CCChartChronicle HealthEMR · HMIS
HomePlatformPricingSecurityContactSign inStart free trial

Security

Security & data protection

Your patients trust you with the most sensitive information they have. ChartChronicle Health is built so you can hold that trust — and prove you have held it.

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAcceptable Use PolicySub-processorsSecurity
Healthcare privacy and security team reviewing how patient records are kept separate, who accessed them, and which staff can see what
Your patients stay yoursNo other hospital can reach your records - enforced twice over, in the application and in the database itself.
Encrypted end to endProtected in transit, at rest, and on every phone and tablet in the field.
Only the access the job needsEach role sees exactly its own patients; withdraw access and it ends immediately, everywhere.
Two-step sign-inRequired for senior roles, with automatic lockout after repeated failed attempts.
An audit trail that cannot be editedEvery record access is sealed, so you can prove nothing was quietly changed.
Patients in controlPatients can read their own record, see who opened it, and manage their consent.

Your records are yours alone

Every clinical record belongs to one organisation and facility. Another hospital on the platform cannot see your patients - and cannot even discover that a given patient exists, because a request outside your organisation returns “not found” rather than hinting at data it will not show. That boundary is enforced twice: once in the application, and again by the database itself, so a single mistake in code cannot expose your records. It holds across facilities, states and countries alike.

Encryption

Data is encrypted in transit (TLS) and at rest. Passwords are stored only as salted hashes, multi-factor secrets are encrypted, and offline data cached on devices for community/CHW workflows is encrypted on the device.

Each person sees only what their job requires

Access follows the role, not the person - a ward nurse, a pharmacist and a finance officer each see a different view of the same patient. When someone changes role or leaves, you withdraw their access once and it ends everywhere immediately, including on any phone or tablet already holding offline data. Senior roles must use two-step sign-in, and repeated failed attempts lock the account rather than letting an attacker keep guessing.

Prove what happened, and let patients see it too

Every time a clinical record is opened it is written to an audit trail that is sealed against later editing - so when a regulator, a board or a patient asks who saw a record, you can answer with evidence rather than assurance. Emergency access to a record outside someone's normal remit is allowed when a life depends on it, but it demands a reason and is reviewed afterwards. Patients can read their own record, see exactly who opened it and when, ask for corrections, and withdraw consent - the transparency rights Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation 2019 (NDPR) gives them, delivered rather than promised.

Keeps working when the connection does not

Community health workers and rural clinics keep registering patients, recording visits and raising referrals with no signal at all - everything is held safely on the device and files itself the moment a connection returns. Scans and documents are kept in durable cloud storage rather than on a single server, reporting runs against a separate copy so clinical screens stay fast at peak, and backups are not merely taken but regularly rehearsed, so a recovery is a known quantity rather than a hope.

Data-protection alignment

The platform is built around Nigeria's data-protection framework - Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation 2019 (NDPR), supervised by the NDPC - including data-subject access and breach-notification workflows, and its architecture supports other countries' data-protection laws as those markets open. We describe our handling of personal data in the Privacy Policy and our processing commitments in the Data Processing Agreement. We continue to mature our independent assurance posture; we do not claim certifications we do not hold.

Responsible disclosure

If you believe you have found a security vulnerability, please report it privately to hello@chartchronicle.com. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure, and that you do not access, modify or delete data that is not yours. We will acknowledge legitimate reports and keep you informed.

Contact

Security questions, due-diligence requests or our security documentation: hello@chartchronicle.com or contact our team.

ChartChronicle Health

Multi-facility EMR & HMIS for African health systems.

chartchronicle.com

ChartChronicle Health Technologies Limited · RC 9585931 · SCUML-registered (AML/CFT)
Kilometer 10, Plot 6, Amugbekun Street, Apata, Ibadan, Oyo State, NigeriaRegistered with the Nigeria Data Protection Commission (NDPC) as a data controller and data processor.

ProductPlatformModulesPricingSecurityCountries
CompanyContact usTalk to salesRequest a demoGet support
LegalTerms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAcceptable UseSub-processors
© 2026 ChartChronicle Health Technologies Limited. All rights reserved.Terms·Privacy·Cookies