Skip to content
Security & Privacy

Patient trust is the whole product.

This page is maintained by MedBiCare to answer common security and privacy questions about the platform. It describes controls we operate today, not certifications by a third party.

Controls in place

How we protect data.

Encryption in transit & at rest

All traffic is served over HTTPS/TLS. Stored data is encrypted at rest using industry-standard providers.

Mandatory two-factor authentication

TOTP-based 2FA is required on every account. Login is rate-limited and sessions are securely managed.

Role-scoped access

Cases are visible only to their author and, on institutional plans, to designated administrators. No cross-tenant data access.

Immutable audit trail

Every query, view, export, and prescription is logged with user, timestamp, and action for internal review.

Reputable cloud infrastructure

MedBiCare is hosted on major cloud infrastructure with hardened networking, isolated environments, and regular backups.

Data-residency awareness

We work with institutional customers to align hosting region and data-flow with local regulatory expectations where possible.

Our principles

How we think about your data.

Minimum necessary data

MedBiCare is designed for de-identified or minimally-identified clinical inputs. Do not enter direct patient identifiers (full name, ID number, phone) unless your institution has explicitly enabled and authorized identified use.

You control your data

You can export your case history at any time and request deletion of your account. Deletion removes personally identifiable account information; anonymized aggregate metrics may be retained for platform quality.

No sale of clinical data

MedBiCare does not sell case data or personal information to third parties. Data is used to deliver the service you've signed up for.

Regulatory alignment

MedBiCare's data-handling practices are designed to align with the Kenya Data Protection Act, 2019. Institutional customers can request a Data Processing Agreement (DPA) covering roles, sub-processors, breach notification, and data-subject rights before rollout.

MedBiCare is not a certified medical device and does not currently hold SOC 2, ISO 27001, HIPAA, or GDPR certifications. Where certification is a procurement requirement, please contact us to discuss timelines and interim compensating controls.

Report a vulnerability

If you believe you've found a security issue, please email security@medbicare.com. We acknowledge reports within 3 business days and coordinate responsible disclosure.

Clinical responsibility

MedBiCare is a clinical decision-support tool. The treating clinician retains full responsibility for diagnosis, prescribing, and patient care. Do not use MedBiCare as the sole basis for a clinical decision.

Need a DPA or security review?

Our team supports institutional procurement and security questionnaires.