Security & Privacy

How is my clinic’s patient data protected?

Last updated: 2026-05-26

Patient data is isolated by clinic (your records are only visible to your own team), encrypted both in transit (TLS) and at rest, access-controlled by role, and audited (admins can see who viewed or changed what). For our formal security and privacy policy — including regional specifics — contact support.

The protection layers

  • Isolated by clinic — your patient records are only visible to your own team. We do not share across clinics.
  • Encrypted in transit — every connection between your browser/app and our servers uses TLS.
  • Encrypted at rest — patient data is encrypted on the servers we run.
  • Access controlled by role — Admin / Doctor / Staff each have different visibility (see "Who can see what").
  • Audit trail — admins can see who in your team viewed or changed records.

What you control

  • Who has access — invite and deactivate team members from Settings → Team & Roles.
  • What channels are used for outbound messages — SMS, Email, WhatsApp toggles per patient.
  • Your account password and 2-factor flow.
  • Data export and deletion (see related articles).

Formal policy

For our complete security & privacy policy — including data handling, retention, and regional compliance specifics — contact support@epikdoc.ai. We will share the current document.

Related guides

Was this guide helpful?

Still need help? Choose how you’d like to ask.

Community answers are public and often faster — no account needed. Private tickets to the EpikDoc team require signing in.