Law enforcement requests
Last updated
This document is being reviewed by legal counsel and may be updated.
Our approach
SwyftHer holds health records that people keep for themselves and their clinicians. We treat every request for that data with care. This page explains how we respond to law enforcement agencies, courts, lawyers and other parties who ask for member data.
- We require valid legal process before we disclose any member data.
- We narrow every request to the smallest set of data the law requires.
- We tell the member before we disclose anything, unless the law prohibits it.
- We publish a count of the requests we receive and what we did with each one.
- We never hand over member data on an informal request.
What we require
We disclose member data only in response to valid legal process, such as a production order, search warrant, subpoena or other court order, issued under Canadian law by an authority with the power to issue it.
We do not disclose member data in response to informal requests. A phone call, an email, a letter or an in-person visit that is not backed by valid legal process will not get member data, even if the request comes from a police service or a government agency. Requests from outside Canada must come through a process that is valid in Canada.
How we review a request
- We check that the request is genuine, that it was issued by an authority with the power to issue it, and that it was served properly.
- We check that it identifies a specific account and describes specific information.
- We narrow requests that ask for more than the law requires, and we may object to or challenge a request that is too broad, unclear or not valid.
- When we must disclose, we provide only the information the request legally requires.
Telling the member
Before we disclose any data, we tell the member about the request by email, so they have a chance to seek legal advice. We do not give notice only when the law or a court order prohibits it. If that prohibition ends, we tell the member then.
What we hold, and what we do not
We can only provide what we actually store. The Privacy Policy lists it in full: account details, and the logs, medications, questions, appointments, summaries and care plans a member enters.
- We do not track location.
- We do not store Ask my health questions or answers.
- We do not keep Apple Health export files after an import.
- When a member deletes their account, their account and records are permanently removed, and we cannot recover them.
- SwyftHer is not monitored, so we cannot say whether a member is in danger.
How we record requests
Every request is logged as it arrives, with the date, jurisdiction, requesting agency, type of request, the scope in general terms and the outcome. This log never contains the member’s health data. Only senior staff can see it.
Transparency report
We publish the number of legal requests we receive each year and how many were rejected, narrowed, complied with or still pending. Read the transparency report.
How to send a request
To send legal process to SwyftHer, use the contact form. Include the issuing authority, the legal basis, the specific account and information requested, and a way for us to confirm the request is genuine.
If someone’s life is in immediate danger, call 9-1-1. SwyftHer is not monitored for emergencies.