Security and compliance

Health data, handled the way regulators expect.

Siderina is a clinical records system first. Compliance support is not a badge on a website; it is how the product is built.

How it is built

Six things that are true of every clinic on Siderina.

  • Clinical record-keeping

    Clinical records, consent and every change are versioned and audit-tracked, designed to support clear, accurate and secure record-keeping aligned with HCPC, GOsC, GCC and professional-body expectations. Notes lock on signing; completed forms stay pinned to the exact version the patient signed.

  • An append-only audit trail

    Every change to a clinical record lands in an append-only audit trail with a per-record history view, so there is always an answer to who changed what, and when.

  • Access control

    Every staff sign-in is protected by multi-factor authentication, with recovery codes and step-up checks before sensitive actions. Five staff roles, from practitioner to receptionist, see only what their job needs, and idle sessions expire automatically.

  • UK GDPR, special category

    Health data is special-category data under UK GDPR. Siderina is designed to support clinics with their obligations: UK hosting, strict access controls, audit trails and a Data Processing Agreement, with the ICO complaints route surfaced to patients. Data minimisation and retention are designed in.

  • UK data residency

    All patient data is hosted in the London region. No health data leaves the UK without legal review. Encrypted, off-site, UK-resident backups are taken and restore-tested, not just assumed to work.

  • Isolated by construction

    Every clinic’s data is isolated by row-level security in the database itself, not only in the application. One clinic can never see another’s records.

At a glance

The facts, plainly stated.

Data region
United Kingdom (London)
Record-keeping
Aligned with HCPC, GOsC and GCC expectations
Staff sign-in
Multi-factor authentication, enforced for every staff account
UK GDPR
Special-category safeguards, and a Data Processing Agreement on request
Backups
Encrypted, UK-resident, restore-tested
Operator
Bailey & Prosper Holdings Ltd

Talk to us about compliance.

We are happy to walk your data protection officer or practice manager through how it works, and to share the Data Processing Agreement before you commit.