This page is maintained by MedCare Clinic to answer common security and privacy questions about our patient portal. It describes our current practices and the controls we have enabled. It is not an independent certification or audit report.
Trust, Security & Privacy
Last updated: 8/2/2026
Authentication & Access Control
Patient accounts require registration with a phone number and a unique Patient ID. Staff accounts are managed separately by clinic administrators. We enforce role-based access so that patients, nurses, admins, and super-admins each see only the tools and data appropriate to their role.
We rely on the authentication and session management provided by our backend platform. Sessions are managed via secure tokens and we do not store plain-text passwords in our application database.
Data Protection
We collect and store patient registration details, appointment records, consultation notes, and billing information. Access to this data is restricted by row-level security policies in the database, scoped to the patient or authorized staff member.
Transcripts and recordings from online consultations are processed to generate summaries and are stored alongside the consultation record. Only the patient and authorized clinic staff can access these records.
Data Collection & Use
We collect the minimum information needed to provide clinic services: personal identifiers (name, phone), medical context (symptoms, allergies, medications), appointment preferences, and billing details.
We do not sell patient data. Data is used only to deliver care, manage appointments, generate bills, and improve the quality of our online consultations.
Cookies & Analytics
We use standard session cookies and local storage to keep you signed in and remember language preferences. We do not use third-party advertising cookies or trackers.
Any analytics we collect are used solely to understand application usage and improve performance. We do not share analytics data with external marketing platforms.
Retention & Deletion
Medical records are retained for as long as required by applicable healthcare record-keeping rules. If you would like to request deletion of non-medical account data, please contact us using the email below. Note that we may be required to retain certain healthcare records by law.
Privacy Requests & Contact
For questions about your data, correction requests, or deletion requests, please email us at the address provided by your clinic administrator. We will respond within a reasonable timeframe.
Security Concerns & Incident Reporting
If you discover a security issue or have a vulnerability to report, please contact your clinic administrator directly. We review all reports and take appropriate action to protect patient data.
Shared responsibility
MedCare Clinic operates the application and its data practices. The underlying platform provides hosting, authentication infrastructure, and database services. Platform-level security features are managed by the platform provider. MedCare Clinic is responsible for application-level access controls, data handling, and privacy practices described on this page.