Security, privacy and AI · last reviewed 2 October 2026

We will not show you a badge we have not earned.

Clinic software holds some of the most sensitive information a person shares. This page says what is established about ClinicJourney today, what is not yet, and the questions you should put to us, or to any vendor.

Early access. No certifications yet.

ClinicJourney is in early access. It does not hold third-party security certifications. The controls listed below as “to confirm” will be verified and documented before any clinic stores real patient information in ClinicJourney.

We publish this openly because many vendors in this category display compliance badges with nothing behind them. You should be able to check what a vendor tells you.

Questions to ask any vendor, and our answers as of 2 October 2026.

Ask every vendor you evaluate for evidence: a report, a named auditor, a dated document, a signed agreement. A logo is not evidence.

Security and privacy questions with ClinicJourney's current answers and status
QuestionOur answerStatus
Do you hold third-party security certifications (for example SOC 2 or ISO 27001)? No. ClinicJourney does not hold any third-party security certification today. We will not display a badge until a report or certificate exists, and we will publish its date here. None held
Are you “HIPAA compliant”, “PHIPA compliant” or “GDPR compliant”? We do not use these labels. There is no official certification for HIPAA or PHIPA, and compliance depends on how the clinic uses a system as well as on the vendor. We will describe our controls and agreements instead. Not claimed
Is data encrypted in transit and at rest? To be confirmed before launch. We will state the method here when it is verified. To confirm
Where is data hosted, and by whom? To be confirmed. We will name the hosting provider and region, and list our sub-processors. To confirm
Can each role see only what it needs? The product is designed around roles (front desk, practitioner, medical director, patient). How access is enforced will be documented here before launch. To confirm
Is there an audit trail of who viewed or changed a record? To be confirmed. To confirm
Is multi-factor authentication available for staff? To be confirmed. To confirm
Can we export all our data, and delete it when we leave? We believe clinics should be able to do both. How export and deletion work, and how long backups are kept, is to be confirmed. To confirm
Will you sign a business associate agreement (US) or a data processing agreement (UK, EU, Canada)? To be confirmed. Agreements will be reviewed by counsel before we offer them. To confirm
How will you tell us about a security incident? To be confirmed, including how quickly. We will publish the commitment here. To confirm

Your clinic stays in charge of your patients’ information.

Under health privacy laws in Canada, the United States, the United Kingdom and the European Union, the clinic is generally the custodian or controller of patient information. A software vendor acts on the clinic’s behalf, under a written agreement.

That means privacy is shared. The vendor is responsible for securing the platform and handling data only as instructed. The clinic decides who on the team has access, what is collected, and how patients are informed. We will set out this split in writing before any clinic stores patient data with us.

This is general information, not legal advice. Your obligations depend on where you practise.

How ClinicJourney is designed to treat patient data.

These are design commitments, not verified controls. Each will be confirmed against the product before launch.

  1. Each role sees what it needs.

    The front desk does not need a clinical note to chase a questionnaire.

  2. The record shows who did what, and when.

    Sign-offs, signatures and changes carry a name and a time.

  3. Patient photos stay in the clinical record.

    With the uses each patient agreed to, recorded next to them.

  4. Your data is yours.

    You should be able to export it, and to have it deleted when you leave.

  5. No advertising use, no sale of data.

    Patient information is used to run your clinic’s journeys, and for nothing else.

Software that supports professionals. It does not replace their judgement.

ClinicJourney is practice software. It does not diagnose, recommend treatments, calculate doses, analyse photos, assess symptoms, or make clinical decisions. Clinical decisions are made by your practitioners.

  • Treatment plans record what the practitioner decided.
  • Charting captures what the practitioner did.
  • Marked answers are questions your clinic chose to flag for a person to review.
  • Follow-up sends messages your clinic wrote, and routes replies to a person.

No AI features are described on this site. If that changes, these are the rules.

Nothing on this website depends on artificial intelligence. If ClinicJourney adds AI to help with drafting or summarising, we commit to the following, and we will publish the details here first.

  1. AI drafts. A person approves.

    Nothing would be sent to a patient or saved to a record until a member of your team reviews and approves it.

  2. AI never makes clinical decisions.

    No diagnosis, no treatment recommendations, no triage of patient replies.

  3. Drafts show their source.

    If a draft is based on the record, you can see which part.

  4. We say where data goes.

    Which provider processes it, in which region, and whether it is used to train models.

  5. You can switch it off.

    For your whole clinic.

Ask us anything about security or privacy.

If your clinic, your medical director or your IT adviser has a question, send it. We will answer in writing, including when the answer is “not yet”.