Protecting Protected Health Information (PHI) is at the core of everything we build. Discover our multi-layered defense architecture.
SelfClinic enforces bank-grade cryptographic standards across all software layers:
For United States covered entities and healthcare practices, SelfClinic operates in full alignment with the HIPAA Security, Privacy, and Breach Notification Rules. We execute formal Business Associate Agreements (BAA) guaranteeing strict administrative, physical, and technical safeguards.
SelfClinic is fully compliant with the European Union General Data Protection Regulation (Regulation EU 2016/679). European clients benefit from:
Every staff account is assigned customized permission roles. Receptionists cannot view clinical notes, while billing teams only access financial ledgers. All system events—including record views, modifications, and downloads—are immutably logged with user IDs, IP addresses, and timestamps.
Automated incremental snapshots are captured continuously and replicated across geographically separated cloud availability zones, ensuring a Recovery Point Objective (RPO) of under 5 minutes and Recovery Time Objective (RTO) under 15 minutes.
Need our comprehensive security architecture documentation, SOC 2 compliance summary, or a signed Business Associate Agreement for your healthcare organization?
Contact Security Team →