Security
Healthcare data deserves enterprise-grade protection.
Controls are part of the platform and configurable to hospital policy and local regulation. We describe what the product does; certifications are listed only when issued.
Identity and access
Role-based permissions
Access by role, department, location and data category, with detailed permissions down to individual actions and fields.
Multi-factor authentication
MFA for privileged and remote users, enforceable by policy per role.
Single sign-on
SAML and OIDC single sign-on with the hospital's identity provider, where configured.
Access controls
Session policies, device and network restrictions, and break-glass access that is logged and reviewed.
Data protection
Encryption
Encryption in transit and at rest for application data, files and backups.
Patient consent workflows
Consent capture, purpose and withdrawal recorded against the patient record and enforced in sharing workflows.
Configurable retention
Retention and archival rules set per record type to match local regulation and hospital policy.
Secure API architecture
Scoped keys, rate limits, signed webhooks and full request logging for every integration.
Visibility
Audit trails
Immutable logs of who viewed, changed, printed or exported what, and when.
User activity monitoring
Unusual access patterns surfaced to administrators, such as bulk record views outside a user's department.
Resilience
Data backup
Automated, encrypted backups with periodic restore testing.
Disaster recovery architecture
Separate recovery region and documented recovery objectives for cloud deployments.
Certifications and attestations
Certifications and attestations are listed here only once issued and verified. None are claimed at this time.
Deployment options
The security model is the same in each. What changes is where the platform runs.
Cloud
Managed deployment in a region chosen for data residency, with continuous updates.
On-premise
Available where hospital policy requires it, with managed update cycles. Confirm supported configurations with our team.
Hybrid
Cloud application with on-site components for imaging, device interfaces or offline continuity, where supported.
Shared responsibility
RevSyn Care secures the platform, its infrastructure and the application. Hospitals control who has access, what consent is collected and how long records are retained, using the controls above. Both sides are documented in the security overview we share during evaluation.
To report a vulnerability, write to hello@revsyncare.com. We acknowledge reports within two working days.
Send this page to your CIO or IT committee.
Then book a technical session on architecture, access control and audit.