Start with identity and authorisation
Review clinician authentication, patient/case ownership, role boundaries, administrative access and how protected records remain inaccessible across tenants or cases.
Clinician-controlled evidence
Security due diligence
Security review should begin with what data enters the system, where it travels, who can access it, how access is recorded, how long it remains and what happens when a clinic leaves. SheldonDx provides current answers through due diligence rather than unsupported certification claims on a landing page.
Can your team draw the data flow and name the owner of every access decision?
Review clinician authentication, patient/case ownership, role boundaries, administrative access and how protected records remain inaccessible across tenants or cases.
Ask which infrastructure and model providers process which fields, the deployment regions, contractual safeguards and whether sensitive data is minimised before any external call.
Clarify retention controls, backups, deletion workflow, audit logs, incident response, exports and the evidence available when a clinic ends service.
Request the current dated security and compliance statement. This page intentionally does not imply certifications that may not apply to the current release.
Yes. Use the contact route to request the current architecture, processor and control information appropriate to the pilot or contract.
Get the dated security information your governance or procurement review requires.
Email to request the security pack