Security & Compliance

Security & Compliance

Handling healthcare data securely

Rexium HealthOS processes sensitive data: patient data in Rexium Clinical, claims data in Rexium Declaraties and quality and staff data in Rexium Quality. Privacy, information security and auditable access are therefore considered throughout the development and further configuration of all our systems.

Our approach is guided by the GDPR and relevant NEN standards for information security in healthcare. Because we come from the clinical practice of Skin & Vision Clinics ourselves, we know what it means to be responsible for patient data.

Security is not an afterthought; it is part of the design.

Privacy by design

Only the data that is needed, and as little access as possible by default.

Roles & access

Every staff member sees and does only what fits their role.

Logging

Key actions can be audited afterwards: who did what, and when.

European hosting

Applications and data are hosted within the European Union.
Our approach

What we focus on

01

Privacy by design and privacy by default

For every function we ask which data is really needed. What is not needed is not recorded. New users get the fewest possible rights by default, and retention periods are agreed per type of data.

02

Roles and access authorisation

Access is set up per role: a clinician, a front-desk employee, a quality officer or an auditor each have their own rights. Rexium Quality, for example, has a read-only auditor role. When someone leaves, their access is ended.

03

Logging and auditability

Key actions are recorded in an audit trail, so it can be traced afterwards who recorded or changed which data, and when.

04

Secure processing and exchange

Data is processed and exchanged over encrypted connections, never through regular email or a public website form.

  • Encrypted connections (HTTPS/TLS)
  • Applications and data hosted within the EU
  • Claims data exchanged through a secure channel
05

Backup and continuity

We agree on backup, recovery and continuity, so data stays available and your clinic can keep working if something goes wrong.

06

Risk management, review and testing

Privacy and information security risks are identified and managed. Measures are reviewed periodically, tested technically and improved where needed.

Working together

Clear agreements with your clinic

Your clinic remains responsible for your patients' data; Rexium acts as processor. That is why we put the agreements in writing before any data is processed.

  • A data processing agreement, signed before any data is processed
  • Roles, authorisations, logging and termination of access agreed in advance
  • Data used solely for the purpose your clinic provides it for
  • Retention periods aligned with your clinic's legal obligations
Read our privacy policy

Want to know how this is set up for your clinic?

We are happy to explain our approach and discuss which agreements and measures fit your clinic and your systems.