Security & Privacy
Built to be trusted with your most sensitive data
Patient data security is a foundational principle at WelliRecord, not an afterthought. Every design decision starts with consent and privacy.
End-to-End Encryption
All health records are encrypted at rest (AES-256) and in transit (TLS 1.3). Only the patient and explicitly consented parties can access data.
NDPA 2023 Compliance
Designed from day one to align with the Nigeria Data Protection Act (NDPA) 2023, administered by the National Data Protection Commission (NDPC).
Immutable Audit Trails
Every access event is permanently logged. Patients see exactly who accessed what and when — with full provenance on every record.
Patient-Controlled Access
Patients grant and revoke provider access explicitly. WelliRecord never shares your data without your direct consent.
Sovereign Data Hosting
Data is hosted on NG-CERTs compliant infrastructure in Nigerian data centres, maintaining data sovereignty under Nigerian law.
FHIR R4 Standards
All records are stored in HL7 FHIR R4 format, ensuring portability and interoperability with any compliant system globally.
Responsible Disclosure
We run a responsible disclosure programme. If you discover a security vulnerability in WelliRecord, please report it to security@wellirecord.com. We respond within 48 hours and acknowledge responsible researchers.