Security your clinic can rely on.
Patient data is the most sensitive information you handle. We treat protecting it as our first responsibility, not a feature.
How we protect your data
The safeguards behind every clinic and patient record on NxaCare.
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
Access controls
Role-based permissions and optional two-factor authentication for every account.
Hardened infrastructure
Hosted on leading cloud providers in isolated, access-controlled environments.
Audit logging
Every access to a patient record is logged and reviewable by clinic admins.
Automated backups
Encrypted backups run continuously with tested, point-in-time recovery.
Least privilege
Internal access is granted on a need-to-know basis and reviewed regularly.
Compliance & certifications
We align with recognised standards and test our defences with independent experts.
- DPDP Act 2023 aligned
- HIPAA-ready (BAA available)
- ISO 27001 practices
- Annual third-party pen-testing
Responsible disclosure
Found a vulnerability? We'd genuinely like to hear from you. Report it privately to our security team and we'll acknowledge your report within 48 hours and keep you updated as we investigate.
security@nxacare.comLooking for how we handle health data specifically? See our compliance page and privacy policy.