This internal policy stems from the implementation of Law 25, which mandates Quebec businesses to adopt and implement a Personal Information Protection (PIP) policy as part of their normal course of business.
Services Progressifs placements en soins de santé, "SP," is committed to ensuring, to the best of its abilities, the protection of entrusted personal information. SP undertakes to restrict access to personal and sensitive data to prevent compromise, ensuring no harm to its employees, clients, suppliers, or any individuals who have provided such information.
While zero risk is unattainable, it is understood that this internal policy aims to minimize the risks of personal information theft.
The policy applies to any information containing personal data of individuals, including employees, clients, suppliers, or third parties, enabling their identification. It extends to all servers, databases, and computer systems processing such data, including any devices regularly used for email, web access, or other professional tasks. Any user interacting with our information services is subject to this policy.
The policy does not apply to publicly classified information.
The personal information held by SP is essential to its ongoing activities. Therefore, SP acknowledges that these data must undergo constant assessment, appropriate use, and adequate protection.
Access to SP's resources and information technology services will be granted through a unique user account and a complex password.
Access to data classified as "confidential" or "restricted" is limited to authorized personnel whose professional responsibilities require it, as determined by the Data Security Policy or management.
SP retains personal information for as long as necessary for the purposes described in this policy. These data will be retained to comply with legal obligations, among other reasons.
Access control applies to all networks, servers, workstations, laptops, mobile devices, web applications, websites, cloud storage, and services.
Incident reports will be produced and processed by the responsible party for personal information and their team, then forwarded to the relevant authorities and involved parties, if applicable.
High-priority incidents discovered will be reported immediately. The responsible party for personal information and their team will be contacted as soon as possible, along with relevant authorities and involved parties.
The person responsible for personal information protection:
Any user who violates this policy is subject to disciplinary sanctions, up to and including termination. Any partner caught in violation may have their business relationship suspended.
| Version | Date of Revision | Author | Description of Changes |
|---|---|---|---|
| 1.0 | 2024-01-08 | S Prévost, Responsible for Personal Information Protection | Initial version |