Security & privacy
Your patients' data,
treated like it's yours.
Clinitricks was designed around the DPDP Act (India) and HIPAA (US) from day one — not bolted on after. Sensitive fields are encrypted, every action is logged, access is role-based, and you can walk away with all your data at any time.
We say "designed for", never "certified for". A formal SOC 2 audit is on our roadmap — until it's done, we won't display a badge we haven't earned.
How we protect it
A DPDP- and HIPAA-aligned framework, in plain terms.
Encryption at rest
Sensitive patient fields — phone, email, health IDs, allergies and more — are encrypted with AES-256 in the database, not stored as plain text. In transit, everything moves over 256-bit TLS.
Tamper-evident audit trail
Every create, view, edit and delete on patient data is written to an append-only audit log. If something changes, there's a record of who, what and when — designed so the trail can't be quietly rewritten.
Role-based access
Doctors, admins and receptionists each see only what their role needs. Access is checked on every request, and a break-glass path exists for genuine emergencies — always logged.
Digital consent capture
Register the patient, then capture consent with real, trackable links — on the device, over WhatsApp, or printed. Consent is recorded against the patient, so you always know what was agreed and when.
Sign-in hardening
Multi-factor authentication, session fingerprinting and rate-limited login protect accounts from takeover and brute-force attempts — without making the day-to-day sign-in painful.
Export anytime · no lock-in
Your data is yours. Export your tenant's records whenever you like, and exercise right-to-erasure when a patient asks. Cancel and leave with everything — we never hold your data hostage.
Where we stand — no overclaiming
Consent, purpose-limitation, right-to-erasure and audit are built into how patient data is handled.
Access controls, encryption, audit logging and minimum-necessary access follow HIPAA's Security Rule principles.
A formal third-party audit is planned. Until it's complete, we make no SOC 2 claim and display no badge.
"Designed to align" means our architecture follows these frameworks' principles. It is not a certification or a guarantee of legal compliance — your clinic remains the data controller and is responsible for its own regulatory obligations.
Questions about security or a vulnerability to report?
We take responsible disclosure seriously. Reach the team and we'll respond — and if you're evaluating Clinitricks for a clinic, we're happy to walk through our data-handling in detail.