Skip to main content
Security

Security your clinic can rely on.

Patient data is the most sensitive information you handle. We treat protecting it as our first responsibility, not a feature.

How we protect your data

The safeguards behind every clinic and patient record on NxaCare.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.

Access controls

Role-based permissions and optional two-factor authentication for every account.

Hardened infrastructure

Hosted on leading cloud providers in isolated, access-controlled environments.

Audit logging

Every access to a patient record is logged and reviewable by clinic admins.

Automated backups

Encrypted backups run continuously with tested, point-in-time recovery.

Least privilege

Internal access is granted on a need-to-know basis and reviewed regularly.

Compliance & certifications

We align with recognised standards and test our defences with independent experts.

  • DPDP Act 2023 aligned
  • HIPAA-ready (BAA available)
  • ISO 27001 practices
  • Annual third-party pen-testing

Responsible disclosure

Found a vulnerability? We'd genuinely like to hear from you. Report it privately to our security team and we'll acknowledge your report within 48 hours and keep you updated as we investigate.

security@nxacare.com

Looking for how we handle health data specifically? See our compliance page and privacy policy.