Skip to content
AfriHealthSys AfriHealthSys

Security

How AfriHealthSys protects tenant data, clinical workflows, and access across clinics and hospital networks.

Last updated July 14, 2026

Healthcare software must earn trust every day. This page summarises AfriHealthSys security practices for buyers, IT leads, and compliance reviewers. For a detailed questionnaire, penetration test summary, or subprocessors list, contact support@afrihealthsys.com.

Security principles

  • Least privilege — users and staff only receive the access required for their role.
  • Tenant isolation — organisation data is separated so one facility cannot read another facility’s records.
  • Auditability — sensitive clinical and administrative actions are recorded for investigation and accountability.
  • Defence in depth — transport encryption, application controls, monitoring, and operational process work together.

Application controls

Authentication & sessions

User access to the product application requires authenticated sessions. Customer administrators manage invitations, role assignment, and offboarding. Workspace selection confines activity to the organisation and branch context the user is authorised to use.

Authorisation

Role-based permissions govern patients, appointments, encounters, nursing, radiology, laboratory, pharmacy, billing, claims, reports, settings, and website administration. Module enablement at the tenant level further limits unused capability.

Audit logging

Operationally significant events (such as clinical documentation, billing, claims, and administrative changes) can be reviewed through audit trails to support incident response and internal governance.

Data protection

  • Encryption in transit — public website and product traffic are served over TLS.
  • Encryption at rest — database and disk encryption are applied at the infrastructure layer according to hosting configuration.
  • Backups — regular backups support recovery objectives defined with customers and operations.
  • Secrets management — application secrets and credentials are kept out of source control and injected via environment configuration.

Infrastructure & operations

  • Production hosts are hardened and limited to necessary inbound services.
  • Application and server logs are monitored for abnormal behaviour.
  • Dependency and framework updates follow a regular maintenance cadence.
  • Access to production systems by AfriHealthSys personnel is restricted and reviewed.

Customer responsibilities

Security is shared. Facilities should:

  • Assign roles carefully and revoke access when staff leave.
  • Use strong passwords and protect shared workstations on the floor.
  • Limit export of patient lists and printouts according to internal confidentiality policy.
  • Notify AfriHealthSys promptly of suspected account compromise.

Incident response

We investigate security incidents affecting confidentiality, integrity, or availability of the service. Where a customer tenant is reasonably believed to be impacted, we notify the primary facility contacts as required by the customer agreement and applicable law, then work toward containment, remediation, and post-incident review.

Procurement documents

Available on request: security questionnaire responses, summary architecture overview, subprocessors list, and data processing terms. Start with Contact or email support with your facility name and requested packet.

Need something more specific?

Request a security questionnaire, DPA, or facility agreement addendum from support@afrihealthsys.com.