Get started
ComplianceLive · in the productRegister

Security Centre

The security answers a hospital’s IT committee files — read from what already happened.

Get Security CentreOpen the appAvailable nowHow pricing works →

What it is

One screen that answers the questionnaire: who signed in and whether they used a second factor, which devices are live and how to end one, the quarterly review of every grant carrying the whole patient record or the money, and a printable statement for a patient of exactly who opened their file and why — with emergency accesses called out. Underneath it, the statutory privacy desk: access, correction, erasure, nomination, consent withdrawal and objection, each on a thirty-day clock with a named grievance officer.

Who uses it
Built for: Every specialty
Reads
Sign-ins, the audit chain, role grants, the vault, job runs
Writes
Access reviews, privacy requests, retention rules and sweep logs
Never
It asserts nothing.
Access
Only people whose role includes it — the clinic owner decides who
Your data
Full PHI. Hosted in Boston, United States. On uninstall: Reviews, privacy requests and sweep logs stay with the tenant as evidence.

How it works

  1. Name the grievance officerOne person, reachable, whose name is printed on every privacy notice the clinic hands out.
  2. Open the quarterly access reviewEvery grant carrying the whole patient record, the money, the platform console or emergency access is listed for a manager to attest or challenge. A challenge needs a second person to approve before anything is removed.
  3. Work the privacy queueLog the request the day it arrives, record how you checked identity, then answer it in writing inside thirty days.
  4. File the summaryPrint the posture summary. It carries this morning’s numbers and only the claims those numbers support.

Rules it keeps

What it does not do, by design. A listing with only benefits is an advertisement.

It asserts nothing.
Every figure is measured from a row somebody else wrote, and a figure it could not read says “not known” rather than “OK”.
Erasure replaces identifiers and keeps the clinical record under the retention the clinic has stated; a legal hold stops it outright and produces the written refusal the person is owed.
No statutory period is shipped: the clinic states the period and cites its source, and the patient’s notice quotes that citation back.

AI in Security Centre

AskQuestions about what is on screen — “What needs attention in Security Centre today?” — answered with the records it read.
DraftSummaries and notes for the team, marked as drafts until a person signs.
Every answer shows its sources. Nothing AI writes is saved until a person accepts it.

See it on screen

Live product
01Security Centre — See who signed in, review privileged access, answer privacy requestsCaptured from the running demo clinic
Security Centre — Security Centre — See who signed in, review privileged access, answer privacy requests
1 of 1

Connected to

Read out of the code, not the brochure: each app below is here because one service queries the other’s tables. Install either side and the hand-over is already wired.

See the whole clinic →

Questions clinics ask

What does Security Centre do?
The security answers a hospital’s IT committee files — read from what already happened. One screen that answers the questionnaire: who signed in and whether they used a second factor, which devices are live and how to end one, the quarterly review of every grant carrying the whole patient record or the money, and a printable statement for a patient of exactly who opened their file and why — with emergency accesses called out. Underneath it, the statutory privacy desk: access, correction, erasure, nomination, consent withdrawal and objection, each on a thirty-day clock with a named grievance officer.
What data does Security Centre read and write?
Security Centre reads sign-ins, the audit chain, role grants, the vault, job runs and writes access reviews, privacy requests, retention rules and sweep logs. Its data class is Full PHI. Every app works on the same patient record — nothing is copied into a silo.
What does Security Centre deliberately not do?
It asserts nothing. Every figure is measured from a row somebody else wrote, and a figure it could not read says “not known” rather than “OK”. Erasure replaces identifiers and keeps the clinical record under the retention the clinic has stated; a legal hold stops it outright and produces the written refusal the person is owed. No statutory period is shipped: the clinic states the period and cites its source, and the patient’s notice quotes that citation back.
What happens to our data if we uninstall Security Centre?
Reviews, privacy requests and sweep logs stay with the tenant as evidence.
Is Security Centre available today?
Yes — Security Centre is live in clinics today. Set up your practice on MedAppz and install it from your dashboard.

Want to see Security Centre running on your own patients?

Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.

More in Compliance

All 153 →