How we protect clinic data.
Here are the controls we use for access, encryption, backups, monitoring and support. Certificates are in the Trust Centre.
Protection model
Four parts of the security model.
Product controls, service operations and shared responsibilities.
Security controls
The controls in place.
Some are clinic settings. Others are measures Medicasimple runs and records in the Data Processing Addendum.
Account access
Set access by role.
Clinic admins choose what each role can see and do. Optional IP restrictions can block sign-ins outside approved clinic networks.
Data protection
Encrypt data and back it up.
TLS protects data in transit. Supported data stores are encrypted at rest. Backups are encrypted and covered by recovery procedures.
Monitoring & maintenance
Monitor the service and fix vulnerabilities.
Centralised logs and alerts help our team spot service issues. We scan for vulnerabilities, fix findings and use external testing where appropriate.
Staff & support access
Restrict staff access.
Only authorised staff can access systems or data. Access depends on role and need, with confidentiality duties, security training and incident procedures.
Shared responsibility
Your clinic decides. Medicasimple operates.
Your clinic decides why patient data is used and who gets access. Medicasimple runs the service under your instructions.
Clinic or practice · Data Controller
Decides why data is used and who has access.
- Choose who gets an account and which permissions they receive.
- Protect passwords, devices and clinic network access.
- Set optional access restrictions to suit the clinic.
- Set the lawful basis, notices and instructions for patient data.
Medicasimple · Data Processor
Runs the service and applies its safeguards.
- Run authentication, monitoring and backup processes.
- Apply the security measures recorded in the DPA.
- Limit staff access by role, need and confidentiality duties.
- Support security, data-rights and incident duties under the DPA.
Review routes
Security documents and contacts.
Certificates are in the Trust Centre. Contract terms are in the DPA. Data handling is in the Privacy Policy. Vulnerabilities go to our security email.
Assurance status and evidence
Check our current assurance status, open public records and request certificates.
Open the Trust CentreData Processing Addendum
See controller and processor duties, security measures, audit rights and sub-processors.
Read the DPAPrivacy Policy
See when Medicasimple acts as controller or processor, plus rights and retention.
Read the Privacy PolicyReport a security issue
Email a suspected vulnerability directly. Do not publish details while we investigate.
Email security@medicasimple.comSecurity questions
Security questions.
Does Medicasimple guarantee absolute security?+
No online service can guarantee absolute security. We use technical and organisational controls to reduce risk, monitor the service and respond to incidents.
Who controls patient data in Medicasimple?+
The clinic or practice is the Data Controller. Medicasimple is the Data Processor and acts on the clinic’s documented instructions.
How can a clinic control account access?+
Clinic admins assign permissions by role. Optional IP restrictions can limit access to approved networks.
Where can a procurement team review certificates?+
The Trust Centre lists current assurance status and public sources. Use its form to request certificates.
How should a vulnerability be reported?+
Email security@medicasimple.com with enough detail to investigate. Do not publish the suspected vulnerability while we review it.
Evidence for your review
Need a certificate or security document?
Check the current status or request the specific evidence your team needs.