Security

How a medical record is protected in Medalyt. These are measures already in place, not intentions.

Last updated: September 22, 2026

Every practice, isolated

Separation between clinics does not depend on the code remembering to filter: the database itself rejects any query that tries to read another practice’s rows. A programming mistake cannot expose one clinic’s patients to another.

Permissions by role

Each person signs in with their own account and sees only what their role allows. Front-desk staff can schedule and take payment without reaching the clinical history. Permissions are granted per clinic: someone working at two practices does not carry one’s permissions into the other.

Signed prescriptions

Every prescription is signed with a 2048-bit RSA private key that never leaves the server. The printed QR leads to a public page where anyone — a pharmacy, the patient — checks that the prescription is authentic and unaltered. Change one letter and verification fails.

Encryption

All traffic travels over HTTPS and data is stored encrypted at rest. Passwords are not stored: only a one-way cryptographic digest is kept, so nobody at Medalyt can read anyone’s password.

Session control

One active session per user and automatic sign-out on inactivity, so a screen left behind in a consulting room does not stay open.

Audit log

Every relevant change is recorded with who made it, when, and exactly what changed. The log cannot be edited from the application.

Backups

The database is backed up automatically and continuously, with point-in-time restore.

Reporting a problem

If you find a vulnerability, write to soporte@medalyt.com before publishing it. We answer and fix; we do not pursue anyone reporting in good faith.