Security Centre
MedFlow is designed with healthcare privacy and security controls and is built to support healthcare organisations' compliance obligations. The statements below describe implemented controls and design alignment — not independent certification.
Access control
- Configurable role-based access control, enforced in the database as well as the user interface
- Facility-scoped access so staff see the records of the facility they work in
- Single active session enforcement with inactivity timeout
- Emergency ('break the glass') access requires a recorded justification and is reviewable afterwards
- Administrator-controlled password workflows and forced password change
Auditability
- Access to patient records is recorded in an audit trail
- Clinical, billing and administrative changes are logged with the acting user
- Clinical data follows a retain-and-amend model rather than hard deletion
- Interoperability exchanges are logged with status and user attribution
Data protection
- Encrypted transport for all application and database traffic
- Sensitive fields protected by additional access controls
- Secrets and API credentials are held server-side and never exposed in the browser
- Separation between marketing analytics and clinical systems: no patient data is captured by website analytics
Compliance position
- Designed with healthcare privacy and security controls
- Built to support healthcare organisations' compliance obligations
- Security controls aligned with recognised healthcare data-protection principles
- Designed to support compliance with the Nigeria Data Protection Act 2023
- Supports configurable role-based access controls
- FHIR R4-ready where implemented and tested
- HIPAA-aligned safeguards for applicable deployments
- GDPR-aligned data-protection principles for applicable deployments
What we do not claim
MedFlow does not claim independent certification against HIPAA, ISO 27001, SOC 2 or any other standard unless a specific certificate is provided by an accredited assessor. Where a customer requires certified hosting or assessment, this is scoped as part of the deployment and named explicitly in the contract.
Customer dependencies
- Independent security certification (for example ISO 27001 or SOC 2) requires an accredited external audit engaged by Ubora One Limited.
- Penetration-test reports and certificates can only be published once completed by an external assessor.
MedFlow home — Contact Ubora One Limited