Your records stay inside your clinic
Every time someone opens a record, the system checks which clinic they belong to on its own side. Staff from another clinic cannot reach your patients, even with a copied or altered link.
Security
A clinic holds the most sensitive category of personal data there is, and is accountable for it whether or not its software vendor made that easy. This page is what we have built so that answering an auditor is a matter of opening a screen.
| Time (SGT) | Actor | Action | Object |
|---|---|---|---|
| 14:22 | front-desk.1 | Viewed patient | S••••567G |
| 14:19 | doctor.a | Issued MC | MC-2026081714 |
| 09:03 | admin.1 | Revoked permission | Void invoice → front desk |
| 08:47 | unknown | Login refused | device not approved |
A revoked permission is kept on record, so the next update cannot quietly restore it.
Separation
Every time someone opens a record, the system checks which clinic they belong to on its own side. Staff from another clinic cannot reach your patients, even with a copied or altered link.
Automated tests try to cross from one clinic into another before each release. If a change ever made that possible, it would not ship.
Running the platform and running your clinic are separate kinds of access. Your clinic administrator cannot act as MedPath, and MedPath support access is logged.
Application and database run in the Singapore region, on private networking, with encrypted connections.
Access control
Access control is the heaviest section of every clinic security assessment. It is also the one most systems implement as a single "admin" toggle.
| Role | Read notes | Prescribe | Void invoice |
|---|---|---|---|
| Doctor | ✓ | ✓ | — |
| Front desk | Bookings only | — | Revoked |
| Clinic admin | — | — | ✓ |
Permissions are set per role, so who can do what is reviewable. A revoked permission stays revoked after the next update.
Doctor, nurse, front desk, pharmacist, clinic admin — each with a default permission set maintained as configuration, so what a role can do is reviewable rather than folklore.
When a clinic takes a permission away from a role, that decision is kept on record. A later update that restores the defaults will not quietly give the permission back.
Front desk staff can see what they need to serve a patient and are blocked from the clinical actions they should not perform, without needing a second login.
Staff confirm their login with a code from an authenticator app. Each person can turn it on, and the clinic can make it compulsory.
A clinic can require that staff sign in only from computers it has approved. Approval is a real workflow — pending, approved, revoked — and revoking a device kills its sessions rather than just labelling it.
The device check runs only after the password is right, so nobody can use the login page to find out whether an account exists. That order is fixed, not a setting.
Accountability
Clinical and administrative actions are written to an audit log with the acting user attached per request, rather than reconstructed afterwards.
Successful logins, failed attempts and logouts are recorded distinctly, with the reason for a failure carried in the record.
Destructive-looking operations are modelled as recorded events, so a record’s history survives the operation that changed it.
The account inventory, the role/permission matrix, MFA status and the audit log are exportable — which is exactly the evidence a certification assessment asks for.
The data itself
Documents, scans and images are kept in private storage. Each time a staff member opens one, the system issues a link that expires within minutes, so there is no permanent public link to leak.
Connections are encrypted end to end, and storage is encrypted at rest by default rather than as an upgrade.
Backups are taken continuously and restore has been exercised against a real dataset — an untested backup is a belief, not a control.
A full export of the clinical and financial record across every domain, in open formats, with a data dictionary, so you can leave without asking permission.
How it stays true
The everyday habits that make the promises above hold up on an ordinary Tuesday.
The keys that connect the system to other services are kept in a secured store, never written into the program itself.
The third-party software the system is built on is checked for published weaknesses all the time, and anything found is fixed or explicitly ruled out.
When something goes wrong on a screen or behind it, we are alerted with the details, so a fault is usually fixed before anyone has to call.
All times are Singapore time, including the day-end cut-off. An invoice raised at 7:30 in the morning lands on the right day in every report and submission.
Certification
MedPath has passed Cyber Essentials for HIMS Vendors certification.
The clauses that require you to evidence your software supplier’s security are answered with a pack we produce for our own product, so your assessment does not stall waiting on us.
Account inventory with last-login dates, the role/permission matrix, audit logs and MFA status come out of the system rather than being compiled by hand.
Clinics have their own obligation under the HIA Entities edition. We run that engagement as a service.
MedPath is not a certification body. Certification is issued by a certification body appointed by CSA.
Questions
MFA is enrollable per user and can be enforced by the clinic. Trusted-device gating can be layered on top so that even a correct password from an unapproved machine does not get in.
Running the platform and seeing clinic data are separate kinds of access, and every access is logged. We will walk through exactly what support access looks like on the call.
Yes. The export covers the clinical and financial domains in open formats with a data dictionary, and it is a product feature rather than a services request.
Next step
Thirty minutes, screen shared, using your workflow — your busiest hour, your payer mix, your claim types. We will tell you plainly if we are the wrong fit.
No slide deck. No obligation.