Trust & Security

    Security transparency

    Security review & FAQ

    A plain-language account of how Medi-Chi protects information and where the limits are. This is a self-reported security review, not an independent audit or certification.

    Documented controls

    Encryption

    HTTPS/TLS protects data in transit. The hosting provider encrypts stored data and backups at rest. Encryption does not replace careful access management.

    Access controls

    Sign-in and database row-level rules restrict ordinary access to private records. Administrative permissions are checked separately from user profiles.

    Health information

    Intake forms, notes, images and test results are treated as sensitive. AI requests may be processed by a model provider; direct patient identifiers should not be entered in AI prompts.

    Review status

    These statements describe documented safeguards. No independent penetration-test report or certification is published. Security can change, and no online service is risk-free.

    Latest automated self-check

    Run 1 October 2026. Automated scanning of database access rules and app connections.

    • No open issues affecting patient records, accounts or payments.
    • Three items reviewed and kept on purpose: the herb library and the list of locked book chapters can be read by anyone (public reference content, no personal data), and the ChatGPT lookup connection answers without sign-in because it only returns public reference content.
    • Limits: this is an automated self-check, not an independent penetration test. One optional cloud scanner wasn't connected and didn't run. Quotes for an independent CREST-accredited test have been requested.

    Frequently asked questions

    Is data encrypted?

    Connections to the site and its services use HTTPS/TLS, which protects data while it travels over the network. Stored records and backups use the hosting provider's encryption at rest. Encryption reduces exposure if data is intercepted or storage media is accessed; it is not a guarantee against a compromised account or authorised access.

    Who can see patient records?

    Users sign in to access private records. Database row-level access rules scope practitioner records to their owner; supervised Student Clinic access is limited to the student and authorised educator. Access for administrative service operations is separate from ordinary user access. A practitioner can share patient contact details with their own connected HubSpot or Cliniko account, and a patient can choose to share records through the patient workflow.

    How does Medi-Chi handle sensitive health data?

    Clinical notes, intake answers, tongue photos and test results can contain sensitive health information. Medi-Chi stores submitted records behind account-based access controls and uses clinical inputs to provide the requested features. AI-assisted features send relevant inputs to a model provider to generate a response; users should remove direct identifiers before entering AI prompts. Patient data is not used to train Medi-Chi's own AI models. Optional tongue-photo research use requires opt-in.

    Are card details or clinical records shared for advertising?

    Stripe handles card numbers directly; Medi-Chi does not store full card numbers. Medi-Chi does not sell patient records to advertisers. Analytics and marketing tags are subject to the choices described in the Privacy Policy and are not intended to receive clinical inputs or patient records.

    Can I export or delete data?

    Export options are available for supported records. You can request deletion of clinical data while keeping your account, or deletion of the whole account. Some billing records must be retained for legal reasons and deleted records may remain temporarily in rolling encrypted backups. Copies already synced to a practitioner's connected external service must be handled in that service.

    Has Medi-Chi passed an independent security audit?

    No independent penetration-test report or security certification is published here. This page is Medi-Chi's own summary of its documented controls, not a third-party assessment. Do not treat it as proof that the service has no vulnerabilities or as a HIPAA certification.

    Read the full policies

    Regulatory position Privacy Policy Terms of Service Account and data deletion Incident response

    To report a security concern, email support@medichi.online. Please do not send real patient data in your report.