Data, security, and privacy

How Cerawave isolates clinic data, enforces access by clinic role, and keeps an audit trail of activity.

Practice owners3 min read

One clinic cannot read another

Isolation is enforced in the database rather than only in the application, so a request for another clinic’s patients returns nothing regardless of what the caller asks for.

Access follows the staff record a person holds in a specific clinic. There is no global role that reaches across clinics.

Audited activity

Clinic activity is written to an audit trail, because a patient record is a document a practice may later have to account for.

That trail is part of the clinic’s own data, subject to the same isolation as everything else.

What we ask of you

Give each person their own account at the role that matches their job, rather than sharing one login at the front desk. Shared logins make an audit trail meaningless.

Remove staff who leave. An invitation and an account are the clinic’s to manage.

Common questions

Can Cerawave staff read our patient records?
Access is governed by clinic membership and enforced in the database. Our privacy policy sets out how data is handled.
Should reception and doctors share a login?
No. Give each person their own account at the appropriate role, or the audit trail cannot tell you who did what.