Security & compliance

Physio clinic software security: records in India, consent recorded, changes audited

Physio Clinic Software keeps patient data on servers in India, records the patient's consent at registration (helping your clinic with the DPDP Act 2023) and logs every create and edit of clinical records.

In short: Physio Clinic Software stores patient records on servers in India, encrypted at rest and with TLS 1.2+ in transit. It records the patient's consent at registration, which helps the clinic meet the DPDP Act 2023, logs every create and edit of clinical records with user and time, keeps daily backups for 30 days and sends WhatsApp messages through the official Business API.
HIPAA CompliantData hosted in IndiaAES-256 at rest, TLS 1.2+ in transitRole-based access and audit logOfficial WhatsApp Business API

Consent at registration

Time of consent stored per patient, signed consent documents attached to the record, WhatsApp opt-in per patient; deletion handled from the record.

Staff logins

Every staff member has their own login to the clinic workspace, and the owner adds or disables them. Per-therapist patient restriction is planned.

Audit log

Every create and edit of patients, assessments, SOAP notes, outcome scores, packs and mandates is logged with user, time, IP and browser. View logging is planned.

WhatsApp via the official API

Messages go from your clinic number through Meta's platform; WhatsApp opt-in is recorded per patient and the clinic can switch it off at the patient's request.

Backups and export

Daily encrypted backups kept 30 days; export patients, notes, invoices and plans as CSV or PDF any time.

Medical document handling

MRI reports, prescriptions and consent forms (images or PDF, up to 8 MB) stored on the patient record and opened only by signed-in staff of that clinic.

How we build and run Physio Clinic Software

  • Isolation. Every record carries your workspace ID and every query is scoped to it at the data layer, so one customer can never read another's data.
  • Encryption. TLS 1.2+ in transit; encrypted disks at rest; passwords hashed with Argon2id; API keys stored only as hashes.
  • Access control. Roles (owner, admin, staff, viewer) with per-module permissions, session hardening and login throttling with temporary lockout after repeated failed attempts. Two-factor authentication is on the roadmap.
  • Audit trail. Every create, edit and delete is logged with who, when, from where and what changed.
  • Backups. Nightly encrypted backups, kept on a 30-day rolling cycle.
  • Data ownership. Your data is exported for you on request (and much of it is available through the REST API). If you leave, you get a 30-day export window and then your data is deleted.
  • Read more. See our privacy policy, terms of service, the full Physio Clinic Software feature list and pricing.
  • Responsible disclosure. Found a vulnerability? Email info@radiatus.com and we will respond within 2 business days.

Security questions

How does Physio Clinic Software help with the DPDP Act 2023?

It gives the clinic the tools the Digital Personal Data Protection Act 2023 expects: the time of the patient's consent is recorded at registration (and a signed consent document can be attached), WhatsApp opt-in can be switched off per patient, a patient record can be deleted, staff need their own login, and creates and edits are audit-logged. Your clinic remains the data fiduciary and is responsible for its own compliance; we act as processor.

Can I export or delete all my clinic data?

Yes. Owners can export patients, notes, invoices and exercise plans as CSV or PDF at any time from settings. If you close the account, Physio Clinic Software deletes your data within 30 days of the request, and backups age out on the normal 30-day cycle.

Where is patient data stored?

On servers in India (AWS ap-south-1, Mumbai), encrypted at rest, with daily backups kept for 30 days. Clinical records stay in India; WhatsApp messages pass through Meta's WhatsApp Business Platform to reach the patient, so keep message content to the plan and check-in.

How do WhatsApp messages stay private?

Plans and check-ins go through the official WhatsApp Business API from your clinic's number. Only the patient's registered number receives messages, consent is recorded at registration and WhatsApp can be switched off per patient. Each plan link uses a long random token; anyone with the link can see that plan and mark it done, so patients should not forward it.

Who can see pain scores and adherence data, and are they shared?

Pain scores (0–10) and Done replies are stored per day against the patient's exercise plan in the clinic's workspace, on servers in India. Every staff login of that clinic can see them; per-therapist restriction is planned. They leave the clinic only when a physiotherapist puts them in a progress letter and sends it to the referring doctor, after confirming the patient's consent. We never sell or share them, and they are deleted with the patient record.

Patients do their exercises. You see the progress.

Physio Clinic Software sends home-exercise plans on WhatsApp with a daily check-in in Tamil, Hindi, Telugu, Kannada, Malayalam or English, keeps every session pack's balance in view, and runs appointments, SOAP notes and GST billing in one place. From ₹999 per therapist a month, with a 30-day free trial, no card and free data import.