Skip to main contentSkip to navigationSkip to accessibility settings
Trustworthy by design

Drafted by AI. Signed by you.

Every output is a draft until you approve it. We flag anything the AI made up, encrypt every transcript, and capture patient consent before each recording.

Six pillars of safety

Built so you stay in control

Hallucination detection flags ungrounded claims
AI output always marked as draft until doctor approves
Full audit trail, aligned with HPCSA Booklet 9
POPIA compliant. Transcripts encrypted at rest
Patient consent captured before every recording
You are always the final decision-maker

Security layers

Client
Edge
Application
Data
The specifics

What “secure” means here, precisely

Claims are cheap in security pages. These are the controls as they are built — ask to see any of them live in the demo.

Encrypted field by field

Clinical notes, transcripts, identifiers and medical-aid numbers are each encrypted individually, with versioned keys that rotate — encrypted data never reaches the browser.

A sign-off that can refuse

The server blocks signing an encounter with an unresolved critical allergy–medication conflict or a note not grounded in its transcript. Overrides require a written justification, on the audit record.

Two-factor, not optional

Every clinical role is required to enrol in authenticator-app two-factor sign-in, with backup codes. No SMS second factors.

Built for shared workstations

An hour of inactivity signs the session out — with a warning first — and each user holds a single active session.

A tamper-evident audit trail

Every access to patient information is logged append-only, each entry cryptographically chained to the previous one, with the chain verified live in the dashboard. Purpose-of-use is recorded on every access.

Statutory retention, automatic

Record retention follows HPCSA Booklet 9 schedules by record type — adult, paediatric, obstetric and more. Retention can be extended, never shortened.

Standards, not lock-in

Your records are stored in the open standard the healthcare industry reads, with a partner API for approved integrations. They are portable because the format is not ours.

POPIA operations built in

Data-subject exports as data files or PDF, deletion and anonymisation workflows with reasons recorded, and an incident register with severity and status.

app.nissihealth.co.za
Access trail
Chain verified · 12,408 entries
Encounter signed
Dr. L. Khumalo
Treatment
Patient chart viewed
Sr. N. Dlamini
Treatment
Audit export (CSV)
P. Botha (Admin)
Compliance
Prescription verified
Pharmacy QR scan
Operations
Append-only · each entry chained to the previous

The audit log, as owners see it

Readable names, filterable actions, purpose-of-use on every row — and a live integrity check across the whole chain.

Questions

What security reviewers ask

Is my patient data secure?

Yes. Patient data is encrypted at rest and in transit, every practice’s data is isolated from every other practice’s, and all access is logged in a tamper-evident audit trail with role-based access controls. NissiHealth is built for POPIA compliance, and records are stored in open healthcare standards so they stay portable. The technical specifics are set out in our Privacy Policy.

Where is my data stored?

Audio recordings, generated documents and encryption keys are stored in a Cape Town, South Africa data centre. Your practice’s clinical database (records, transcripts, notes) is hosted in the European Union (Frankfurt) under a binding agreement that meets POPIA’s section 72 standard, encrypted at rest and in transit. During a consultation, audio goes to our speech-to-text processors in the EU and de-identified text to our AI note-drafting processor in the United States, both under data-processing terms. The full list of providers and locations is in our Privacy Policy.

Can the AI sign notes or issue prescriptions on its own?

No. Everything the AI drafts stays a draft until you review and approve it, section by section. The system will also refuse to sign an encounter that has an unresolved critical allergy–medication conflict, or a note that is not grounded in the transcript. A clinician can consciously override a block — but only with a written justification that is recorded in the audit log.

Read the fine print, then see the real thing

Our privacy policy details exactly how patient data is handled. Book a demo to walk through the safety controls live.