HIPAA-aligned controls
PHI access controls, audit trails, and BAA available for US-facing clinics.
How Clinit protects patient data: httpOnly cookies, CSP, Redis rate limits, automatic audit logging, PDPL export, and alignment with HIPAA, GDPR, SOC 2, and PCI DSS frameworks.




PHI access controls, audit trails, and BAA available for US-facing clinics.
Data export, erasure workflows, and consent capture for MENA and EU patients.
Hosted checkout minimizes card data on clinic servers — webhooks idempotent.
Security controls documented; enterprise clients can request audit summaries under NDA.
Every mutating API route writes to tenant audit trail — exportable for GAHAR quarterly.
Self-hosted on DigitalOcean Cairo region via Coolify — your data stays in your deployment.