Skip to content

Security and data protection

Patient data is kept apart between hospitals on the server, access is set by role, and every action is recorded in an audit trail that cannot be deleted. This page describes how each part works, and what has not been done yet.

Each hospital’s data is kept apart

Every record belongs to one hospital, and every database query is scoped to the hospital of the signed-in user on the server. The hospital is decided from the address and the account, never from anything the browser sends.

An address that does not belong to an active hospital is refused rather than shown somebody else’s data.

Who can see what

Access is role-based. Roles and their permissions are data the hospital’s administrator controls, and every action is checked on the server, not only hidden in the menu.

A module a hospital has not bought refuses at the endpoint.

An audit trail with no delete

Who did what, to which record, and when, including attempts that were refused. The trail records field names, never their values, so the log itself does not become a second copy of patient data.

Backups that are tested

Hosted databases are backed up on an hourly schedule, encrypted, and each backup is restored into a scratch database to check that it actually works.

In transit and in the browser

Every page is served over HTTPS with HSTS. Pages carry a content security policy and refuse to be framed by other sites.

Erasure on request

A patient can ask for their data to be erased. Erasure removes what identifies them and keeps only what the law requires a hospital to retain.

What we have not done

The platform has not been through an external certification such as ISO 27001 or SOC 2. If your procurement needs one, tell us; we would rather say so now than in a contract review.

Questions buyers ask

Can another hospital on the platform see our patients?

No. Data is scoped to one hospital on the server for every request, and requests for another hospital’s records are refused and recorded in the audit trail.

How does the platform handle backups?

Hosted databases are backed up hourly, and every backup is restored into a scratch database to prove it can be recovered.

Can we run it on our own servers?

Yes. Hospitals whose policy forbids external hosting can run it on their own infrastructure, where the data never leaves their network.

See it working before you decide

Open the demo clinic and sign in as a doctor, a nurse or the front desk. Nothing to install and no account needed. When you want your own patients in it, the trial runs for thirty days with everyone who works there included.

Security and data protection | QClinicOne