Patient Data Security in Clinic Software: A Buyer's Checklist
Ten questions to put to any clinic management vendor before you store patient records in it — and what a good answer sounds like.
Clinic software is safe for patient data when identifying fields are encrypted, every request is checked on the server against the user's clinic and role, changes are logged, data is backed up, and the vendor is specific about which certifications it does and does not hold. Phrases like "bank-grade security" or "HIPAA-ready" answer none of these questions; the checklist below does.
Which patient data should clinic software encrypt?
At minimum, the fields that identify a person: name, phone, email, address and identity or passport details. Encryption "at rest" at disk level protects against a stolen drive but not against someone with database access; field-level encryption in the application protects the values themselves. Ask which fields are encrypted, with which algorithm, and where the key is kept.
The 10-point checklist
| Question | A good answer |
|---|---|
| Which fields are encrypted, and how? | Named fields, a named algorithm (e.g. AES-256-GCM), key held outside the database |
| How does search work on encrypted names? | A separate normalised search column — not decrypting every record |
| Can another clinic on the platform see our data? | No: membership and role resolved on the server for every request |
| Where are permissions enforced? | On the server; hiding a button is not a control |
| Can one staff member get extra access without changing the whole role? | Per-member overrides on top of a role |
| Is there an audit log, and who can read it? | Per-clinic log, readable by roles you choose |
| How often is data backed up? | A stated schedule per plan |
| Which certifications are held? | A specific list — or an explicit "none" |
| Is there a data processing agreement? | Yes, on request, naming the legal entity |
| How do we report a vulnerability? | A named contact address |
KVKK and GDPR: what changes for clinics?
Both Turkey's KVKK (Law No. 6698) and the EU GDPR (Article 9) treat health data as a special category of personal data with stricter processing conditions. GDPR Article 32 names encryption as an example of an appropriate security measure, and the Turkish Personal Data Protection Board has published adequate-measure requirements specifically for special-category data. The clinic remains the data controller; the software vendor is a processor, which is why a data processing agreement matters. This article is general information, not legal advice.
How ClinicArchitect answers these questions
- Identifying fields (name, phone, email, address, passport) are encrypted with AES-256-GCM before they are written to the database.
- Name search uses a separate normalised column, so encrypted fields are never searched by content.
- Every clinic-scoped request is checked on the server against the caller's membership and role in that clinic.
- Roles carry a permission matrix over 14 product areas, with per-member overrides.
- Each clinic has its own audit log.
- Backups: monthly on Premium; weekly database and file backups on Pro.
- No HIPAA, ISO 27001 or SOC 2 certification is claimed.
Clinical fields such as diagnosis and visit notes are protected by the same server-side permission checks and clinic isolation rather than by field-level encryption. Full details, including how to request a data processing agreement, are on the security and data handling page.
Často kladené otázky
Is encryption at rest enough for patient data?
Disk-level encryption protects against a stolen drive, not against someone with database access. Field-level encryption of identifying data, done by the application before the database write, protects the values themselves.
Is ClinicArchitect HIPAA certified?
No. ClinicArchitect does not claim HIPAA, ISO 27001 or SOC 2 certification. It publishes the specific controls it applies instead, so clinics can assess them against their own obligations.
Who is responsible for patient data under KVKK or GDPR, the clinic or the software vendor?
The clinic is the data controller. The software vendor processes data on the clinic's behalf, which is why the clinic should have a data processing agreement with the vendor.
