Where the data sits, and who may see it
A health record is the most sensitive thing a facility holds. The platform records who read it, who changed it and under what authority, and keeps it in the region the facility is licensed in.
Reading a record is an event
Most systems record changes. A health record needs the reads as well, because the question after an incident is who looked, not only who edited. Access, disclosure and consent are recorded against the patient, and the record of them outlives the session that produced it.
The platform reports evidence status and gaps. A data protection officer signs off, and no software makes anyone compliant.
Controls
- Role based access, per facility
- Permissions are granted against a role at a facility rather than against a person globally, so a clinician working at two sites carries two sets.
- Break-glass with a reason
- An emergency override to view a record outside normal permissions requires a justification, notifies, and is reviewed afterwards. The override is the exception it is designed to be, not a second way in.
- Residency set at the tenancy
- Where records are stored and processed is a facility level setting, so a group in two countries runs two residency regimes in one deployment.
- Consent recorded, not assumed
- Lawful basis, consent and withdrawal are recorded against the patient with the time and the channel, which is what a data subject request is answered from.
Privacy regimes we build against
What each regime asks for, and what the platform records against it. Read from the library, so the list follows it.
Send us your security questionnaire
We will answer it against the controls above rather than against a template.