Trust & legal
Security Overview
A factual overview of controls currently represented in the OpsClinica application.
Current application controls
- Clinic-scoped records and staff access paths.
- Role-based staff permissions for clinic operations and messaging.
- Two-factor authentication for privileged accounts where enabled.
- Rate limiting for sensitive login, signup, password-reset, and appointment-lookup flows.
- Security events, audit history, and configurable IP/country access rules.
- Encrypted fields for selected sensitive patient, message, waitlist, and support data.
- Signed appointment-management links and security headers when production security settings are enabled.
Shared responsibility
Security also depends on each clinic's account administration, workstation controls, network practices, staff training, and the production hosting, database, email, and payment providers selected for deployment. Clinic administrators should use 2FA, restrict roles, review access, and remove inactive users promptly.
Security reporting
Report suspected security issues to support@opsclinica.com. Do not send patient information in a public security report or ordinary email. OpsClinica will assess reports under its incident-response process.
Important limitation
This page is not a certification, audit report, or guarantee of compliance with HIPAA, GDPR, or any other law. Any compliance claim must follow a documented control review, contract review, and applicable legal assessment.