NEESH DENTAL | PRIVACY POLICY
NEESH DENTAL
Privacy Policy
How we collect, use, share and protect patient and website information Last updated: September 3, 2026
Our commitment
Dental care depends on trust. At NEESH Dental, we collect and use personal information only for clear and legitimate purposes connected with patient care, clinic operations, payment, legal obligations and the limited website activities described below. We do not sell or rent patient information, and we do not use information from a patient’s clinical record for targeted advertising. This policy explains, in practical terms, what information we collect, why we need it, who may receive it, how long we keep it and the choices and rights available to you.
- Who and what this policy covers
This policy applies to NEESH Dental, the dentists and other regulated health professionals practising through the clinic, and employees, contractors and service providers acting on their behalf. It covers information handled in the clinic, by telephone, email or text message, through our website at neeshdental.com, through online forms and through approved systems used to provide and administer dental care. Under Saskatchewan’s The Health Information Protection Act (HIPA), the responsible “trustee” may be the treating dentist or another regulated health professional, or the practice, depending on who has custody or control of the record and the circumstances. NEESH Dental’s Privacy Officer coordinates privacy questions and requests for the clinic and will direct a request to the appropriate trustee when necessary. This public policy is supported by more detailed internal policies for access, confidentiality, information security, electronic communications, service providers, incident response, record retention and secure destruction.
- Laws and professional requirements
Personal health information is handled in accordance with Saskatchewan’s The Health Information Protection Act and The Health Information Protection Regulations, 2023, as well as applicable requirements of the College of Dental Surgeons of Saskatchewan. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) may also apply to personal information handled in commercial activities, particularly where information crosses provincial or national borders. Canada’s anti-spam legislation applies to commercial electronic messages. If this policy differs from a mandatory legal requirement, the law governs.
- Information we collect
We limit collection to information that is reasonably necessary for the purposes described in this policy. Depending on your relationship with NEESH Dental, this may include:
- Identity and contact information: name, preferred name, date of birth, address, telephone number, email address, language and communication preferences, and the name and contact information of a parent, guardian, substitute decision-maker, emergency contact or other authorized person.
- Registration information: Saskatchewan health services number or other identifiers when needed for a health service, benefit program or legal requirement.
- Clinical and health information: medical and dental history, current conditions, medications, allergies, symptoms, examination findings, diagnoses, chart notes, treatment recommendations and plans, referrals, prescriptions, consent records, outcomes and follow-up information.
- Dental images and records: X-rays, photographs, intraoral images, digital scans, models, laboratory prescriptions, aligner or implant-planning records and other diagnostic or treatment records.
- Insurance, benefit and billing information: insurer or plan details, member and dependent numbers, estimates, predeterminations, claims, benefit decisions, Canadian Dental Care Plan information, invoices, account history and payment or refund information.
- Communications: appointment requests, messages, consent and opt-out choices, complaints, access or correction requests, and other correspondence with you or an authorized person.
- Website and device information: IP address, browser and device type, operating system, referral page, pages viewed, approximate location derived from an IP address, interactions with the site and information collected through cookies or similar technologies.
- Information you choose to make public: for example, a social-media comment or public review. Public platforms control their own collection and use of that information under their privacy policies. NEESH Dental |
- Where information comes from
We usually collect information directly from you. We may also receive it from:
- a parent, guardian, substitute decision-maker or other person authorized to act for you;
- another dentist, physician, pharmacist, specialist, hospital, diagnostic service or health-care provider involved in your care;
- a dental laboratory, imaging service or digital treatment-planning provider;
- an insurer, benefit administrator, employer-sponsored plan or government benefit program, including the Canadian Dental Care Plan;
- eHealth Saskatchewan, the Saskatchewan Health Authority or another trustee, where access or disclosure is authorized by law; and
- our website, communications, payment and technology service providers when you use the relevant service.
- Why we collect and use information
We collect and use information for purposes that include:
- confirming identity, opening and maintaining an accurate dental record, and understanding your health, concerns, priorities and communication needs;
- assessing, diagnosing, planning, explaining, providing and following up on dental care;
- coordinating care with other providers, arranging referrals, prescriptions, imaging, laboratory work, implants, aligners, oral appliances and related services;
- booking appointments, managing wait-lists, sending confirmations and reminders, recalling patients for recommended care and contacting patients about treatment or follow-up;
- preparing estimates and predeterminations, submitting and reconciling insurance or benefit claims, processing payments and refunds, administering patient accounts and collecting overdue accounts through lawful means;
- responding to questions, concerns, complaints and requests to access, correct or transfer records;
- quality assurance, professional review, staff training, audit, risk management, infection prevention, patient safety and clinic administration, using the minimum information reasonably necessary;
- meeting professional, tax, accounting, public-health, insurance, regulatory and legal obligations, and establishing, exercising or defending legal claims;
- protecting patients, staff, systems and property; detecting or investigating fraud, misuse, security incidents or privacy breaches;
- producing de-identified information for internal planning, service evaluation and statistics where individuals cannot reasonably be identified; NEESH
- operating, securing and improving our website and understanding how it is used; and
- sending newsletters, clinic news or promotional messages only where permitted by law and subject to your communication choices. We do not use identifiable personal health information for research unless the use is authorized by law and all required consent, ethics and privacy safeguards are in place.
- Consent and your choices
Where consent is required, it must relate to the purpose, be informed and voluntary, and be given without misrepresentation or coercion. Consent may be express or implied where the law permits. When you ask us to provide dental care, the law may permit us to use or share information for the purpose for which it was collected and for purposes reasonably connected with arranging, providing, continuing or supporting that care. We generally seek express consent for uses that would not reasonably be expected as part of care or clinic administration, including:
- using identifiable photographs, video, testimonials or treatment results for education, publication, social media or promotion beyond your direct care;
- sending optional promotional electronic messages where express consent is required;
- sharing information with a person who is not involved in your care or account and is not otherwise authorized by law; and
- using information for a materially different purpose from the one originally explained. You may withdraw consent at any time by contacting us. Withdrawal applies going forward and cannot undo a use or disclosure already lawfully made. It also does not prevent us from keeping records or collecting, using or disclosing information where required or permitted by law. If information is reasonably necessary to provide safe care, process a requested claim or meet a legal obligation, limiting that information may affect what we can do for you. We will explain the practical effect where possible. We will not make optional marketing consent a condition of receiving dental care. Children and individuals represented by another person A parent, guardian, substitute decision-maker or other legally authorized person may exercise privacy rights where permitted by law. Capacity is considered in relation to the person and decision; a capable young person may have privacy rights regarding their own health information. We take reasonable steps to verify authority and identity and, where appropriate, involve the patient directly.
- When we share information
We disclose only what is reasonably necessary on a need-to-know basis, with consent or as otherwise authorized by law. Depending on the purpose, recipients may include:
- dentists, hygienists, dental assistants, administrative team members and contractors working with NEESH Dental who need the information to perform their duties;
- dentists, physicians, specialists, pharmacists, hospitals, emergency services, dental laboratories, imaging providers and other people involved in arranging or providing your care;
- insurers, benefit administrators, government benefit programs and electronic claim networks when you ask us to seek coverage or payment, or where disclosure is otherwise authorized;
- a family member, caregiver or person close to you with your consent, at your direction, or where HIPA permits the disclosure and you have not expressed a contrary instruction;
- technology and information-management service providers described in section 8;
- professional advisers, auditors, insurers, payment processors or collection agencies, limited to what they reasonably require and subject to applicable confidentiality and legal safeguards;
- the College of Dental Surgeons of Saskatchewan, the Saskatchewan Information and Privacy Commissioner, the Office of the Privacy Commissioner of Canada, eHealth Saskatchewan, public-health or other government authorities where required or authorized; and
- law enforcement, a court, a tribunal or another person where a subpoena, warrant, court order or law authorizes or requires disclosure, or where the law permits disclosure to address a serious and imminent safety concern. If the practice is sold, reorganized, closed or transferred, records may be reviewed or transferred as part of an appropriately safeguarded professional-practice transition, subject to HIPA, professional requirements and any required notice. Patient information is not treated as an unrestricted marketing asset. We do not sell or rent patient lists or personal health information to data brokers, advertisers or unrelated third parties.
- Service providers and processing outside Saskatchewan
NEESH Dental uses service providers for practice management and electronic records, appointment confirmation and recall, electronic claims, digital X-rays and imaging, intraoral scanning and treatment planning, dental laboratory work, payment processing, telephone, email and fax, secure file transfer, data storage and backup, IT and cybersecurity support, website hosting and forms, analytics, record storage and secure destruction. These providers receive only the information reasonably needed for the service. Where a provider qualifies as an information management service provider under HIPA, we require a written agreement with NEESH Dental addressing permitted services, access, use, disclosure, security, breach notification, retention and destruction. Providers may not use patient information for their own unrelated purposes simply because they process it for us. Some digital dentistry, communications, website or cloud-service providers may store or process information outside Saskatchewan or outside Canada. In that situation, information may be subject to the laws and lawful access processes of the place where it is processed. We assess the sensitivity of the information, the purpose, available safeguards and contractual protections before using such a provider. Contact the Privacy Officer if you would like more information about service providers relevant to your information.
- Appointment reminders, email, text messages and online forms
We may contact you by telephone, voicemail, email or text message for appointment confirmations, reminders, recall, treatment follow-up, account matters or a response to your inquiry. We try to keep routine messages brief and limit the amount of health information they contain. Please tell us if you prefer that we avoid a particular channel, number or address, or if we should not leave voicemail. We will make reasonable efforts to follow that direction, although we may still use a channel where legally required or reasonably necessary for safety. Ordinary email and text messaging are convenient but are not always secure. Do not use the website contact form, ordinary email or social media for a dental emergency or for highly sensitive information. Call the clinic at 306-665-8414. If a message contains information that warrants stronger protection, we may verify your identity or ask to continue through a more secure method. The website appointment form asks for your name, email address, telephone number, preferred contact method and appointment details. Information entered into the form is used to respond to the request and may become part of the dental record where it relates to care. Please provide only what is reasonably necessary at that stage. You may opt out of optional promotional messages at any time by using the unsubscribe method in the message or contacting us. An opt-out does not stop service messages that are reasonably necessary for appointments, treatment, safety, billing or another existing relationship.
- Website cookies, analytics and external links
Our website may use cookies and similar technologies to operate correctly, remember choices, protect forms, measure website use and, where enabled, understand the effectiveness of advertising. These technologies may collect device and usage information such as an IP address, browser type, pages viewed, referral source and interactions with the site. The NEESH Dental website currently uses Google Tag Manager to manage website tags. Depending on the tags configured and your cookie choices, related analytics or advertising providers may collect website and device information. NEESH Dental does not intentionally send the contents of appointment request forms or information from dental records to analytics or advertising providers. We use non-essential cookies only where permitted by law and with consent where required. You may manage cookies through the website’s cookie controls, where provided, and through your browser settings; blocking some cookies may affect website functions. Our site contains links or embedded services operated by others, such as Google Maps, social-media platforms and a third-party patient-financing provider. If you follow a link or use an external service, that organization’s privacy policy applies to its collection and handling of information. A link from our website does not give NEESH Dental control over the external provider’s practices.
- How we protect information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity, amount, format and location of the information. These safeguards include:
- privacy and security policies, orientation and ongoing training, confidentiality pledges, role-based responsibilities, service-provider agreements, incident procedures and periodic review;
- access limited to people who need information for their work, individual user credentials, password controls, audit capability where supported, encryption where appropriate and available, firewalls, malware protection, software updates, secure backups and recovery measures;
- reasonable controls over remote access, portable devices, email, text, fax and transfer of records;
- secured clinic premises, restricted work areas, attention to screen and conversation privacy, locked storage for paper records and secure disposal containers; and
- review of suspected inappropriate access and consequences for employees or contractors who breach confidentiality. No system or method of transmission can be guaranteed completely secure. We therefore review safeguards as technology, threats, legal requirements and clinic systems change.
- Retention and secure destruction
NEESH Dental retains personal health information for at least 10 years after the last episode of care, or until the patient reaches age 20 if the patient was a minor, whichever period is longer. We may keep particular records longer where reasonably required for continuing care, professional or legal obligations, an audit, investigation, complaint, claim or other legitimate purpose. Other personal information is kept only as long as reasonably necessary for the purpose and any applicable tax, accounting, employment, contractual, limitation-period or legal requirement. Information scheduled for destruction is disposed of in a way that protects privacy. Paper is securely shredded or otherwise irreversibly destroyed; electronic information and storage media are securely deleted or destroyed using appropriate methods. Required destruction records are maintained. Information in system backups may remain until the backup is securely overwritten or retired under the applicable schedule. A request to delete information does not override a legal or professional duty to retain the dental record.
- Your privacy rights
Access to your record
You may ask to examine or receive a copy of personal health information about you in the custody or control of a trustee. A formal access request should be in writing, provide enough detail to identify the requested information and include satisfactory proof of identity and, where applicable, authority to act for another person. You may designate another person in writing to exercise your rights. We will respond to a written access request within 30 days, unless HIPA permits an extension of up to 30 additional days. Access may be limited only where the law permits; if part of a record can reasonably be separated and released, we will provide that part. We may charge a reasonable fee that does not exceed the amount permitted by law and will explain the fee in advance where appropriate. Original records normally remain with the responsible trustee; a copy is provided. A record will not be withheld solely because an account is outstanding.
Correction or amendment
If you believe factual personal health information is inaccurate or incomplete, you may request an amendment in writing and provide supporting information. Within 30 days, we will advise you in writing that the amendment has been made or that a notation of the requested amendment has been added. Clinical observations or opinions made in good faith are not generally replaced simply because there is disagreement, but your requested notation may be added as provided by law.
Information about disclosures and privacy choices
You may ask about anticipated uses and disclosures, certain disclosures made without consent, your communication preferences, the effect of withdrawing consent and the service providers relevant to your information. Some statutory exceptions apply.
- Privacy incidents and breaches
If we learn of a suspected loss, inappropriate access, unauthorized collection, use or disclosure, or other privacy or security incident, we will take reasonable steps to contain it, preserve relevant evidence, investigate what happened, assess risk, recover or secure information where possible, reduce potential harm and improve safeguards. We document incidents and notify affected individuals, regulators or others when required by applicable law or when notification is otherwise appropriate in the circumstances. If you believe information has been sent to the wrong person, lost, accessed inappropriately or otherwise mishandled, please contact the Privacy Officer promptly so we can respond.
- Questions, requests or complaints
Please contact us first. We would like the opportunity to understand and address your concern. Privacy Officer: NEESH Dental Address: 100-402 21st Street East, Saskatoon, Saskatchewan S7K 0C3 Telephone: 306-665-8414 Email: [email protected] If a concern about personal health information is not resolved, you may contact the Saskatchewan Information and Privacy Commissioner at 1-877-748-2298 or [email protected], or visit oipc.sk.ca. Where PIPEDA applies, you may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
- Changes to this policy
We review this policy at least annually and when there is a material change in law, technology, service providers or our information practices. The current version will be posted on our website with its last-updated date. Material changes will be brought to attention in a reasonable manner. Previous versions may be requested from the Privacy Officer.
NEESH Dental | September 2026