Layered authentication, per-role access control, a tamper-evident audit log and encrypted storage, active by default, with nothing extra for your team to configure.
Every account can require a second step at login. Pick what fits each person: an authenticator app, a passkey, or a one-time code by email or SMS.
Choose an authenticator app (TOTP) or a one-time passcode by email or SMS. Turn it on for one person, or make it mandatory for the whole clinic.
Scan this QR code
Scan with your authenticator app, then enter the 6-digit code it shows.
Can't scan? Enter this key manually:
FHUN576QN31HQL22GQ7A6NKL57TE72YRRRegister a hardware security key, Face ID, or fingerprint as a passwordless login method, built on the FIDO2 / WebAuthn standard, phishing-resistant by design.
Not every team member wants an authenticator app installed. ClinyPal sends a time-limited passcode to the email or mobile number already on file instead.
Hi ,
Use the code below to complete your sign-in. It expires in 1 minute and can only be used once.
If you didn’t request this code, please secure your account immediately.
Give each team member a role that matches their job (Administrator, Practitioner, Receptionist, Bookkeeper or Scheduler) and they only see what that role needs. Admins handle billing, integrations and staff accounts; everyone else gets a focused view of scheduling, charts and telehealth, with clinical notes and sensitive settings out of reach unless granted.
Every clinic gets a full audit trail automatically, nothing to turn on, nothing to configure. ClinyPal tracks who viewed, printed or downloaded a patient's data, and records every change: the field, what it changed from and to, and who made it. Nothing is ever deleted or rotated out.
The parts of security that have nothing to do with logging in. All active by default, on every plan.
Access controls, audit logging and encryption practices are designed to support the obligations clinics already operate under: HIPAA in the US, GDPR in the EU/UK, and equivalent frameworks elsewhere. A Business Associate Agreement and Data Processing Addendum are available on request.
2FA, passkeys and email/SMS codes, enforced per role.
Every action, kept indefinitely and exportable.
TLS 1.3 in transit, AES-256 at rest.
Reception sees the diary, not the clinical notes.
Start a 30-day free trial with every security feature enabled from day one: 2FA, passkeys, role-based access and the full audit trail, included.
No card required · no setup fee