Skip to content
Security & compliance

Security and compliance your clinic can trust

Protecting client data isn’t a feature — it’s the foundation of everything we build. Healthcare data demands the highest standards of security and compliance, and we hold ourselves to those standards every day. Below you’ll find an overview of the technical and organisational controls we have in place to keep your clinic’s information safe.

MediSync encrypts clinic data with TLS 1.2 or higher in transit and AES-256 at rest, separates every clinic's records with database-level row security, keeps an immutable audit log for five years, and signs a Data Processing Agreement with every customer — with a Business Associate Agreement available on request for clinics with HIPAA obligations.

Encryption everywhere

All data in transit is protected with TLS 1.2 or higher. All data at rest — including database volumes, backups, and file storage — is encrypted with AES-256. Encryption keys are managed through a dedicated key management service with automatic rotation. We never store credentials or secrets in plaintext.

Role-based access control

Every user is assigned a role that limits their access to exactly what their job requires. Administrators can create custom roles with fine-grained permissions down to individual features. All privileged access — including internal MediSync staff access to production systems — requires multi-factor authentication and is logged.

Full audit trails

Every sensitive action within the platform — creating or modifying a client record, changing permissions, accessing billing information — is captured in an immutable audit log. Logs are retained for 5 years and available for export to support your own compliance obligations.

Backups and disaster recovery

Your data is backed up automatically every hour with daily snapshots retained for 30 days and monthly snapshots retained for 12 months. Backups are encrypted and stored in a geographically separate region from the primary data. We test restoration procedures regularly so that recovery time objectives are met in the event of a failure.

Strict tenant isolation

Each clinic’s data is partitioned at the database level using row-level security policies. This means it is architecturally impossible for one tenant’s queries to access another tenant’s data, even in the event of an application-layer bug. We conduct regular penetration tests specifically targeting the isolation boundary.

Reliability and uptime

MediSync is deployed across multiple availability zones with automatic failover. Our infrastructure is monitored 24/7 with automated alerting. We maintain an uptime SLA of 99.9% for paid plans. Planned maintenance is scheduled outside peak clinic hours and announced at least 48 hours in advance.

Regulatory compliance

MediSync is designed to help you meet your obligations under GDPR (EU/UK), HIPAA (US), and regional healthcare privacy regulations. We sign Data Processing Agreements (DPAs) with all customers and maintain a current sub-processor list, and a Business Associate Agreement (BAA) is available on request for customers with HIPAA obligations. Our controls are aligned with ISO 27001 principles and we pursue formal certification on an ongoing basis.

Vulnerability management

We run automated dependency scanning on every build, perform regular internal security reviews, and engage independent security firms for annual penetration tests. Critical vulnerabilities are patched within 24 hours; high-severity issues are resolved within 7 days. We operate a responsible disclosure programme — report suspected vulnerabilities to [email protected].

Incident response

In the event of a confirmed security incident affecting your data, we will notify affected organisations within 72 hours as required by GDPR, and as soon as reasonably practicable under HIPAA and other applicable frameworks. Our incident response plan is tested annually through tabletop exercises. A dedicated security team is on call around the clock.