Security at Medicasimple

How we protect clinic data.

Here are the controls we use for access, encryption, backups, monitoring and support. Certificates are in the Trust Centre.

Role-based accessTLS in transitEncrypted backupsSecurity evidence on request

Protection model

Four parts of the security model.

Access · Data · Operations · Evidence
01
Clinic controlsAccounts, roles and devices
02
Product safeguardsSign-in controls and encryption
03
Service operationsMonitoring and backups
04
EvidencePolicies and certificates
Clinics control user accessMedicasimple runs backups and monitoringCertificates are available through the Trust Centre
Security overview · You are here

Product controls, service operations and shared responsibilities.

Trust CentreCurrent assurance status, public sources and certificate requests.

Security controls

The controls in place.

Some are clinic settings. Others are measures Medicasimple runs and records in the Data Processing Addendum.

Account access

Set access by role.

Clinic admins choose what each role can see and do. Optional IP restrictions can block sign-ins outside approved clinic networks.

Role-based permissionsOptional IP restrictionsClinic-controlled support access

Data protection

Encrypt data and back it up.

TLS protects data in transit. Supported data stores are encrypted at rest. Backups are encrypted and covered by recovery procedures.

TLS in transitEncrypted backupsRecovery procedures

Monitoring & maintenance

Monitor the service and fix vulnerabilities.

Centralised logs and alerts help our team spot service issues. We scan for vulnerabilities, fix findings and use external testing where appropriate.

Logging and alertingVulnerability managementSecurity maintenance

Staff & support access

Restrict staff access.

Only authorised staff can access systems or data. Access depends on role and need, with confidentiality duties, security training and incident procedures.

Least-privilege accessConfidentiality obligationsIncident-response playbooks

Shared responsibility

Your clinic decides. Medicasimple operates.

Your clinic decides why patient data is used and who gets access. Medicasimple runs the service under your instructions.

Clinic or practice · Data Controller

Decides why data is used and who has access.

  • Choose who gets an account and which permissions they receive.
  • Protect passwords, devices and clinic network access.
  • Set optional access restrictions to suit the clinic.
  • Set the lawful basis, notices and instructions for patient data.

Medicasimple · Data Processor

Runs the service and applies its safeguards.

  • Run authentication, monitoring and backup processes.
  • Apply the security measures recorded in the DPA.
  • Limit staff access by role, need and confidentiality duties.
  • Support security, data-rights and incident duties under the DPA.

Security questions

Security questions.

Does Medicasimple guarantee absolute security?+

No online service can guarantee absolute security. We use technical and organisational controls to reduce risk, monitor the service and respond to incidents.

Who controls patient data in Medicasimple?+

The clinic or practice is the Data Controller. Medicasimple is the Data Processor and acts on the clinic’s documented instructions.

How can a clinic control account access?+

Clinic admins assign permissions by role. Optional IP restrictions can limit access to approved networks.

Where can a procurement team review certificates?+

The Trust Centre lists current assurance status and public sources. Use its form to request certificates.

How should a vulnerability be reported?+

Email security@medicasimple.com with enough detail to investigate. Do not publish the suspected vulnerability while we review it.

Evidence for your review

Need a certificate or security document?

Check the current status or request the specific evidence your team needs.