Clinic data security overview

Security

HelloClinic uses a combination of technical, organizational, and operational measures to help protect data handled through the Service. This page is a general overview only. Measures may change as the Service evolves and do not constitute a guarantee that the Service will be uninterrupted, error-free, or free from every security risk.

Scope and Service Boundaries

The security measures available to you depend on the Service, feature, environment, plan, current configuration, and applicable written agreement. The Terms of Service, Privacy Policy, order, SOW, service agreement, SLA, and documented customer instructions govern where applicable.

Customer-Controlled Data

The clinic customer generally decides what data to upload and how its authorized users use the Service. The customer remains responsible for its notices, permissions, lawful instructions, data accuracy, user administration, and any responsibilities assigned by the applicable agreement.

Third-Party Providers

We may use cloud, network, storage, communications, support, payment, analytics, and security providers to operate the Service. Actual providers, processing locations, and controls may vary by configuration and may be described in the Privacy Policy or customer agreement.

No Elimination of Risk

No technical or organizational measure can eliminate every security, availability, or data-loss risk. This page is not a warranty, certification, service-level commitment, or substitute for the applicable written agreement.

Infrastructure and Network Protection

We may use Google Cloud, Cloudflare, and other providers or controls that support hosting, network protection, availability, and abuse prevention. The specific services and controls in use may change over time.

Cloud Infrastructure

Underlying cloud providers may apply physical, environmental, platform, access, patching, monitoring, and resilience controls to their services. Provider certifications or standards apply to the relevant provider scope and should not be read as a certification of HelloClinic unless expressly stated in writing.

Network Protection

Depending on the endpoint and configuration, we may use traffic filtering, rate limiting, DDoS mitigation, web application firewall, and related controls to reduce common attack risks. These controls do not prevent every attack or guarantee uninterrupted availability.

Secure Transmission

The Service is designed to use Transport Layer Security (TLS) for supported connections between clients and Service endpoints. Actual protocol negotiation depends on the endpoint, client, and current configuration.

Data Protection

We use technical and organizational measures intended to help protect data at rest and in transit. The exact encryption, key-management, retention, deletion, and backup arrangements may vary by data type, environment, and agreement.

Data at Rest

Storage encryption and related safeguards may be provided by underlying infrastructure, application controls, or both, where configured. Encryption reduces risk but does not make data immune to unauthorized access or other loss scenarios.

Data in Transit

Supported network communications are protected using transport encryption appropriate to the endpoint and configuration.

Retention and Deletion

Retention, export, deletion, and routine backup rotation are governed by the Privacy Policy, Terms of Service, and applicable customer agreement. Data in routine backups may remain until overwritten in the ordinary backup cycle, and the Service should not be treated as the customer's only backup.

Access Control and Account Security

Access is managed according to role, operational need, and available Service features. Customers also control important parts of their own account security.

Need-to-Know Access

We aim to limit internal access to information needed for an authorized operational purpose and may record or review access where appropriate to the Service and applicable requirements.

Roles and Permissions

Where supported, clinic administrators can configure roles or permissions for authorized users. Customers are responsible for reviewing those settings and removing or changing access when staff, roles, or working arrangements change.

Credentials and MFA

Customers and users should use unique passwords, protect credentials, and enable multi-factor authentication where available. Do not share accounts or credentials.

Secure Development and Operations

We incorporate security considerations into development, maintenance, monitoring, and support activities according to the nature of the Service and the risks involved.

Development and Testing

Activities may include code review, testing, dependency and vulnerability management, logging, monitoring, and other controls appropriate to the relevant change or risk. We do not promise that every defect or vulnerability will be identified before it affects the Service.

Vulnerability Reports

We may assess reports we receive, request information needed to investigate, and take remedial action based on severity, evidence, impact, and available resources. Unless a written agreement says otherwise, no fixed response, remediation, or disclosure timeline is promised.

Security Incidents

If we confirm a security incident involving Customer Data, we will notify the relevant customer without undue delay where notification is required by applicable law or the applicable agreement, or where the incident is reasonably likely to create a material risk. Updates may be provided as the investigation develops.

Customer Responsibilities

Security is shared. Customers remain responsible for the parts of the environment, people, data, and processes under their control.

User and Device Security

Manage user access, passwords, MFA, devices, browsers, networks, integrations, and connected services used to access the Service.

Data Governance

Collect, notify, authorize, use, disclose, and maintain Customer Data lawfully and accurately, and provide instructions that are appropriate for the Service.

Continuity and Reporting

Maintain any backups, exports, internal procedures, and business-continuity arrangements required for your operations, and notify us promptly if you suspect credential misuse, unauthorized access, or a security issue.

For questions about security measures or the documents that apply to your Service, please contact us. Do not include patient data, passwords, API keys, or other sensitive information in a general enquiry.

Contact us