Security and compliance
An overview of DoctSoft's enterprise security: encryption at rest, tenant isolation, MFA, audit logging, break-glass access and ABDM/FHIR interoperability.
DoctSoft is built for the sensitivity of hospital data. Security is layered: encryption, isolation, access control, strong authentication and complete auditing work together, so no single control is the only thing standing between patient data and misuse.
Encryption at rest
Sensitive fields are protected with field-level AES-256 encryption at rest, so patient data is encrypted where it is stored rather than sitting in the clear on disk.
Per-tenant data isolation
Each hospital is a tenant, and tenants are kept apart by row-level security. Data carries its tenant, and access is scoped to it, so one hospital can never see another's records.
Within a hospital, role-based access control limits each staff member to what their role permits. Combined with tenant isolation, this means access is bounded both by which hospital you belong to and by what your role allows.
Multi-factor authentication
Multi-factor authentication (MFA) is required on every staff sign-in, on every session rather than just the first login, so a stolen password alone is not enough to reach patient data.
Complete audit log
A complete audit log records actions across the system, producing an accountable trail of who accessed or changed what and when: the foundation for both security investigations and compliance.
Break-glass access
For genuine emergencies, break-glass access lets an authorised user reach records they would not normally see. Every break-glass use is audited, so emergency access is available when a patient's life depends on it but never invisible.
Break-glass is for emergencies only. Because every use is logged and reviewable, it should never be used as a routine shortcut around normal access controls.
Interoperability, no vendor lock-in
DoctSoft is ABDM-aligned and supports FHIR R4 export, so your data follows recognised health-data standards and can be exported rather than trapped. Interoperability is a deliberate design choice, not an afterthought. You can request a FHIR R4 export whenever you need to share data with another system or migrate, so your records are never locked to one vendor.