Security is a shared responsibility across technology, people, providers, and partners. This page describes the platform’s control baseline without revealing details that would weaken those controls.
Encryption and secure transport
Production connections are designed to use TLS 1.2 or later. Managed storage and backups are configured for strong encryption at rest, such as AES-256 or an equivalent provider control where supported. Encryption keys and secrets are separated from application code and access is restricted.
Identity and access controls
Role-based access limits each account to the work it needs. Strong password controls, session protection, provider verification, administrative separation, least-privilege permissions, and multi-factor authentication for privileged access reduce unauthorised access risk.
Audit logs and accountability
Security-relevant actions such as sign-in, verification, consent, document access, clinical updates, administrative changes, and payment events are logged with appropriate context. Logs are protected from ordinary user editing and reviewed for investigation and compliance needs.
Secure engineering and operations
Changes are reviewed and tested before release. Dependencies, secrets, backups, permissions, environments, and recovery procedures are managed as part of the operating baseline. Sensitive production information is not intended for use in development or demonstration environments.
Providers and service partners
Providers and vendors must protect credentials, devices, patient information, and physical records. Technology and payment partners receive only the access needed for contracted services and are expected to maintain confidentiality and appropriate security controls.
Incident response
Suspected incidents are triaged, contained, investigated, documented, and remediated. Where a breach creates a legal notification duty, affected users and the relevant authority are informed within the timeframe required by applicable law.
Compliance approach
The platform is designed around the Nigeria Data Protection Act, NDPR principles, professional confidentiality, auditability, and patient rights. Other frameworks, including GDPR or healthcare-specific contractual controls, apply only where the service, location, or agreement makes them relevant; no certification is implied unless explicitly stated.
Report a security concern
Report suspected account compromise, inappropriate record access, a vulnerable page, or a lost device through the contact page. Do not include exploit details or sensitive patient information in a public channel. Urgent reports are prioritised by the support and security team.
Ask before you act.
Our support team can explain the relevant policy or route a formal privacy, consent, legal, or security request.
This public document is intended to explain MyDoctor24’s operating approach and does not replace personalised legal or medical advice.