We're in beta — first 50 clinics get 3 months free. Limited spots left.🚀 Early Access
Security

Security at CareNexa

Patient data is the most sensitive data in the world. Here's exactly how we protect it across ClinicOS, MediCore HIS and ClinicBot.

Last updated: June 1, 2026

🛡️

Our security commitment

CareNexa handles sensitive health data for thousands of patients. We treat security not as a checkbox but as a core product value. Every feature is designed with security and privacy in mind from day one.

Security practices

🔐

Encryption at rest

All data encrypted with AES-256 on MongoDB Atlas India (Mumbai region).

🔒

Encryption in transit

TLS 1.3 enforced on all API and web connections. HTTP redirects to HTTPS.

🪪

JWT Authentication

Stateless JWT tokens with short expiry. Refresh token rotation on every session.

🧱

Role-based access

Granular roles: Doctor, Receptionist, Nurse, Lab, Pharmacy, Admin, Patient. Each sees only what they need.

📋

Audit logs

Every critical action (login, data edit, ABHA link, invoice creation) is logged with user, timestamp and IP.

🌐

Data isolation

Each clinic and hospital is a completely isolated tenant. No cross-tenant data access is possible.

🔑

Password hashing

All passwords hashed with bcrypt (12 rounds). Plain passwords are never stored.

🛡️

Rate limiting

API rate limiting on all endpoints. Brute-force protection on login and OTP flows.

🏥

ABHA consent trail

Every ABHA verification and link is logged with patient consent, staff member, method and timestamp.

Compliance & standards

IT Act 2000

Data processing and storage per Indian IT laws

Compliant

DPDP Act 2023

Digital Personal Data Protection Act compliance

Compliant

ABDM / ABHA M1

MediCore HIS certified for ABDM Milestone 1

Compliant

TLS 1.3

All data in transit encrypted

Enforced

AES-256

All data at rest encrypted

Enforced

bcrypt (12 rounds)

All passwords securely hashed

Enforced

Infrastructure

Database: MongoDB Atlas with data residency in Mumbai, India. Automated daily backups with 7-day retention. Point-in-time recovery available.

Application hosting: Node.js/Express backend. Next.js frontend. Deployed on cloud infrastructure with auto-scaling.

Uptime: 99.5% monthly uptime SLA. Real-time status monitoring. Incident response within 30 minutes for critical issues.

Vulnerability Reporting

If you discover a security vulnerability in CareNexa products, please report it responsibly to security@carenexa.in. We aim to respond within 48 hours and will credit responsible disclosures.

Please do not publicly disclose vulnerabilities until we have had a chance to address them.

Security questions?

Our team is available for security reviews and compliance queries.

security@carenexa.in →