Information Security Policy

Last updated: July 2026

1. Purpose and Scope

Patiento is committed to maintaining the confidentiality, integrity, and availability of all information assets. This Information Security Policy outlines the principles, controls, and practices we follow to protect patient data, clinic information, and our platform infrastructure.

2. Information Security Principles

  • Confidentiality: information is accessible only to authorized individuals and systems.
  • Integrity: information is accurate, complete, and protected against unauthorized modification.
  • Availability: information and services are accessible to authorized users when needed.

3. Organizational Security

  • Roles and responsibilities: information security responsibilities are defined and assigned across the organization.
  • Training: all personnel receive information security awareness training during onboarding and annually thereafter.
  • Third-party management: vendors and service providers are assessed for security compliance before engagement and monitored throughout the relationship.

4. Access Control

  • Access to systems and data follows the principle of least privilege — users and services are granted only the permissions necessary to perform their function.
  • Multi-factor authentication is enforced for all administrative access to production systems.
  • Access is reviewed quarterly and revoked promptly upon role change or departure.
  • Clinic data is logically segregated; each Clinic's data is accessible only to that Clinic's authorized users.

5. Data Protection

  • Encryption at rest: all stored patient data and messages are encrypted using AES-256 or equivalent.
  • Encryption in transit: all communications are encrypted using TLS 1.3 (or 1.2 as a fallback).
  • Data classification: information is classified by sensitivity level and handled according to defined procedures.
  • Backup and recovery: data is backed up regularly with tested recovery procedures. Recovery Time Objective (RTO) is 4 hours; Recovery Point Objective (RPO) is 1 hour.

6. Platform and Network Security

  • Infrastructure is hosted on industry-leading cloud providers with SOC 2, ISO 27001, and related certifications.
  • Network segmentation separates production, staging, and development environments.
  • Firewalls, intrusion detection/prevention systems (IDS/IPS), and DDoS protection are deployed at all entry points.
  • All production changes go through code review and automated CI/CD pipelines with security scanning.

7. Application Security

  • Secure development practices follow OWASP guidelines; developers receive security training.
  • Dependencies are scanned automatically for known vulnerabilities (Software Composition Analysis).
  • Static and dynamic application security testing (SAST/DAST) runs in the CI/CD pipeline.
  • Regular penetration testing is conducted by independent security researchers at least annually.
  • Input validation, output encoding, and parameterized queries are used to prevent common vulnerabilities (XSS, SQL injection, CSRF).

8. Incident Response

  • A documented incident response plan defines roles, escalation paths, and communication procedures.
  • Security incidents are classified by severity with defined response timeframes: critical (1 hour), high (4 hours), medium (24 hours), low (5 business days).
  • Data breaches involving personal data are reported to affected Clinics without undue delay and to relevant supervisory authorities within 72 hours where required by law.
  • Post-incident reviews are conducted and findings are incorporated into security improvements.

9. Business Continuity

  • A business continuity plan ensures critical services remain available or are restored within defined timeframes.
  • The plan is tested at least annually through tabletop exercises or live drills.

10. Compliance

We maintain compliance with applicable regulations and standards:

  • GDPR (EU General Data Protection Regulation)
  • KVKK (Turkish Personal Data Protection Law No. 6698)
  • Applicable healthcare data protection requirements

11. Policy Review

This policy is reviewed at least annually and updated as needed to reflect changes in our infrastructure, threat landscape, and regulatory requirements.

12. Contact

To report a security concern or vulnerability, please contact [email protected].

Patiento — [email protected]