Patient trust is the whole product.
This page is maintained by MedBiCare to answer common security and privacy questions about the platform. It describes controls we operate today, not certifications by a third party.
How we protect data.
Encryption in transit & at rest
All traffic is served over HTTPS/TLS. Stored data is encrypted at rest using industry-standard providers.
Mandatory two-factor authentication
TOTP-based 2FA is required on every account. Login is rate-limited and sessions are securely managed.
Role-scoped access
Cases are visible only to their author and, on institutional plans, to designated administrators. No cross-tenant data access.
Immutable audit trail
Every query, view, export, and prescription is logged with user, timestamp, and action for internal review.
Reputable cloud infrastructure
MedBiCare is hosted on major cloud infrastructure with hardened networking, isolated environments, and regular backups.
Data-residency awareness
We work with institutional customers to align hosting region and data-flow with local regulatory expectations where possible.
How we think about your data.
Minimum necessary data
MedBiCare is designed for de-identified or minimally-identified clinical inputs. Do not enter direct patient identifiers (full name, ID number, phone) unless your institution has explicitly enabled and authorized identified use.
You control your data
You can export your case history at any time and request deletion of your account. Deletion removes personally identifiable account information; anonymized aggregate metrics may be retained for platform quality.
No sale of clinical data
MedBiCare does not sell case data or personal information to third parties. Data is used to deliver the service you've signed up for.
MedBiCare's data-handling practices are designed to align with the Kenya Data Protection Act, 2019. Institutional customers can request a Data Processing Agreement (DPA) covering roles, sub-processors, breach notification, and data-subject rights before rollout.
MedBiCare is not a certified medical device and does not currently hold SOC 2, ISO 27001, HIPAA, or GDPR certifications. Where certification is a procurement requirement, please contact us to discuss timelines and interim compensating controls.
If you believe you've found a security issue, please email security@medbicare.com. We acknowledge reports within 3 business days and coordinate responsible disclosure.
MedBiCare is a clinical decision-support tool. The treating clinician retains full responsibility for diagnosis, prescribing, and patient care. Do not use MedBiCare as the sole basis for a clinical decision.
Need a DPA or security review?
Our team supports institutional procurement and security questionnaires.