HomeSecurity

Security

Your patient data stays secure and compliant.

Data residency, encryption, and role-based access — built in from day one, not patched on afterwards.

Built for healthcare regulatory complianceHIPAA-aligned · Data residency · End-to-end encryption

Data residency

Patient records stored in-country. Oman now — additional regions on the roadmap.

Encrypted end-to-end

TLS on every request. Data at rest encrypted. No plaintext patient records, ever.

Role-based access

Admin, therapist, receptionist. Each role sees only what they need.

Audit logging

Every clinical and billing action is timestamped and logged. HIPAA-aligned.

Database-per-clinic

Physical isolation from every other clinic. No shared schema.

2FA for every account

Two-factor authentication is mandatory for all staff. Cannot be disabled.

Backups & point-in-time recovery

Continuous backups with PITR. Restore to any moment in the retention window.

Compliant by design

Meets data-protection requirements out of the box — built in, not patched on. No extra compliance setup required.

Data sovereignty

Your clinic's data stays in your country

CureYou.ai runs a dedicated infrastructure deployment per region. Patient records, appointment data, and clinical notes are stored and processed within the country where your clinic operates — they do not leave that jurisdiction.

Oman is the first live region. Additional countries are planned. If your country is not yet listed, contact us to discuss a timeline.

Oman · LiveMore regions · Coming soon

Common questions

Security questions, answered plainly

Is each clinic's data truly isolated from other clinics?
Yes. Each clinic runs on its own dedicated database — not a shared schema with row-level filtering. A misconfiguration or breach in one clinic cannot expose another clinic's records. This is a foundational architectural decision, not an add-on.
Where is our clinic's data stored?
For clinics based in Oman, all patient records, appointment data, and clinical notes are stored within Oman. CureYou.ai never migrates that data to another jurisdiction without your explicit consent. Additional regional deployments are planned — contact us to discuss your country requirements.
What happens if a staff member's credentials are compromised?
Every staff account is protected by two-factor authentication (2FA), which is mandatory — it cannot be disabled. Even with a stolen password, an attacker cannot log in without the second factor. In addition, role-based access control ensures that a receptionist, for example, cannot access clinical notes or billing records.
How do you handle backups and data recovery?
Databases are backed up continuously with point-in-time recovery (PITR). This means that in the event of accidental deletion or data corruption, we can restore your data to any point within the retention window, not just the last snapshot.
Is CureYou.ai HIPAA-compliant?
CureYou.ai is built to align with HIPAA principles: access controls, audit trails, encryption in transit and at rest, and a minimum-necessary-data approach. We are happy to sign a Business Associate Agreement (BAA) with clinics that require it. Contact us for details.
How do I report a security vulnerability?
We operate a responsible disclosure programme. Send your findings to security@cureyou.ai with a clear description and reproduction steps. We acknowledge reports within 48 hours and aim to resolve critical issues within 14 days.

Ready to transform your clinic?

Join forward-thinking clinics already using CureYou.ai to manage care securely and efficiently.

Get started free →