← All whitepapers

Whitepaper

Security & Compliance Technical Specification

By Dr Youssef Ghaly and Dr Mostafa Helmy · Published June 2025

Encryption HIPAA GDPR Access control Audit logging Incident response

Abstract

A technical specification of ClinixSummary's security architecture, written for compliance officers, CISOs, and CTOs, covering encryption standards, access controls, audit logging, and HIPAA/GDPR technical implementation details. The paper presents security and compliance as foundational architectural principles rather than added features, and concludes by inviting security teams to review its detailed documentation and schedule review sessions with the compliance team.

What the paper covers

Encryption in transit and at rest

All data in transit uses TLS 1.2 or higher (TLS 1.3 preferred), with certificate pinning on mobile clients and mutual TLS between internal services. Persistent storage uses AES-256 encryption with KMS/HSM-backed key management and 90-day key rotation with zero-downtime re-encryption.

Audio purged after note generation

Audio recordings are encrypted immediately upon capture and permanently deleted via cryptographic erasure as soon as the clinical note has been generated. The paper states no audio data is ever retained beyond note generation.

Authentication, RBAC, and data isolation

Authentication options include email/password with mandatory MFA (TOTP or WebAuthn), SAML 2.0 SSO for enterprises, and OAuth 2.0 with scoped, short-lived tokens. Fine-grained RBAC offers four default roles (Clinician, Reviewer, Administrator, Billing Manager) plus custom roles, with logically isolated multi-tenant data partitions and optional physically isolated database instances for enterprise customers.

Tamper-evident audit logging

Every action — authentication, data access, administrative changes, API calls, and system events — is recorded in a tamper-evident audit trail stored in append-only, cryptographically signed storage. Logs are retained for a minimum of 7 years and are available to organisation administrators through the ClinixSummary Console.

Regulatory coverage across jurisdictions

The paper describes HIPAA measures (BAAs, the required Administrative, Physical, and Technical Safeguards, risk assessments, workforce training, breach notification) and GDPR measures (lawful basis documentation, DPIAs, data subject rights, DPAs, EU data residency options). It also cites PIPEDA/PHIPA, CCPA, and the Australian Privacy Act, and says UK medical device registration (MHRA) is being pursued.

Incident response and breach notification

A documented incident response plan covers detection, containment, eradication, recovery, and post-incident review, backed by 24/7 security monitoring with automated anomaly detection. Customers are notified within 72 hours of any confirmed data breach per GDPR, or without unreasonable delay per HIPAA.

Figures and statements reflect the paper as published in June 2025.

Read the full paper

Assured by ClinixQM Quality Management Process