Secure access
Use individual staff accounts, strong passwords and role-based access where those controls are implemented.
This page intentionally avoids unverified compliance claims. Final security statements must match the production system and hosting setup.
Use individual staff accounts, strong passwords and role-based access where those controls are implemented.
The production website and application must use HTTPS with a valid TLS certificate.
Define automated database and file backup schedules, retention periods and a tested restore process.
The privacy policy and service agreement should explain who controls clinic and patient information.
Log sensitive account activity where technically supported and review unusual access.
Do not publish HIPAA, ISO or GDPR compliance claims unless the product has been properly assessed and documented.