Skip to content

Security & compliance

Health data, handled the way health data should be.

Medlitics carries some of the most sensitive information a person has. These are the commitments and the design principles behind how we protect it — written plainly, so a clinician, an administrator or a member can check them.

Data protection and consent

Personal and health data is handled under the data-protection law that applies where the member is — Nigeria's NDPA and equivalent regimes elsewhere. Consent is captured explicitly at onboarding, and a member can see and manage what they have agreed to.

  • Consent captured and revocable per member
  • Regional regimes, configured per market
  • Data minimisation — we collect what a purpose needs

Verified access, by role

Every clinical actor is verified before they can touch a patient. Practitioners submit credentials for review, and their licensing is checked against the jurisdictions they are permitted to practise in. Access to any record is scoped to a role and a relationship.

  • Credential review before a practitioner goes live
  • Cross-border licensing validated at verification
  • Role-scoped access — no record without a reason

Integrity, online and off

The patient app is offline-first. Readings and actions are stored on the device and synced when a connection returns, de-duplicated by a per-action identifier so nothing is double-counted and nothing is lost — a design target of no loss on queued readings.

  • Durable local queue with per-action identifiers
  • De-duplicated, conflict-resolved sync
  • Every record owned by exactly one source of truth

In transit and at rest

Traffic runs over standard TLS, and money is always stored as an amount and a currency so nothing is misread across markets. Access to systems is logged, and sensitive actions are auditable.

  • TLS for data in transit
  • Auditable access to sensitive actions
  • Currency-safe money handling across regions

Where the machine stops and a clinician starts.

Meddy, our AI assistant, explains a member's own trends and helps them prepare for a conversation. It does not diagnose, it does not prescribe, and it cannot change a care plan. Every clinical decision belongs to a verified practitioner. Medlitics supports clinical care — it does not replace it, it is not an EHR replacement, and it does not take custody of insurance funds.

Responsible disclosure

Found something? Tell us.

If you believe you have found a security issue in Medlitics, we want to hear from you before anyone else does. Reach our team and we will respond quickly.

security@medlitics.com

Reviewing Medlitics for your organisation?

We work with hospitals, clinics and insurers through their security and data-protection reviews. Tell us what your process needs and we will meet it.