How we protect Clinic and patient data, in plain terms
A Clinic's trust rests on keeping patient information safe. Here is what RevisitMD actually does to protect it, described plainly, not as a certification we hold.
Every request in our backend is scoped to the Clinic that owns the data. One Clinic's patients, visits, and messages are never visible to another Clinic.
All traffic to and from RevisitMD runs over HTTPS, so data moving between your browser and our servers is encrypted on the wire.
Patient records live in a database that only our own backend can reach. It is not exposed directly to the internet.
Patient messages are sent through Meta's own WhatsApp Cloud API, the official channel WhatsApp provides to businesses, not a scraped or unofficial integration.
Account passwords are stored using industry-standard hashing. We never store or can see a password in plain text.
Patient data is backed up nightly to separate cloud storage, so a problem with our server doesn't mean losing a Clinic's records.
Patient records belong to the Clinic that created them, not to RevisitMD. We process that data on the Clinic's behalf, as described in our Terms.
Purpose-limited collection, data handled on the Clinic's behalf, and a process for honouring access, correction, and erasure requests under India's DPDP Act, 2023.
We would rather be accurate than impressive. RevisitMD does not hold a formal security certification today. We don't advertise HIPAA, SOC 2, or ISO compliance, because we don't have those audits behind us. Everything on this page describes what the product genuinely does, not an external audit result. If your Clinic needs a specific control confirmed before relying on RevisitMD, write to us and we'll answer directly.
This page is a plain-language overview. For exactly what we collect, how long we keep it, who we share it with, and your rights under the DPDP Act, read our Privacy Policy.