MEDI | Clinic privacy and workflow review Use this discussion checklist with your privacy lead and MEDI team. It is not a certification or a completed privacy impact assessment. SERVICE SCOPE 1. Which calls, messages and patient requests are in scope? 2. Which actions can MEDI perform in this EMR and which require staff review? 3. How are patient identity, consent and caregiver requests handled? INFORMATION HANDLING 4. Which information is collected, processed and stored at each step? 5. Where does each service process and store information? 6. Which service providers are involved, and which contractual terms apply? 7. Who can access recordings, transcripts, messages and patient summaries? 8. What access records are available for clinic review? 9. What retention, export and deletion settings apply to each information type? OPERATIONAL BOUNDARIES 10. How are clinical questions, sensitive requests and urgent concerns routed? 11. What happens after hours or when the designated staff member is unavailable? 12. How does the clinic identify and follow up on an incomplete action or connection failure? 13. Who owns privacy or security incident communication and the response process? DOCUMENTATION 14. Which PIA support materials apply to our province and configuration? 15. What is the current status and scope of third-party security assessments? 16. Which items need confirmation before the workflow is activated? Record the answer, supporting document, owner and follow-up date for each open item. To arrange a review: hello@talktomedi.com Do not include patient information in your initial enquiry.