includes, but is not limited to:

  • Contact and identifying information, including your name, phone number and email address.
  • Practice credentials and other professional information of physicians and other medical professionals who use our Platform, including College of Physicians and Surgeons of Ontario number, Ontario Health Insurance Plan (“OHIP”) billing number, and practice specialty.
  • Transaction information including details of commercial or other transactions, such as the purchase of or subscription to our products or services.
  • Payment information including your credit card details, bank account information, billing address, and payment or other information required when you purchase or subscribe to our products or services.
  • Profile information and login credentials, including your username and password.
  • Records of your communications with us.
  • User information including messages and images uploaded / shared as part of a public forum, message boards and user chats.
  • Usage information including information about how you use the Services.
  • Technical information including device type, device identifiers, IP address, MAC address, location, browser type, operating system and platform, protocol, sequence information, cookies, beacons, pixel tags, browser language and type, and domain name system requests.
  • Internet or other electronic network activity including browsing, session, interaction, search history, duration of use, frequency of use, material and pages viewed, time and date of access, number of bytes transferred, number of clicks per visit and other user behaviour related to our Services.
  • Other information which you voluntarily provide to us, our service providers, our employees, or our contractors.

We may also collect personal health information of the patients and clients of our users of our Platform. This may include name, health number, gender, treatment and diagnostic codes and billing information, such as date of service, location, admission date, physician name and other information entered by the users of the Platform (including through manual, PDF or Excel upload). In each such case, the user of our Platform, and not MedConcierge, is the health information custodian with respect to such personal health information and shall remain responsible for and shall control the Processing of such information.

We may collect, use and share aggregated information such as statistical or demographic data for any purpose. Aggregated information could be derived from your Personal Information but is not considered “personal information” in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage information to calculate the percentage of users accessing a specific feature of the Services. However, if we combine or connect aggregated information with your Personal Information so that it can directly or indirectly identify you, we treat the combined data as Personal Information which will be used in accordance with this Policy.

Purposes for Collection and Processing of Personal Information

Personal Information may be collected by MedConcierge for purposes that include, but are not limited to:

  • Providing our products and services to our customers and making the Platform available to our users, including to prepare, validate, and submit OHIP billing claims and provide billing-related functionality and workflow support.
  • Maintaining and improving our products and services and otherwise running and managing our business in the ordinary course, and keeping our records up to date.
  • Assisting you when you contact our customer support services, including to direct your questions to appropriate individuals, investigate and address any of your concerns, and to improve and monitor our customer support responses.
  • Administering and protecting our business and the Services, including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data.
  • Using data for business development and market research to understand demographics, interests, usage patterns, and other characteristics of individuals and to track and analyze trends and patterns.
  • Complying generally with all laws and applicable statutory requirements.

Methods of Collection of Personal Information

General

Personal Information may be collected by MedConcierge in a number of ways, including in person, through our Services, by mail, by email, and from third parties whom you have authorized to disclose Personal Information to us.

If you provide information about a third party or authorize a third party to do so, we will assume you have taken proper measures to obtain informed consent.

Platform

Personal Information is collected by MedConcierge when you subscribe for and create an account on our Platform. In order to create and administer your account and authenticate you, we will collect your email address (i.e., your username) and a password that you create. You will also have the option to add information to your account profile, such as your full name, payment information, and organization. You are required to keep your username and password secure and not share it with anyone else.]

Phone Calls

For the purpose of maintaining quality service, telephone calls to MedConcierge’s customer services lines may be recorded. If your call is subject to a quality assurance program, you will be advised prior to speaking to a representative.

Clickstream Data

When you visit the Services, we may also collect clickstream data (e.g. server address, domain name, device type, browsing software) which may be stored on the Services’ server. This information can be combined with information you have provided to us which will enable us to analyze and better customize your visits. We may use clickstream data for traffic analysis or e-commerce analysis of the Services, to determine which features of the Services are most or least effective or useful to you.

Mobile and Location Information

MedConcierge’s Services features may be accessible from web-enabled mobile devices. On some devices, functionality may be limited. If you use mobile-enabled services provided by our Services, we may receive information about you from your mobile device. This may also include information about your precise location if you have enabled location-based services on your mobile device. Some devices may allow you to opt-out of this collection or access, and in those cases, you may be able to subsequently stop the collection or access. Please review your device settings for more information.

Social Media

If you post a review, make a comment, or otherwise submit Personal Information on a public forum such as social media accounts or public forums, your communications may be viewable by the public. When voluntarily disclosing Personal Information about yourself to other users, we are unable to control what may be done with that content. You should take all necessary precautions to protect your private information by not posting or publishing any information that you do not want in the public domain. While we strive to provide the highest level of confidentiality, you should review your personal privacy settings to further restrict any or all parts of your profile or other certain content or information.

Artificial Intelligence

We use artificial intelligence (“AI”) technologies to enhance limited aspects of our operations and to improve the functionality and user experience of our Services.. In particular, we use Amazon Textract to automatically extract text, handwriting, layout elements, and data from documents scanned and uploaded to the Platform by our users.

We will ensure that any use of your Personal Information by our AI tools is in compliance with applicable privacy laws and regulations. We take appropriate measures necessary to mitigate risks associated with AI, including requiring our third-party AI vendors to agree to strict confidentiality and data protection standards and prohibiting them from using your Personal Information to train their own their own AI models. We will also periodically update this Privacy Policy and any associated consent language to accurately reflect our use of AI. These steps ensure that the Processing of your Personal Information remains transparent and aligned with our commitment to privacy.

Other

MedConcierge may collect Personal Information when you interact with us, including when you access the Services, send or respond to our emails, or otherwise communicate with us.

Sharing of Personal Information with Third Parties

Although you are entering into an agreement to disclose your Personal Information to MedConcierge pursuant to this Policy, we may delegate our authority for Processing of your Personal Information to third-party individuals and organizations who assist us with providing our products and services and administering our business, and for such other purposes as set forth below, including:

  • Suppliers, vendors, service providers, agents, contractors and affiliates, including companies we use for storage, processing, and delivery of our products and services.
  • Administrative and technical support, including cloud storage providers, software providers, IT support, and data analytics providers.
  • The OHIP for claims processing purposes in connection with the provision of our services.
  • Parties in connection with proposed or actual financing, insuring, sale, securitization, assignment or other disposal of all or part of our business or assets.

We use the following third-party service providers to Process Personal Information:

Third PartyCategory of SubprocessorLocation of Processing
Amazon Web ServicesCloud storage providerCanada
Helcim Inc.Payment processorCanada & USA
Sendinblue dba BrevoCRM software providerEuropean Union

We do not store your payment information for online purchases and subscriptions. This information is shared directly with our third-party payment providers including financial institutions and payment processors, such as Helcim Inc.

We may also disclose Personal Information in situations where we are legally required or permitted to do so. These situations may include criminal investigations, government tax reporting requirements, court orders, or instances where we believe the rights and safety of others may be at risk.

If you believe that a third party has inappropriately disclosed your Personal Information to us, please contact that third party directly. If the third party does not sufficiently respond to your inquiries, please let us know immediately.

MANAGING YOUR PERSONAL INFORMATION

Limiting the Collection and Processing of Personal Information

MedConcierge takes care to ensure that Personal Information you provide to us is accessed internally only by individuals that require access to perform their tasks and duties, and externally only by service providers with a legitimate purpose for accessing it. We will not use or disclose any collected Personal Information outside of the purposes described in this Policy unless you have otherwise consented or it is required or permitted by law.

We do not sell, trade, rent or otherwise share for marketing purposes the Personal Information that we collect with third parties, unless you consent or authorize us to do so. We limit the Personal Information provided to the aforementioned third-party service providers to the extent necessary for them to provide the services. We do not allow these third-party service providers to use your Personal Information for their own purposes and only permit them to access and process your Personal Information for specified purposes and in accordance with our instructions. Such service providers are required by contract to safeguard any Personal Information disclosed or transferred by us.

Accuracy of Personal Information

MedConcierge takes all reasonable steps to keep your Personal Information as accurate, complete and up-to-date as necessary to fulfill the purpose for which your Personal Information has been collected. If desired, you may verify the accuracy and completeness of your Personal Information in our records with our Privacy Officer.

Despite our efforts, errors sometimes do occur. Should you identify any incorrect or out-of-date Personal Information in your file, we will remedy any such errors on a timely basis. You may request correction of the Personal Information we hold about you, though we may need to verify the accuracy of the new information you provide to us. If inaccurate Personal Information is mistakenly sent to a third party, we will communicate relevant changes to the third party where appropriate.

Making Changes to Your Account

You can review and change Personal Information that is displayed in your profile on the Platform, and can close your account at any time. If you wish to have us delete all data about you held on our servers or otherwise, contact us and we can assist with this. Contact information can be found at the end of this Policy document.

Retention of Personal Information

MedConcierge will store your Personal Information only for as long as is reasonably necessary to fulfill the purpose for which the Personal Information was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. Once your Personal Information is no longer needed, we will securely and effectively dispose of it.

To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this anonymized information indefinitely without further notice to you.

Request for Access to Personal Information and Processing

You may request access to your Personal Information, which enables you to receive a copy of the Personal Information we have collected from you and information about how we are Processing it, in a commonly used and structured electronic format.

We may need to request specific information from you to help us confirm your identity and right to access your Personal Information. This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. MedConcierge may not always be able to comply with your request for access to Personal Information for specific reasons which you will be notified of, if applicable, in our response to your access request.

Request for Information About Third Party Processing

You have the right to receive information that identifies any third-party companies or individuals that we have shared your Personal Information with, as well as a description of the categories of Personal Information disclosed to that third party. You may obtain this information by contacting our Privacy Officer.

Opting Out of Certain Personal Information Processing

You also have the right to opt-out of certain Personal Information Processing, including the disclosure of Personal Information to third parties which is not reasonably necessary for providing the products and services you’ve requested or as otherwise required by law.

PROTECTING YOUR PERSONAL INFORMATION

Integrity and Security

MedConcierge uses industry standard measures, including administrative, organizational, technical, and physical safeguards, to help protect Personal Information from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. We implement measures and processes to help us keep your Personal Information secure and to maintain its quality. We regularly review our security and related policies to adapt the technology as new threats evolve and monitor our systems to help ensure the highest level of availability. If you have any questions about the security of our Services, you can reach out to our Privacy Officer.

Access to private, sensitive and confidential information, including Personal Information, is restricted to authorized employees or contractors with legitimate business reasons. MedConcierge’s employees and contactors understand the importance of keeping your Personal Information private. All employees and contractors are expected to maintain the confidentiality of Personal Information.

Risks

Despite the foregoing security measures and significant steps MedConcierge has taken to protect your Personal Information, no organization can fully eliminate all security risks associated with the Processing of Personal Information. With that in mind, we cannot guarantee the security of any Personal Information provided to or received by us. We encourage you to keep watch for communications that are suspicious, and report any suspicious activity to us as soon as possible.

In the event there has been a breach of our security safeguards which involve your Personal Information, including the unauthorized access, use or disclosure of your Personal Information, loss of your Personal Information, or other breach, and where there is a risk that significant harm will come to you as a result of that breach, MedConcierge will notify you and, if required, the applicable privacy commissioner or other data protection authority.

SERVICES GOVERNED BY THIS POLICY

The Services and our other products and services are governed by the provisions and practices stated in this Policy. Our Services may contain links to third-party sites or applications that are not governed by this Policy. Although we endeavour to only link to sites or applications that share our commitment to your privacy, please be aware that this Policy will no longer apply once you leave our Services, and that we are not responsible for the privacy practices of third-party sites or applications. We therefore suggest that you closely examine the respective privacy policies of third-party sites and applications to learn how they collect, use and disclose your Personal Information.

LOCATION OF PROCESSING

Personal Information provided to our service providers may be stored outside of Canada, including as set out in the “Sharing of Personal Information with Third Parties” section of this Policy. You acknowledge and agree that, as a result, your Personal Information may be processed, used, stored or accessed in other jurisdictions and may be subject to the laws of those jurisdictions. For example, information may be disclosed in response to valid demands or requests from government authorities, courts, or law enforcement in other countries.

ADDRESSING YOUR INQUIRIES AND CONCERNS

Your privacy is very important to us. We are happy to provide you with a copy of this Policy in an alternative, accessible format and to discuss any of its contents with you.

MedConcierge’s Privacy Officer is responsible for the implementation of this Policy and monitoring our adherence to its terms and all applicable laws. The Privacy Officer also handles questions and concerns about our Policy, as well as Personal Information access requests and complaints. You may also seek advice from the applicable privacy commissioner or other data protection authority and, if appropriate, file a written complaint with such data protection authority.

MedConcierge’s Privacy Officer may be contacted at:

Privacy Officer, MedConcierge Inc.admin@medconcierge.ca181 Bay Street, Suite 1800Toronto, OntarioM5J 2T9

Data Processing Addendum

Incorporated into and forming part of the Terms of Use.

This Data Processing Addendum (“DPA”) forms part of the Terms or other agreement governing the use of the Services (“Terms”) entered by and between you (“Customer“ or “you”) and MedConcierge Inc. (“MedConcierge”).

WHEREAS, the Terms may require MedConcierge to process Personal Information (as defined below) provided by or collected on behalf of Customer or Authorized Users; and

WHEREAS, this DPA sets out additional terms, requirements and conditions for Processing Personal Information when MedConcierge provides access to the Service to Customer and its Authorized Users under the Terms,

NOW, THEREFORE, in consideration of the mutual covenants and agreements contained in this DPA and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties agree as follows:

PRIVACY

Definitions. Any capitalized terms used but not defined herein shall have the meaning given to such term in the Terms. For the purposes of this DPA, the following terms will have the meanings set forth below:

“MedConcierge Personnel” means all employees, officers, partners, personnel, agents, representatives, sub-contractors, vendors, independent contractors or other third party contractors of MedConcierge.

“Requirements” has the meaning set out in Section 1.5.

“Security Incident” has the meaning set out in Section 2.2.

This DPA is subject to the terms of the Terms and is incorporated into the Terms by reference. In the case of conflict or ambiguity between any provision contained in the Terms and any provision contained in this DPA, the provision contained in this DPA will prevail.

As between Customer and MedConcierge, all Personal Information is and will be deemed to be and remain the exclusive property of Customer. Customer retains control of the Personal Information and remains responsible for its compliance obligations under the applicable Privacy Laws, providing any required notices and obtaining any required consents, and for the Processing instructions it gives to MedConcierge. Customer acknowledges that MedConcierge is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions or the Personal Information other than as required under applicable Privacy Laws.

Without limiting the foregoing, Customer acknowledges that it is a “health information custodian” and that MedConcierge acts as its “agent”, each as defined in PHIPA, solely for the purposes set out in this DPA and the Terms. Customer acknowledges that the Service is provided in support of, and not in substitution for, its obligations as a health information custodian under PHIPA.

To the extent that MedConcierge Processes any Personal Information in connection with Customer’s access to the Service, MedConcierge shall comply with the information privacy and security requirements set out in this DPA (“Requirements”).

Privacy Requirements. MedConcierge confirms that it will comply with applicable Privacy Laws in the course of Processing any Personal Information in connection with the Service. Further, Personal Information shall be maintained by MedConcierge in accordance with its Privacy Policy available at medconcierge.ca/privacy. The Privacy Policy is hereby incorporated into and forms a part of this DPA and the Terms, by reference.

Without limiting the foregoing, MedConcierge shall:

  • only Process Personal Information for the purposes of providing you with access to the Service, complying with legal obligations, court orders, or regulatory requirements and as otherwise instructed by Customer from time to time, including to:
    • prepare, validate, and submit OHIP claims and related billing transactions on Customer’s behalf;
    • perform health card validation and patient eligibility checks;
    • process remittance advice and reconcile claim outcomes;
    • provide technical support, troubleshooting, and customer service in response to Customer requests; and
    • operate, maintain, secure, monitor, and improve the Service, including software development, debugging, error investigation, and quality assurance;
  • not disclose Personal Information to any third party without the prior consent of Customer except to the extent that a disclosure or transfer is permitted by this DPA, the Terms or required by law;
  • to the extent permitted by law, promptly notify Customer of any (i) enquiry received from an individual relating to, among other things, the individual’s right to access, modify or correct Personal Information, (ii) complaint received by MedConcierge relating to the Processing of Personal Information, and (iii) order, demand, warrant or any other document purporting to compel the production of any Personal Information, and to reasonably assist Customer in retrieving, exporting, or correcting Personal Information within the Service to support any such inquiry;
  • establish and maintain written security (including the security requirements set forth in Section 2 of this DPA) policies and procedures as necessary for MedConcierge to comply with the obligations set out in this DPA, and provide information regarding such policies and procedures to Customer at Customer’s request;
  • reasonably assist Customer, at Customer’s cost, with meeting Customer's compliance obligations under applicable Privacy Laws in relation to Personal Information, considering the nature of MedConcierge’s Processing and the Personal Information available to MedConcierge;
  • maintain reasonable records of its Processing of Personal Information and provide Customer (or its representatives), upon reasonable advance written notice and legal grounds, with reasonable access to such records for the purpose of Customer fulfilling any legally obligated audit requirement to verify MedConcierge’s compliance with this DPA; and
  • upon the termination of the Terms and subject to any export obligations in the Terms, return (or securely dispose of) the Personal Information in the possession or control of MedConcierge, unless retention is otherwise required by applicable law.

Third Party Sub-Processors. Customer acknowledges and agrees that MedConcierge may engage third parties, including affiliates of MedConcierge and other service providers, to Process Personal Information in connection with the Services. MedConcierge has entered into a written agreement with each such third party containing, in substance, data protection obligations no less protective than those in this DPA with respect to the protection of Personal Information to the extent applicable to the nature of the Services provided by such third party.

SECURITY REQUIREMENTS

Security Requirements. MedConcierge will use commercially reasonable security measures for its computer systems and information storage facilities which are designed to safeguard against the unauthorized destruction, loss, alteration of, Processing or access to Personal Information (whether such information is: (a) on MedConcierge’s systems or stored in MedConcierge’s facilities; (b) in transit or being disposed of; or (c) in hard copy or electronic format).

Security Incident. If MedConcierge discovers any theft or unauthorized loss or access to Personal Information or other illegal Processing of Personal Information (each a “Security Incident”), MedConcierge will as soon as reasonably possible: (a) notify Customer of such Security Incident; and (b) if the applicable Personal Information was in the possession of MedConcierge at the time of such Security Incident, MedConcierge shall: (i) start an investigation of the Security Incident and (ii) provide Customer with a written report on the outcome of its investigation.

Information Security Guidelines. MedConcierge has adopted, documented, implemented and shall adhere to commercially reasonable written information security guidelines for maintaining security controls designed to protect Personal Information against accidental, unauthorized or unlawful destruction, loss, alteration, disclosure, and access, and against all other unlawful activities and shall reasonably discuss such guidelines with Customer. MedConcierge’s information security guidelines shall include physical, organizational, administrative and technical controls. The controls shall relate to the collection, maintenance (including access rights), transmittal and disposal of Personal Information.

MedConcierge Personnel. With respect to any MedConcierge Personnel who at any time have access rights to Personal Information, MedConcierge will: (i) limit such access to only those MedConcierge Personnel with a need for such access in order to perform MedConcierge’s obligations under the Terms; (ii) advise such MedConcierge Personnel (via training or other processes designed to acquaint such person with the security guidelines/programs instituted by MedConcierge) of the Requirements under this DPA and applicable laws; and (iii) obligate such MedConcierge Personnel to abide by the security guidelines/programs instituted by MedConcierge, prior to providing them with such access rights.

Penetration Testing. MedConcierge will periodically retain, at its sole cost and expense, an independent third party to conduct a penetration test of MedConcierge’s infrastructure designed to detect any material security weaknesses in such infrastructure.