Meddesk
Security & Compliance

Built so your organization's data is neveranyone else's to see

Meddesk handles patient records, so keeping that data private and controlling who can see it comes first - not as an add-on, but as the foundation everything else is built on.

Isolated by design

Every organization's information is kept completely private and walled off - never mixed, shared, or visible to anyone outside it.

Role-based access control

Access is granted permission by permission, across every clinical and operational module, so staff only ever see what their role requires.

Encrypted in transit

All traffic between the console, the API, and the patient portal is encrypted end to end.

A record of what happened

Every status change is logged with who changed it and when, and clinical form submissions are amendable only with a reason on record - nothing is silently edited.

Guarded sign-in

Every login is checked against automated and abusive access attempts before it's let through.

Two-factor authentication

Staff can enable TOTP-based two-factor authentication from their account settings, backed by a session manager that lists every active device and lets you sign out a lost or stale login in one click.

Enforce 2FA org-wide

Manage every staff account and its access from one settings page, and require two-factor authentication for all of them with a single switch - anyone without confirmed 2FA is blocked from the app until they set it up.

Built to localize

Currency, timezone, and calendar support - including the Afghan Solar Hijri calendar - so the platform fits your organization, not the other way around.

Private by design

Your data, walled off. No exceptions.

Some platforms keep every customer's information in one shared system, separated only by a filter that has to be applied correctly every time. Meddesk keeps each organization's data completely walled off from the moment it's set up - there's no shared system for anything to slip across. The separation is built in, not something that has to be remembered.

  • Every hospital, clinic, and practice gets its own private space, set up from day one
  • Nothing in the system can ever mix information between organizations
  • Staff logins and platform management are kept separate from clinical data

meddesk.cc - how your data stays separate

One platform. Every practice's data kept apart.
City Hospital
private
Riverside Clinic
private
Dr. Amiri
private
Sunrise GP Practice
private

Role-based access

Access, down to the permission

Every clinical and operational module - patients, appointments, finance, prescriptions, forms - has its own set of permissions. A receptionist role can be scoped to scheduling and check-in without ever exposing clinical notes or financial detail, and every permission can be adjusted per practice.

  • Seeded roles on day one: Doctor, Nurse, Receptionist, Manager, Super Administrator
  • Granular permissions across every module, not just page-level access
  • Sign-in is checked against automated and abusive access attempts
Role permissions
Role permissions checklistRole permissions checklist

Audit trail

A record of what happened

Every status change - an appointment checked in, a treatment plan completed - is logged with who changed it, when, and what it changed from. Clinical form submissions follow the same rule: amendable only with a reason on record, never silently edited.

  • Every transition timestamped, with the staff member who made it
  • A full history on every appointment and treatment plan, not just the latest state
  • Form amendments require a reason on record - nothing disappears quietly
Status history
Status history timeline for an appointmentStatus history timeline for an appointment

Where we are today

Built on these principles from day one

Meddesk is early. We haven't yet pursued formal certifications like SOC 2 or ISO 27001 - the architecture above is what we've built from the start, not a retrofit. If your practice or organization has specific compliance, data residency, or contractual requirements, tell us during your demo and we'll work through them with you directly, including a data processing agreement where needed.

Bring your security questions to the demo