How is my clinic’s patient data protected?
Last updated: 2026-05-26
Patient data is isolated by clinic (your records are only visible to your own team), encrypted both in transit (TLS) and at rest, access-controlled by role, and audited (admins can see who viewed or changed what). For our formal security and privacy policy — including regional specifics — contact support.
The protection layers
- Isolated by clinic — your patient records are only visible to your own team. We do not share across clinics.
- Encrypted in transit — every connection between your browser/app and our servers uses TLS.
- Encrypted at rest — patient data is encrypted on the servers we run.
- Access controlled by role — Admin / Doctor / Staff each have different visibility (see "Who can see what").
- Audit trail — admins can see who in your team viewed or changed records.
What you control
- Who has access — invite and deactivate team members from Settings → Team & Roles.
- What channels are used for outbound messages — SMS, Email, WhatsApp toggles per patient.
- Your account password and 2-factor flow.
- Data export and deletion (see related articles).
Formal policy
For our complete security & privacy policy — including data handling, retention, and regional compliance specifics — contact support@epikdoc.ai. We will share the current document.
Related guides
Was this guide helpful?
Still need help? Choose how you’d like to ask.
Community answers are public and often faster — no account needed. Private tickets to the EpikDoc team require signing in.