Encryption
Sensitive EHR payloads and clinical attachments use AES-256-GCM encryption at rest. Transport encryption is required in production.
Access control
Tenant boundaries, role permissions and patient-specific authorization restrict access. Sensitive document reads are authenticated and audited.
Secure development
DiagMed applies validation, rate limiting, secure session cookies, dependency reviews and production build verification.
Responsible disclosure
If you believe you found a vulnerability, use the contact form with the subject Security report. Do not access, copy or modify data that is not yours.