Handling healthcare data securely
Rexium HealthOS processes sensitive data: patient data in Rexium Clinical, claims data in Rexium Declaraties and quality and staff data in Rexium Quality. Privacy, information security and auditable access are therefore considered throughout the development and further configuration of all our systems.
Our approach is guided by the GDPR and relevant NEN standards for information security in healthcare. Because we come from the clinical practice of Skin & Vision Clinics ourselves, we know what it means to be responsible for patient data.
Security is not an afterthought; it is part of the design.
Privacy by design
Roles & access
Logging
European hosting
What we focus on
Privacy by design and privacy by default
For every function we ask which data is really needed. What is not needed is not recorded. New users get the fewest possible rights by default, and retention periods are agreed per type of data.
Roles and access authorisation
Access is set up per role: a clinician, a front-desk employee, a quality officer or an auditor each have their own rights. Rexium Quality, for example, has a read-only auditor role. When someone leaves, their access is ended.
Logging and auditability
Key actions are recorded in an audit trail, so it can be traced afterwards who recorded or changed which data, and when.
Secure processing and exchange
Data is processed and exchanged over encrypted connections, never through regular email or a public website form.
- Encrypted connections (HTTPS/TLS)
- Applications and data hosted within the EU
- Claims data exchanged through a secure channel
Backup and continuity
We agree on backup, recovery and continuity, so data stays available and your clinic can keep working if something goes wrong.
Risk management, review and testing
Privacy and information security risks are identified and managed. Measures are reviewed periodically, tested technically and improved where needed.
Clear agreements with your clinic
Your clinic remains responsible for your patients' data; Rexium acts as processor. That is why we put the agreements in writing before any data is processed.
- A data processing agreement, signed before any data is processed
- Roles, authorisations, logging and termination of access agreed in advance
- Data used solely for the purpose your clinic provides it for
- Retention periods aligned with your clinic's legal obligations
