Security your clinic can trust
Protecting client data isn’t a feature — it’s the foundation of everything we build. Healthcare data demands the highest standards of security and compliance, and we hold ourselves to those standards every day. Below you’ll find an overview of the technical and organisational controls we have in place to keep your clinic’s information safe.
Encryption everywhere
All data in transit is protected with TLS 1.2 or higher. All data at rest — including database volumes, backups, and file storage — is encrypted with AES-256. Encryption keys are managed through a dedicated key management service with automatic rotation. We never store credentials or secrets in plaintext.
Role-based access control
Every user is assigned a role that limits their access to exactly what their job requires. Administrators can create custom roles with fine-grained permissions down to individual features. All privileged access — including internal MediSync staff access to production systems — requires multi-factor authentication and is logged.
Full audit trails
Every sensitive action within the platform — creating or modifying a client record, changing permissions, accessing billing information — is captured in an immutable audit log. Logs are tamper-evident, retained for at least 7 years, and available for export to support your own compliance obligations.
Backups and disaster recovery
Your data is backed up automatically every hour with daily snapshots retained for 30 days and monthly snapshots retained for 12 months. Backups are encrypted and stored in a geographically separate region from the primary data. We test restoration procedures regularly so that recovery time objectives are met in the event of a failure.
Strict tenant isolation
Each clinic’s data is partitioned at the database level using row-level security policies. This means it is architecturally impossible for one tenant’s queries to access another tenant’s data, even in the event of an application-layer bug. We conduct regular penetration tests specifically targeting the isolation boundary.
Reliability and uptime
MediSync is deployed across multiple availability zones with automatic failover. Our infrastructure is monitored 24/7 with automated alerting. We publish a real-time status page at status.medisync.com and maintain an uptime SLA of 99.9% for paid plans. Planned maintenance is scheduled outside peak clinic hours and announced at least 48 hours in advance.
Regulatory compliance
MediSync is designed to help you meet your obligations under GDPR (EU/UK), HIPAA (US), and regional healthcare privacy regulations. We sign Data Processing Agreements (DPAs) with all customers and maintain a current sub-processor list. Our controls are aligned with ISO 27001 principles and we pursue formal certification on an ongoing basis.
Vulnerability management
We run automated dependency scanning on every build, perform regular internal security reviews, and engage independent security firms for annual penetration tests. Critical vulnerabilities are patched within 24 hours; high-severity issues are resolved within 7 days. We operate a responsible disclosure programme — see our security page for the reporting address.
Incident response
In the event of a confirmed security incident affecting your data, we will notify affected organisations within 72 hours as required by GDPR, and as soon as reasonably practicable under HIPAA and other applicable frameworks. Our incident response plan is tested annually through tabletop exercises. A dedicated security team is on call around the clock.