Information security
Patient data opens only to authorized people
Health data is sensitive personal data. To open a patient file in HekimBis, the user's role, branch, care relationship with the patient and purpose of access must all line up, and every access is written to the audit log.

Health data stays in Türkiye and every organization stays within its own boundary
Production health data is kept in Türkiye. Encrypted backups and point-in-time recovery copies stay inside the same data residency boundary.
Each organization works within its own boundary: one organization's patients, records, finances and staff are never opened to another. Even between two legal entities under the same account, patient or record access does not appear on its own.
Which organization and branch you are working for is not taken from what the client sends; the active scope is resolved on the server for every request from membership and policy records. Web and mobile clients connect over encrypted links and pass through role and context checks.
Patient notifications carry general content and a secure, identity-verified link; health information is never written into the message text.
What happens when a patient file is opened?
The file opens once the plan, role and context checks have all passed. Whatever the outcome, the request is written to the audit log.
Audit record
Who accessed what, when, and why is written in a tamper-resistant record.
- The process is complete here.
All steps
- 01 Request (User) A user asks to open a patient file.
- 02 Role check (Role) The user's membership and role permission are verified.
- 03 Context check (Context) Branch membership, data sensitivity, care relationship, purpose, and time are evaluated together.
- 04 Allowed (Context) The record opens once the role and context checks pass.
- 05 Audit record (Audit) Who accessed what, when, and why is written in a tamper-resistant record.
Alternative path from 03 Context check; it returns to the main flow at 05 Audit record.
- 03a No care relationship (Context) The normal path closes.
- 03b Emergency access request (User) Justification, duration, and extra verification are entered.
- 03c Time-limited access (Context) Narrow access opens, responsible staff are notified, and a separate audit record and later review are created.
05 Audit record

Our support team reaches a patient record only with your approval
HekimBis staff have no standing access to patient records. Support opens when a recorded request exists and the clinic's authorized person approves its scope and duration.
In a support session patient information is masked, and export and bulk search are off by default. When the time runs out, access ends on its own, and every action is written to the audit log with a summary the clinic can see.
If a physician without a care relationship needs the file in an emergency, access opens for a limited time with a reason and additional verification, produces its own audit entry and is reviewed afterward.
Six controls that protect everyday work
- Encryption
- Data is encrypted both in transit and at rest. Keys and secrets are rotated at regular intervals.
- Backup and restore
- Backups are encrypted, the system can return to a specific point in time, and restores are actually rehearsed. Backup retention never exceeds the retention rules of live data; after a restore, reconciliation keeps deleted or canceled data from becoming active again.
- Masking
- Personal and health data is masked in logs, monitoring and support tools. Passwords, keys and clinical content are not written to general logs.
- Secure files
- Uploaded files are scanned, download links are short-lived and tied to the organization, and the file type is verified at upload.
- Abuse protection
- Sign-in attempts, verification codes and form submissions are protected by rate limits, and suspicious patterns are blocked.
- Incident management
- A defined procedure covers security incidents and data breaches, with release rollback and an alert path; responsibilities are assigned in advance.
Which data follows which rule?
Access, correction and retention are set separately for each class of data.
Signed clinical records, results, reports and consents
Authorized roles with a care relationship have access. Corrections are made through a correction entry that preserves the earlier version; permanent deletion does not exist. Retention and disposal follow the approved retention policy.
Patient identity and contact details, operational records
Users within role, branch and purpose scope have access. An authorized user can correct them, and access narrows immediately when membership ends. Data is kept while the purpose and legal obligations last.
Finance and subscription records
Only the finance role has access. Corrections follow the policy version, and card data is not stored in HekimBis. Retention depends on financial and legal policy.
Documents and images
Access is limited by care relationship, organization and branch. Files are versioned, and sharing and export are recorded. They are kept under retention and legal hold rules.
Audit and security records
A narrow group of authorized users can read them. Entries are append-only and cannot be changed; retention follows the policy version.
Trial data
A trial account holds sample data only. Writing closes when the period ends, and after a waiting period the account data is deleted automatically.
The clinic is the data controller, HekimBis supplies the tools
Your clinic is the data controller for its own patients, and HekimBis acts as the data processor. The software does not transfer responsibility; it provides the tools you need to meet your KVKK obligations.
The version of the privacy notice and the time it was shown to the patient are recorded. Explicit consent is collected only for the processing that needs it, as a separate action, and kept apart from clinical consent. When consent is withdrawn, the affected processing becomes visible.
Patient requests are tracked through registration, identity verification, review and response, and the response time follows the statutory period. A record under a legal retention obligation is not deleted by a deletion request; records outside that scope move to a restricted archive.
When an organization closes, an encrypted export with an audited scope is prepared for the authorized owner.
Frequently asked questions about security
Where is health data stored?
Production health data is kept in Türkiye, and backups stay inside the same data residency boundary.
Can another organization see a clinic's data?
No. Data is separated by organization; even between different legal entities under the same account, patient or record access does not appear on its own. Sharing requires its own legal basis, purpose and audit record.
Can HekimBis employees see patient files?
There is no standing support access. Support opens only with a recorded request, the approval of the clinic's authorized person, a narrow scope, a time limit and masking, and every access is written to the audit log with a summary visible to the clinic.
Can a physician without a care relationship open a file in an emergency?
Emergency access opens for a limited time with a reason, a duration and additional verification, produces a separate audit entry and is reviewed afterward. It cannot be used for routine work or convenience.
Can I still reach my data when my plan ends?
Yes. Lowering or ending a plan does not delete data; secure access to the clinical history, the audit log and authorized export are kept. Security is never reduced in any plan.
Do you hold security certifications?
Verified certifications are listed on this page with their scope and validity. For details, get in touch with us.
Keep reading
Related pages
Features
Software guides
Integrations
Company and support
- KVKK complianceHow personal health data is processed, data subject rights, and requests.
- TechnologyHosting in Türkiye, redundancy, restore drills, and monitoring.
- KVKK privacy noticeOur privacy notice as data controller under KVKK, Law No. 6698.
- Data processing agreementThe agreement where the clinic is controller and HekimBis is processor.
Guides
- The Benefits, Risks and Selection Criteria of Cloud-Based Healthcare SoftwareWhat do you gain and what should you question when moving from desktop software to a cloud-based clinic system? A checklist on data location, backup, outages and device connectivity.
- A Practical KVKK and Health Data Compliance Guide for ClinicsHealth data is special-category personal data. The difference between the privacy notice, explicit consent and clinical consent, access control, data subject requests and breach notification.

