🚧 Beta — we're continuously improving PharmiraHealth. We'd love your feedback via the 💬 button!

Security at PharmiraHealth

Last updated: 19 July 2026

Health data deserves the strongest protection. Security is built into PharmiraHealth's architecture, not bolted on.

01. Data protection

Sensitive health fields (allergies, conditions, clinical notes, insurance details) are encrypted at rest.

All traffic is encrypted in transit with TLS/HTTPS.

Role-based access control gates every page, menu, and API endpoint — each role sees only what it needs.

Organisation isolation: a pharmacy, practice, or care facility can never access another organisation's data.

02. Account security

Passwords are hashed with modern algorithms; plain-text passwords are never stored.

Rate limiting protects against brute-force attacks; repeated failures raise automatic security alerts.

Sign-ins from new locations trigger a security notification to the account owner.

Multi-factor authentication is available for professional accounts.

03. Auditability

Every clinically or administratively relevant action is written to an immutable audit log with actor, timestamp, and IP.

Audit records cannot be edited or deleted; retention follows configurable healthcare-grade policies.

04. Compliance & disclosure

We follow GDPR principles: you can export your data and request deletion from Settings.

Found a vulnerability? Please report it responsibly via the in-app feedback button or pharmirahealth@gmail.com — we take every report seriously.

Questions about this policy? Email hello@pharmirahealth.com.