Data Privacy and Security
OnSPARK prioritizes the privacy and security of our homes’ long-term care data. Operating with privacy, security, and sector-led governance at our core, all data use in the Portal is secure, compliant, and clearly aligned with benefiting the sector.
Our privacy and security standards guaranteed to LTC homes
Trustworthy data stewardship
Secure encrypted infrastructure and security
Ethical Data-Driven Decision-Making
-
Deidentified Resident health data
Facility-level data
Research and analytical datasets
-
Supporting quality improvement initiatives in long-term care
Generating insights to improve resident care outcomes
Supporting public health and policy development
Assisting LTC operators in planning, staffing, and operational decision-making
-
Commercial sale or marketing of any data
Attempts to re-identify de-identified or pseudonymized data
Data linkage not explicitly approved by a Research Ethics Board and data governance authority
Use of data outside the scope of approved agreements and purposes
OnSPARK Data
-
Dedicated advisory committees, which includes sector partners, LTC homes, and experts in ethics, cybersecurity, law and health data governance, guide OnSPARK’s policies and support:
Reviewing and approving all data access requests
Ensuring compliance with PHIPA & international standards
Conducting regular security audits & risk assessments
Upholding ethical data usage in research & quality improvement
Data Governance
-
Committed to full compliance with the Personal Health Information Protection Act (PHIPA, 2004) and all applicable privacy legislation and institutional policies
OnSPARK homes retain full ownership and authority over their data at all times
Data is de-identified at source and encrypted end-to-end within secure infrastructure
Formal Research Ethics Board and governance approvals are required prior to any data access or linkage.
-
De-Identification & anonymization to remove all personally identifiable information (PII) from data before transfer and analysis
Limit access to secure datasets to authorized individuals under strict governance
Secure data linkages with secure servers
Only collect and use the minimum data necessary to support LTC quality improvement and research
-
Encrypted data are transferred electronically through secure connections from approved source systems
Securely hosted and stored data in McMaster University's Tier 4 secure institutional server environment
Role-Based Access Control (RBAC) to ensure data can only be accessed based on an individual's approved role and responsibilities
Continuously conduct Privacy Impact Assessments (PIAs) and Threat and Risk Assessments (TRAs) to mitigate cyber security risks
-
When data is stored, it is locked with AES-256 encryption through AWS KMS, a highly secure encryption system.
When data travels across public networks, it's protected using TLS 1.3, a modern encryption standard.
All encryption work is handled by AWS's secure services. Canadian data residency is maintained through the use of our ca-central-1 (Montreal, Canada) AWS infrastructure. AWS KMS also meets FIPS 140-3 Level 3, a strict government security standard.
Privacy and Security
Our Policies
Privacy and security are at the forefront of everything we do. OnSPARK protects your data in two ways.

