Security and compliance
EzClinic protects patient data with encrypted connections, per-clinic data isolation, role-based access control and daily automated backups. Application-level protections include CSRF protection, login rate-limiting and authenticated document storage. Privacy practices are GDPR-aligned, with data minimisation and full audit trails.
Platform protections
- SSL/TLS encryption for data in transit
- Per-clinic (tenant) data isolation at the database level
- Role-based access for reception, clinical and admin staff
- Daily automated backups
- CSRF protection on state-changing requests
- Login rate-limiting against credential stuffing
- Authenticated-only access to medical documents
- Complete patient audit trail
Data isolation explained
EzClinic is multi-tenant: every clinic shares the platform but not the data. Each record carries the clinic it belongs to, and queries are scoped to the signed-in clinic, so another clinic cannot read, list or query your patients, invoices or documents.
Uploaded files follow the same rule. Documents are stored in tenant-isolated storage and served only to authenticated staff of the owning clinic.
Privacy and compliance posture
EzClinic follows GDPR-aligned privacy practices: collect only what the clinic needs, keep an audit trail of access, and give clinics control over their own records. Clinics remain the data controller for their patient data; EzTechify processes it on their behalf.
Our terms, privacy policy and cookie policy describe the full arrangement.
Explore more of EzClinic
See EzClinic in your clinic
Every plan includes a 10-day free trial with no credit card required. Compare plans or send us a message and we will help you choose.