Trust & security
Compliance, security and audit are the parts of NefraOne you should never have to think about - so we think about them constantly. Here is exactly how patient records, billing and registry data are protected.
Registry fields captured at the bedside, prepped for every annual return.
Validated e-Invoices straight from sessions - patients and sponsors alike.
Every change, every actor, every timestamp. Nothing happens off the record.
Nurses see their patients. Managers see their branch. Owners see everything.
Information-security management built to the standard - certification underway.
Big touch targets, guided steps, camera scanning. Designed for gloved hands.
The practices
TLS in transit, encryption at rest - patient records never travel or sleep in the clear.
Every role sees exactly what its job needs - nothing more. Access is granted, scoped and revocable.
Creates, edits, imports, sign-ins - every action is recorded with actor, timestamp and context.
Point-in-time recovery on managed infrastructure - a bad day never becomes a lost record.
PDPA-minded handling of ICs and clinical data - collected for care, shown only where care needs it.
Hosted on hardened cloud infrastructure with health monitoring and controlled deployments.
NefraOne's information-security management system is built to the ISO/IEC 27001 standard, and we are working through independent certification to prove it. Security at the highest level - verified by auditors, not just promised by us.
Send them over - we answer security questionnaires directly, and quickly.