Access follows responsibility
Doctors, nurses, cashiers, pharmacy staff, service teams, and administrators receive access that matches the work assigned to them.
HealthLedger combines encrypted data, responsibility-based access, separated support operations, complete audit visibility, managed backup and recovery, and hospital-directed data policies.
The data-centre photograph is illustrative and does not depict HealthLedger-owned infrastructure. HealthLedger supports internet-hosted and local-server deployment models. See Image Credits.
Access and accountability
Security follows the facility's departments and responsibilities. Clinical, financial, service, and administrative access do not need to be the same.
Doctors, nurses, cashiers, pharmacy staff, service teams, and administrators receive access that matches the work assigned to them.
Authorized managers retain responsibility for users, roles, departments, imports, printing, and other administrative functions.
Authorized facility administrators can use complete audit logs to review important operational and administrative activity.
Department access, administrative responsibility, data handling, and accountability are configured as part of implementation.
Confidentiality and transparency
Patient and facility data is not visible to backend support staff. Authorized facility administrators, however, retain complete audit-log visibility so important activity can be reviewed inside the hospital's own accountability structure.
Data lifecycle
HealthLedger manages backup and recovery without adding routine backup work to hospital teams.
Authorized export and retention are configured around hospital policy and applicable legal obligations.
Deployment and continuity
Deployment planning covers availability needs, facility infrastructure, access responsibilities, and data policy without treating internet continuity as protection from every possible local outage.
Give authorized teams access through an internet connection without managing a server at the facility.
Keep core facility work available when internet connectivity is interrupted. Local power, hardware, and network readiness remain part of deployment planning.
Regulatory alignment
HealthLedger supports controls and data policies aligned with the Nigeria Data Protection Act (NDPA) and, where applicable, GDPR and HIPAA requirements. These controls are part of a facility's broader policies, processes, responsibilities, and legal obligations; they are not a blanket certification of every customer or deployment.
Security review questions
Yes. Patient and facility data is encrypted at rest and in transit. The security review covers the implementation details relevant to the facility's deployment.
No. Patient and facility data is not visible to backend support staff. Hospital users and administrators receive access according to their authorized roles and responsibilities.
Yes. Authorized facility administrators can view complete audit logs. The facility defines who holds that administrative responsibility during implementation.
HealthLedger manages backup and recovery as part of the service. The implementation discussion confirms the facility's policies, operating responsibilities, and agreed recovery scope.
Yes. Authorized export and retention are configured around hospital policy and applicable legal obligations. Exact scope is agreed with the facility.
HealthLedger supports controls and data policies aligned with the Nigeria Data Protection Act and, where applicable, GDPR and HIPAA requirements. Software controls support a facility's wider governance program; this is not a claim that every facility or deployment is automatically certified or compliant.
Discuss roles, administrative responsibility, audit visibility, data policy, backup and recovery, and internet-hosted or local-server deployment.