Security & Data Protection
Patient Data Security & Protection
Your patient data is not our data. We just keep it safe.
Healthcare data is the most sensitive personal information that exists. A patient’s diagnoses, medications, reproductive history, and mental health records are not abstract data points. They are intimate facts about real people that can affect careers, relationships, insurance, and lives if mishandled.
- AES-256 Encrypted
- TLS 1.3 In Transit
- ISO 27001 Hosting
- 🇮🇳 India-Resident Data
- Daily Backups
- MFA Available
- No Data Selling
Security Index
Encryption
How your data is protected in storage and in transit
Encryption is the foundation of healthcare data security. Medisray applies it at two layers: when data is stored (at rest) and when it moves between your device and our servers (in transit).
At rest: AES-256
All patient data stored in Medisray: records, prescriptions, uploaded documents, billing history is encrypted using the Advanced Encryption Standard with a 256-bit key (AES-256). This is the same encryption standard used by financial institutions, government agencies, and defence systems worldwide.
What AES-256 means in practice?
Even if someone were to obtain the raw files from our storage systems, they would be unreadable without the decryption key. The data is not just access-controlled, it is cryptographically protected at the file level.
In transit: TLS 1.3
Every request between your browser or mobile device and Medisray’s servers is encrypted using Transport Layer Security version 1.3 (TLS 1.3) – the current highest standard for data transmission security.
What TLS 1.3 means in practice: When your receptionist opens a patient record, when a prescription is sent over WhatsApp from Medisray, or when a billing record syncs between your device and the cloud, that data cannot be intercepted and read in transit. Older, weaker protocol versions (TLS 1.0, 1.1) are not supported.
Key management
Hosting & Data Residency
Medical data security depends not just on how data is protected, but on where it lives. Here's where your data is stored, and why that matters.
India-resident data
All patient data processed and stored through Medisray is hosted within India. It does not cross Indian borders unless you explicitly request a data export and transfer it yourself.
This matters for two reasons. First, it keeps your patient data within Indian jurisdiction. That means your data is governed by Indian data-protection law – including the Digital Personal Data Protection (DPDP) Act, 2023 and the IT (SPDI) Rules, 2011 and any government or regulatory request must go through Indian legal channels, not foreign ones.
ISO 27001-certified infrastructure
What this means for your clinic?
Physical security
The data centers hosting Medisray infrastructure operate 24/7 physical security, biometric access controls, CCTV monitoring, redundant power supplies, and fire suppression systems. Medisray staff do not have physical access to data centre hardware; access is managed through our cloud infrastructure provider under a shared responsibility model.
Infrastructure redundancy
Access Controls
Who can see what and how we enforce it
Role-based access control (RBAC)
Every user in Medisray is assigned a role that determines what they can see and do. The system ships with pre-defined roles designed for typical clinic structures:
- Doctor / Clinician: full access to their own patients’ records, prescriptions, and clinical notes. Cannot access billing configuration or other doctors’ patient lists without explicit permission.
- Receptionist / Front Desk: appointment scheduling, patient registration, billing. Cannot access clinical notes, prescription history, or lab reports unless explicitly enabled by the clinic administrator.
- Clinic Administrator: full access to all clinic data and configuration. Responsible for setting permissions for other roles.
- Billing Staff: billing records, invoice management, payment tracking. No access to clinical records.
- Read-Only / Reporting: view access only, no ability to create or modify records. Suitable for owners or managers reviewing practice performance.
Roles are fully customizable by the clinic administrator. If your workflow requires a different permission structure, you can configure it.
Multi-factor authentication (MFA)
Audit logs
Medisray maintains a tamper-resistant audit log of all significant actions taken within the system:
- Patient record access: every time a patient record is opened, by whom, and at what time
- Data modifications: who changed what, when, with before/after values preserved
- Login events: successful logins, failed attempts, MFA challenges
- Data exports: when and by whom a data export was initiated
- Permission changes: when a user’s role was modified and by whom
Session management
Backup & Recovery
What happens if something goes wrong
Daily automated backups
Patient data is backed up automatically every 24 hours. Backups are encrypted with the same AES-256 standard as primary data. They are stored in a geographically separate location from the primary database meaning a failure at the primary data centre does not affect the backup.
Clinic-initiated data export
One Secure place for all your health data
Frequently Asked Questions
What encryption does Medisray use for patient data?
All patient data stored in Medisray is encrypted at rest using AES-256, the same standard used in banking and defence systems.