Security overview
Medix is built for regulated healthcare workflows. This page summarizes how we protect patient data — without marketing exaggeration.
Encryption
Sensitive patient fields — including clinical notes and medical history — are encrypted at the application layer using AES-256-GCM when an encryption key is configured for your deployment. Patient data is stored in isolated, clinic-scoped workspaces (multi-tenant architecture).
Audit logging
Create, read, update, and delete actions on clinical records can be recorded in an audit trail with user identity, timestamp, and request context. Audit logs support compliance reviews, incident response, and internal accountability.
Access control
Team members access only their assigned clinic workspace. Role-based permissions limit who can view, edit, or administer patient data. Team access changes are part of your clinic's operational hygiene — visible in the Privacy Center.
Privacy-first calendar sync
Medix is the source of truth for clinical data. Google Calendar integration mirrors appointment times only — not full medical records. With Privacy Mode enabled, external calendar events use generic titles such as Consultation, Follow-up, or Reserved Slot.
Compliance posture
Each clinic has a live compliance posture view in the Privacy Center — covering encryption status, consent coverage, calendar privacy settings, file security, and team access hygiene. This is clinic-specific and actionable, not a generic marketing score.
Retention & data rights
Retention policies, data export, and erasure workflows are built into the platform to support GDPR and KVKK requirements. Enterprise plans include custom retention policies, archive exports, and disaster recovery planning.
Questions
For security inquiries or a Data Processing Agreement, contact hello@medix.healthcare. See also our Privacy Policy.