Security

Written for the day someone asks you to prove it.

A clinic holds the most sensitive category of personal data there is, and is accountable for it whether or not its software vendor made that easy. This page is what we have built so that answering an auditor is a matter of opening a screen.

  • PDPA
  • Clinic-by-clinic separation
  • Two-step login
  • Audit trail
  • Full data export
Audit log · exportableSample
Time (SGT)ActorActionObject
14:22front-desk.1Viewed patientS••••567G
14:19doctor.aIssued MCMC-2026081714
09:03admin.1Revoked permissionVoid invoice → front desk
08:47unknownLogin refuseddevice not approved

A revoked permission is kept on record, so the next update cannot quietly restore it.

Separation

One clinic cannot see another

Your records stay inside your clinic

Every time someone opens a record, the system checks which clinic they belong to on its own side. Staff from another clinic cannot reach your patients, even with a copied or altered link.

Checked before every release

Automated tests try to cross from one clinic into another before each release. If a change ever made that possible, it would not ship.

Our staff and yours are kept apart

Running the platform and running your clinic are separate kinds of access. Your clinic administrator cannot act as MedPath, and MedPath support access is logged.

Regional hosting

Application and database run in the Singapore region, on private networking, with encrypted connections.

Access control

Who can open what, and who said so

Access control is the heaviest section of every clinic security assessment. It is also the one most systems implement as a single "admin" toggle.

Permissions · by roleSample
RoleRead notesPrescribeVoid invoice
Doctor✓✓—
Front deskBookings only—Revoked
Clinic admin——✓

Permissions are set per role, so who can do what is reviewable. A revoked permission stays revoked after the next update.

Roles, defined once and applied consistently

Doctor, nurse, front desk, pharmacist, clinic admin — each with a default permission set maintained as configuration, so what a role can do is reviewable rather than folklore.

Revocation that stays revoked

When a clinic takes a permission away from a role, that decision is kept on record. A later update that restores the defaults will not quietly give the permission back.

Least privilege by role, not by seniority

Front desk staff can see what they need to serve a patient and are blocked from the clinical actions they should not perform, without needing a second login.

Multi-factor authentication

Staff confirm their login with a code from an authenticator app. Each person can turn it on, and the clinic can make it compulsory.

Trusted-device gating

A clinic can require that staff sign in only from computers it has approved. Approval is a real workflow — pending, approved, revoked — and revoking a device kills its sessions rather than just labelling it.

The login page reveals nothing

The device check runs only after the password is right, so nobody can use the login page to find out whether an account exists. That order is fixed, not a setting.

Accountability

What was done, and by whom

Audit logging across the product

Clinical and administrative actions are written to an audit log with the acting user attached per request, rather than reconstructed afterwards.

Login events are auditable

Successful logins, failed attempts and logouts are recorded distinctly, with the reason for a failure carried in the record.

Merges and deletions leave a trail

Destructive-looking operations are modelled as recorded events, so a record’s history survives the operation that changed it.

Exportable for review

The account inventory, the role/permission matrix, MFA status and the audit log are exportable — which is exactly the evidence a certification assessment asks for.

The data itself

Storage, retention and getting it back

Private storage, signed access

Documents, scans and images are kept in private storage. Each time a staff member opens one, the system issues a link that expires within minutes, so there is no permanent public link to leak.

Encrypted in transit and at rest

Connections are encrypted end to end, and storage is encrypted at rest by default rather than as an upgrade.

Backups and recovery, tested

Backups are taken continuously and restore has been exercised against a real dataset — an untested backup is a belief, not a control.

Data portability

A full export of the clinical and financial record across every domain, in open formats, with a data dictionary, so you can leave without asking permission.

How it stays true

How the promises are kept

The everyday habits that make the promises above hold up on an ordinary Tuesday.

Passwords and keys are locked away

The keys that connect the system to other services are kept in a secured store, never written into the program itself.

Known weaknesses are looked for continuously

The third-party software the system is built on is checked for published weaknesses all the time, and anything found is fixed or explicitly ruled out.

Errors are monitored, not discovered by patients

When something goes wrong on a screen or behind it, we are alerted with the details, so a fault is usually fixed before anyone has to call.

Every date is Singapore time

All times are Singapore time, including the day-end cut-off. An invoice raised at 7:30 in the morning lands on the right day in every report and submission.

Certification

We passed the harder version of the assessment you face

The vendor edition, certified

MedPath has passed Cyber Essentials for HIMS Vendors certification.

We supply our own vendor evidence

The clauses that require you to evidence your software supplier’s security are answered with a pack we produce for our own product, so your assessment does not stall waiting on us.

Your registers export instead of being typed

Account inventory with last-login dates, the role/permission matrix, audit logs and MFA status come out of the system rather than being compiled by hand.

And we will take you through yours

Clinics have their own obligation under the HIA Entities edition. We run that engagement as a service.

MedPath is not a certification body. Certification is issued by a certification body appointed by CSA.

Questions

Security questions

Can we require MFA for everyone?

MFA is enrollable per user and can be enforced by the clinic. Trusted-device gating can be layered on top so that even a correct password from an unapproved machine does not get in.

Who at MedPath can see our patient data?

Running the platform and seeing clinic data are separate kinds of access, and every access is logged. We will walk through exactly what support access looks like on the call.

Can we get a copy of everything, today?

Yes. The export covers the clinical and financial domains in open formats with a data dictionary, and it is a product feature rather than a services request.

Next step

See it against your own clinic day.

Thirty minutes, screen shared, using your workflow — your busiest hour, your payer mix, your claim types. We will tell you plainly if we are the wrong fit.

No slide deck. No obligation.