Built for healthcare. Built to be trusted.

Layered authentication, per-role access control, a tamper-evident audit log and encrypted storage, active by default, with nothing extra for your team to configure.

HIPAA-ready GDPR 2FA & Passkeys Audit log RBAC TLS 1.3

Three ways in. One of them yours to choose.

Every account can require a second step at login. Pick what fits each person: an authenticator app, a passkey, or a one-time code by email or SMS.

A second factor on every login.

Choose an authenticator app (TOTP) or a one-time passcode by email or SMS. Turn it on for one person, or make it mandatory for the whole clinic.

  • Authenticator app (TOTP) support for any account
  • One-time codes by email or SMS as a fallback
  • Enforce clinic-wide, or leave it optional per role

Scan this QR code

Scan with your authenticator app, then enter the 6-digit code it shows.

Can't scan? Enter this key manually:

FHUN576QN31HQL22GQ7A6NKL57TE72YRR
6-digit code
Verify and enable
Cancel

Sign in with biometrics, not a password.

Register a hardware security key, Face ID, or fingerprint as a passwordless login method, built on the FIDO2 / WebAuthn standard, phishing-resistant by design.

  • Face ID, Touch ID and hardware keys all work
  • Open FIDO2 / WebAuthn standard, not a proprietary one
  • Nothing typed, nothing for an attacker to phish

A fallback for anyone without an app.

Not every team member wants an authenticator app installed. ClinyPal sends a time-limited passcode to the email or mobile number already on file instead.

  • Codes expire automatically after a short window
  • Delivered to the address or number already on record
  • Nothing extra to install or lose access to
Email · verification code

Hi ,

Use the code below to complete your sign-in. It expires in 1 minute and can only be used once.

If you didn’t request this code, please secure your account immediately.

Staff role list with per-role access levels
Role permission detail toggles

Not everyone needs the keys to everything.

Give each team member a role that matches their job (Administrator, Practitioner, Receptionist, Bookkeeper or Scheduler) and they only see what that role needs. Admins handle billing, integrations and staff accounts; everyone else gets a focused view of scheduling, charts and telehealth, with clinical notes and sensitive settings out of reach unless granted.

The owner's account is protected by designNo admin, however senior, can demote the owner or grant themselves that status.
Every permission change is loggedWho changed a teammate's role or access, and when, is always on record.
Audit history activity drawer

Nothing touches a patient record unlogged.

Every clinic gets a full audit trail automatically, nothing to turn on, nothing to configure. ClinyPal tracks who viewed, printed or downloaded a patient's data, and records every change: the field, what it changed from and to, and who made it. Nothing is ever deleted or rotated out.

Plain language, right on the chartOpen a patient's History tab and read the trail without digging through logs.
A clinic-wide view for adminsThe compliance report covers every record, filterable by date, staff member or type.

Encrypted, hosted, and backed up, without you thinking about it.

The parts of security that have nothing to do with logging in. All active by default, on every plan.

Encryption
TLS 1.3 encrypted in transit
Encrypted at rest AES-256, always on
Rotated signing keys automatic, never manual
Session security times out on its own
Hosting & availability
Reputable cloud hosting not a server in a closet
Automated daily backups kept separate, encrypted
Monitored around the clock alerts the moment something's wrong
Exportable anytime no ticket required

Built with healthcare regulation in mind.

Access controls, audit logging and encryption practices are designed to support the obligations clinics already operate under: HIPAA in the US, GDPR in the EU/UK, and equivalent frameworks elsewhere. A Business Associate Agreement and Data Processing Addendum are available on request.

HIPAA-ready GDPR BAA available DPA available
Authentication

2FA, passkeys and email/SMS codes, enforced per role.

Audit history

Every action, kept indefinitely and exportable.

Encryption

TLS 1.3 in transit, AES-256 at rest.

Role-based access

Reception sees the diary, not the clinical notes.

Security built in, not bolted on.

Start a 30-day free trial with every security feature enabled from day one: 2FA, passkeys, role-based access and the full audit trail, included.

No card required · no setup fee

  • 2FA and passkeys from day one
  • Full audit trail, nothing to set up
  • BAA and DPA available on request
Solutions Features Security Pricing App Integrations

Popular features

Scheduling Telehealth Clinical AI DICOM viewer Billing
Start free trial Sign in