What is changing in Colib to meet the new Quebec standards ?

Created by Thibault Breboin, Modified on Thu, 10 Sep at 9:20 AM by Thibault Breboin

These changes will be available during the week of 14 September 2026.

To meet the new standards set by the Quebec government for digital health solutions (mandatory by 2027), a number of things are changing in Colib and in the client portal. These standards come from the TGV (Trousse globale de vérification), the verification framework of Santé Québec, which governs privacy, security, artificial intelligence and accessibility for any software used by Quebec's public health network.

Several of these standards are stricter than what most practice management software applies today, so you will see new rules and new features appear in your day-to-day work. This article lists each of them, who is affected, and what you may need to do.

Good to know. These changes are required by the framework, not optional improvements we chose to make. Unless stated otherwise they apply to every clinic, and some are mandatory only for clinics located in Quebec.

In this article

  1. Two-factor authentication becomes mandatory for Quebec clinics
  2. Account lockout after five failed attempts
  3. Password rules
  4. Alerts when a new device signs in
  5. Automatic sign-out after inactivity
  6. Acceptance of the terms of use is recorded
  7. A complete journal of who did what
  8. Clients can see their own access history
  9. Transparency on artificial intelligence
  10. Accessibility

1. Two-factor authentication becomes mandatory for Quebec clinics

Quebec clinics · mandatory

What changes. As soon as a clinic's address is in Quebec, two-factor authentication (2FA) is required for every practitioner and every staff member of the clinic, and for every client using the client portal. At each sign-in, a six-digit code sent by email must be entered in addition to the password. The code is valid for ten minutes. The option cannot be turned off from the profile; a notice explains why.

Who is affected. Clinics whose address is in Quebec, or one of whose clinics is in Quebec, their team, and their clients. Clinics located elsewhere keep 2FA optional, and we recommend enabling it. Colib staff accounts are also under mandatory 2FA.

Sign in with Google. For the time being, the "Continue with Google" button is not available for accounts with two-factor authentication, and therefore not for practitioners of Quebec clinics. Google sign-in does not go through Colib's email code, so keeping both would defeat the rule. If you used to sign in with Google, use your email address and your Colib password instead, using "Forgot password" once if you never set one. We may bring Google sign-in back with a second factor later.

What you need to do. Nothing, except make sure the email address on each account is current, since the code is sent there. Let your clients know that they will be asked for a code when they sign in to the portal.

2. Account lockout after five failed attempts

What changes. After five wrong passwords in a row, the account is locked for 30 minutes. The account holder receives an email with the date and the network address of the last attempt. During the lockout, sign-in is refused even with the correct password, and no two-factor code is sent.

What you need to do. If you receive this email without having tried to sign in, change your password and contact support@colib.io. The lock lifts by itself after 30 minutes, or immediately when you reset your password through "Forgot password", since the reset link proves that you control the email address.

3. Password rules

What changes. A new password cannot be one of the last five you used, and that includes the one you are using today. This applies when you change your password from your profile, when you reset it, and when a client sets or resets their portal password.

Passwords themselves are never stored: only the same one-way hashes that already protect your current password are kept for comparison, and they are erased when an account is deleted. The existing rules do not change: at least 12 characters, four kinds of characters, and passwords known to have been leaked elsewhere are refused.

4. Alerts when a new device signs in

What changes. Colib will remember the devices, meaning the browser and the operating system, and the network addresses used by each account. A sign-in from a device we have never seen triggers an email to the account holder with the date, the device and the address. This applies to practitioners on Colib and to clients on the portal. A change of network address alone does not trigger an email.

Devices unused for one year are forgotten automatically, addresses are stored encrypted, and everything is erased when an account is deleted.

What you need to do. Expect an email the first time you sign in from a new computer, phone or browser. If you do not recognize a sign-in, change your password immediately.

5. Automatic sign-out after inactivity

What changes. Each clinic chooses its inactivity delay under Settings > Security > Session: 15, 30, 60 or 120 minutes, 60 by default. Two minutes before the delay is reached, a banner offers to stay connected; otherwise the session ends, on the server side as well, so a screen left open cannot expose a file. On the client portal, clients are signed out after 30 minutes of inactivity.

What you need to do. Pick the delay that suits your practice. A shared reception computer calls for a short delay; a practitioner working alone in their office may prefer a longer one.

6. Acceptance of the terms of use is recorded

What changes. When a clinic signs up, when a team member accepts an invitation, and when a client creates their portal account, they must tick a box confirming that they have read the Terms of Service and the Privacy Policy. The date of acceptance is kept with the account. For accounts created before this change, the creation date is used.

7. A complete journal of who did what

What changes. The security journal under Settings > Security will record every sign-in, failed attempt, two-factor code, lockout and sign-out, in addition to the existing record of who viewed, created, modified, downloaded or deleted client data.

A new selector, Records of: Practitioner / Client (client portal), shows a second journal: what your clients did on the portal, such as signing in, viewing or downloading a document, paying an invoice, sending a message or confirming an appointment. Each line links to the client file or the appointment concerned. Both journals can be filtered, searched and exported to Excel, and are kept for 18 months.

Access review. Under Settings > Team, each member will show their last sign-in, members with no sign-in for 90 days are highlighted, and the list can be exported to Excel. Review it regularly, remove the accounts of people who no longer work with you, and keep the export as evidence of your access review.

Who sees what. A practitioner only sees the lines concerning the clients they are allowed to see, following the same permissions as the rest of Colib. A client of several clinics generates one line per clinic, and each clinic only sees its own.

The Colib team is logged too. When a member of our support team acts on your clinic from our administration area, that action is recorded in a separate journal, with the account used, what was touched and when. Interventions performed inside your clinic already appear in your own journal.

8. Clients can see their own access history

What changes. The client portal dashboard has a new tab, My access log, listing every sign-in and every action a client performed on their data during the last 18 months, with the date, the device and the network address. The portal's Security page is also rewritten in plain language for clients: how their information is protected, what they can do, and who to contact.

Download all my data. From the same tab, a client can download a ZIP file containing everything they can see on the portal: their profile, their access log, and for each clinic their appointments, invoices in PDF, documents, completed forms in PDF, notes shared with them in PDF and conversations. Nothing that is not already visible to them on the portal is included, so a document or a note you have not shared stays out of the export. One export every ten minutes; each export is recorded in your clinic's journal.

What you need to do. Nothing. If a client asks who accessed their file, the information they can see concerns their own actions; accesses by your team are in your clinic's journal. If a client asks for a copy of their data, point them to the "Download all my data" button rather than assembling it by hand.

9. Transparency on artificial intelligence

What changes. A note drafted with Colib's AI carries a visible marker in the client file, together with the model that produced it. The model name and the generation date are also written at the end of the draft itself, and the model actually used is recorded with the note. A link lets you report an inaccurate result in one click; reports and every AI decision, meaning a draft accepted, modified or rejected, are kept in the clinic's journal.

The audio used to draft a note is deleted as soon as the note has been generated. If your clinic has turned on session recording, the recording is kept as a private document in the client's record, visible to the practitioner only, and stays there like any other document of the record. If your clinic has turned on transcript keeping, the transcript is stored encrypted in the client's record. The text sent to the model is never kept in our technical logs. Our AI policy names the model and where it runs.

For clinics located in Quebec

Two additional rules apply. First, the AI processing itself stays in Canada: notes are drafted by a Mistral model hosted on Amazon Bedrock in the Canada region and never leave the country. Mistral AI is a French company whose models have a very strong command of the French language, which suits notes written in French.

Second, before joining a telehealth session that will produce an AI-drafted note, the client must tick a consent box on the session's welcome page. Without it, the client cannot enter the session. The consent is recorded with its date, and you see "AI transcription consent given on …" on the session. If a client does not wish to be transcribed, arrange the session without AI note generation.

Clinics outside Quebec keep Claude Sonnet 4.6: the computation may run in Canada or in the United States, in memory and for the few seconds it lasts. Nothing is stored, logged or kept there, and your records stay in Canada at all times.

Your settings will be enforced everywhere. The rules you set under Settings > Notes, meaning which practitioners and which appointment types may use AI, and a client's refusal recorded in their file, will block AI note generation on every path: telehealth, in-person recording and the rewriting assistant. Until this release only telehealth checked them.

Recording a session in person. Before you can start the recording, you must tick a box confirming that you informed the client and that they agreed to the session being recorded and transcribed. There is no screen in front of the client in that situation, so your confirmation is what we record, with its date and your name, on the appointment. If AI is not allowed for that client, that practitioner or that appointment type, the recorder is replaced by the reason why.

What you need to do. Keep reviewing every AI draft before saving it, as you already do; the marker does not change your responsibility for the note. In Quebec, tell your clients in advance that telehealth sessions with AI notes are transcribed, so that the consent box does not come as a surprise.

10. Accessibility

Colib and the client portal aim for WCAG 2.2 level AA. Already in place: a "skip to main content" link, a visible focus ring for keyboard navigation, colour contrasts checked pair by pair across both applications, and a session-expiry warning that meets the timing rule. Keyboard and screen-reader testing is under way. If you use assistive technology and something gets in your way, tell us at support@colib.io.

Questions about these changes? Write to support@colib.io. We will keep this article up to date as the changes are released.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article