Security
Security & data protection
Your patients trust you with the most sensitive information they have. ChartChronicle Health is built so you can hold that trust — and prove you have held it.

Your records are yours alone
Every clinical record belongs to one organisation and facility. Another hospital on the platform cannot see your patients - and cannot even discover that a given patient exists, because a request outside your organisation returns “not found” rather than hinting at data it will not show. That boundary is enforced twice: once in the application, and again by the database itself, so a single mistake in code cannot expose your records. It holds across facilities, states and countries alike.
Encryption
Data is encrypted in transit (TLS) and at rest. Passwords are stored only as salted hashes, multi-factor secrets are encrypted, and offline data cached on devices for community/CHW workflows is encrypted on the device.
Each person sees only what their job requires
Access follows the role, not the person - a ward nurse, a pharmacist and a finance officer each see a different view of the same patient. When someone changes role or leaves, you withdraw their access once and it ends everywhere immediately, including on any phone or tablet already holding offline data. Senior roles must use two-step sign-in, and repeated failed attempts lock the account rather than letting an attacker keep guessing.
Prove what happened, and let patients see it too
Every time a clinical record is opened it is written to an audit trail that is sealed against later editing - so when a regulator, a board or a patient asks who saw a record, you can answer with evidence rather than assurance. Emergency access to a record outside someone's normal remit is allowed when a life depends on it, but it demands a reason and is reviewed afterwards. Patients can read their own record, see exactly who opened it and when, ask for corrections, and withdraw consent - the transparency rights Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation 2019 (NDPR) gives them, delivered rather than promised.
Keeps working when the connection does not
Community health workers and rural clinics keep registering patients, recording visits and raising referrals with no signal at all - everything is held safely on the device and files itself the moment a connection returns. Scans and documents are kept in durable cloud storage rather than on a single server, reporting runs against a separate copy so clinical screens stay fast at peak, and backups are not merely taken but regularly rehearsed, so a recovery is a known quantity rather than a hope.
Data-protection alignment
The platform is built around Nigeria's data-protection framework - Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation 2019 (NDPR), supervised by the NDPC - including data-subject access and breach-notification workflows, and its architecture supports other countries' data-protection laws as those markets open. We describe our handling of personal data in the Privacy Policy and our processing commitments in the Data Processing Agreement. We continue to mature our independent assurance posture; we do not claim certifications we do not hold.
Responsible disclosure
If you believe you have found a security vulnerability, please report it privately to hello@chartchronicle.com. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure, and that you do not access, modify or delete data that is not yours. We will acknowledge legitimate reports and keep you informed.
Contact
Security questions, due-diligence requests or our security documentation: hello@chartchronicle.com or contact our team.