Back to home

Security overview

Medix is built for regulated healthcare workflows. This page summarizes how we protect patient data — without marketing exaggeration.

Encryption

Sensitive patient fields — including clinical notes and medical history — are encrypted at the application layer using AES-256-GCM when an encryption key is configured for your deployment. Patient data is stored in isolated, clinic-scoped workspaces (multi-tenant architecture).

Audit logging

Create, read, update, and delete actions on clinical records can be recorded in an audit trail with user identity, timestamp, and request context. Audit logs support compliance reviews, incident response, and internal accountability.

Access control

Team members access only their assigned clinic workspace. Role-based permissions limit who can view, edit, or administer patient data. Team access changes are part of your clinic's operational hygiene — visible in the Privacy Center.

Privacy-first calendar sync

Medix is the source of truth for clinical data. Google Calendar integration mirrors appointment times only — not full medical records. With Privacy Mode enabled, external calendar events use generic titles such as Consultation, Follow-up, or Reserved Slot.

Compliance posture

Each clinic has a live compliance posture view in the Privacy Center — covering encryption status, consent coverage, calendar privacy settings, file security, and team access hygiene. This is clinic-specific and actionable, not a generic marketing score.

Retention & data rights

Retention policies, data export, and erasure workflows are built into the platform to support GDPR and KVKK requirements. Enterprise plans include custom retention policies, archive exports, and disaster recovery planning.

Questions

For security inquiries or a Data Processing Agreement, contact hello@medix.healthcare. See also our Privacy Policy.