SinaHealth 的隐私政策
SinaHealth 作者: Sina Medical Clinic
Effective September 7, 2026
SinaHealth is operated by Sina Health Centres Inc. for Sina Medical Clinic. This policy covers the SinaHealth clinic application, its connected browser extension, and patient-facing secure links.
Information we handle and why
We handle patient names, identifiers, dates of birth, contact details, communication preferences, selected health records and documents, messages and attachments, appointment information, and delivery and payment status to support clinic administration, patient communication, document exchange and care coordination. Staff account details, provider identities, session information and audit records support authentication, access control and troubleshooting.
The browser extension works with the configured clinic OSCAR system and SinaHealth service. Authorized staff use it to select patients and carry out clinic workflows. SinaHealth does not ask for or store an OSCAR password.
Google and Gmail connection
When an authorized mailbox owner connects Gmail, SinaHealth receives OAuth authorization tokens and accesses email headers, sender and recipient details, message bodies, attachments, labels and mailbox synchronization information. The Gmail modify permission allows the clinic mailbox features to read and synchronize mail, send replies and update message state, including marking mail read and moving selected messages to Trash when that feature is available. SinaHealth does not receive the Google account password.
Mailbox content is synchronized to the clinic service so authorized clinic staff can handle correspondence and match relevant messages or documents to patient records. Automatic synchronization may continue while the mailbox owner is not using the app. Encrypted refresh tokens allow access tokens to renew without routine sign-in.
SinaHealth's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only for the disclosed clinic mailbox functions and associated security and support. It is not sold, used for advertising or credit decisions, or used to develop, improve or train generalized artificial intelligence or machine-learning models.
Who can receive information
Information is available to authorized clinic personnel and service providers needed to operate the selected function: clinic hosting and security, OSCAR, Google/Gmail and email delivery, SMS delivery, RingCentral fax, telehealth and Stripe payment processing where enabled. Message or document recipients receive the content staff send to them. Clinic fax workflows may use the clinic's Sina-AI document-processing service to extract information and assist filing; this is separate from Gmail synchronization.
We may disclose information with your authorization or when permitted or required by law. Service providers may process information in jurisdictions outside British Columbia or Canada, where local laws may apply. Contact us for information about the providers used for your service.
Security
The service uses HTTPS, staff authentication and role-based access controls. OAuth credentials and selected document artifacts are encrypted at rest, and secure-link tokens are stored as hashes. Patient secure-link workflows use expiry and verification controls. Ordinary email and SMS have inherent privacy risks; avoid including unnecessary sensitive details in them. No electronic service can guarantee absolute security.
Retention, disconnection and deletion
Retention depends on the record and its purpose, including clinical recordkeeping, legal obligations, security and operational needs. Secure-link expiry ends access through that link; it does not necessarily delete the underlying clinical record. Mail already copied to SinaHealth or filed in OSCAR is not automatically erased when Gmail access is disconnected or when the original message is deleted in Gmail.
A clinic administrator can disable mailbox synchronization in SinaHealth. The Google account owner can revoke SinaHealth access through Google account connections. Revocation prevents further authorized Google access but does not remove existing clinic records. To request access, correction or deletion of information held by SinaHealth, contact us. We verify identity and consider the request subject to applicable recordkeeping and legal requirements; some records may need to be retained.
Cookies and technical records
SinaHealth uses session cookies to keep staff signed in and protect application actions. Technical and audit records help operate and secure the service. This policy does not cover independent websites or providers reached through external links.
Questions and changes
Contact us with privacy questions, access or correction requests, deletion requests, or complaints. Please avoid sending health documents in an initial privacy inquiry. We will direct you to an appropriate secure process. Updated policies will be posted at https://sinamed.ca/sinahealth/privacy with a new effective date. You can also contact the Office of the Information and Privacy Commissioner for British Columbia.
Sina Health Centres Inc., Sina Medical Clinic
505 Smithe Street, Vancouver, BC V6B 6H1, Canada
Email: admin@mysina.ca (attention: privacy officer)