← OpsClinica

Trust & legal

Security Overview

A factual overview of controls currently represented in the OpsClinica application.

This is an MVP policy draft based on current product functionality. OpsClinica is developed and operated by Ziloah Solutions, an independent freelance business based in Mintal, Davao City, Philippines. These documents require legal review before a global production launch.

Current application controls

  • Clinic-scoped records and staff access paths.
  • Role-based staff permissions for clinic operations and messaging.
  • Two-factor authentication for privileged accounts where enabled.
  • Rate limiting for sensitive login, signup, password-reset, and appointment-lookup flows.
  • Security events, audit history, and configurable IP/country access rules.
  • Encrypted fields for selected sensitive patient, message, waitlist, and support data.
  • Signed appointment-management links and security headers when production security settings are enabled.

Shared responsibility

Security also depends on each clinic's account administration, workstation controls, network practices, staff training, and the production hosting, database, email, and payment providers selected for deployment. Clinic administrators should use 2FA, restrict roles, review access, and remove inactive users promptly.

Security reporting

Report suspected security issues to support@opsclinica.com. Do not send patient information in a public security report or ordinary email. OpsClinica will assess reports under its incident-response process.

Important limitation

This page is not a certification, audit report, or guarantee of compliance with HIPAA, GDPR, or any other law. Any compliance claim must follow a documented control review, contract review, and applicable legal assessment.