Trust

Data security

A clinical record carries a duty ordinary software does not. Here is what that means in practice, described honestly and specifically.

Last updated: 14 August 2026Applies to: the Onceva clinical record system

We only describe controls, standards and practices that are actually implemented today. Where something is planned but not yet built, we say so explicitly rather than implying it already exists. We do not claim any certification, audit or compliance status that Onceva has not actually obtained.

01Security by design

Onceva is built around the fact that it holds patient records, not general-purpose business data. Access control, encryption and audit logging are core parts of the record system itself, not features bolted on afterward.

02Access controls

Access to a clinic's records is role-based. Reception, clinical and billing staff see only the parts of a record their role in the clinic requires, and no account outside a clinic can see that clinic's patient data. A clinic's administrator controls who on their own staff has an account and what role they hold.

03Authentication

Each person who uses Onceva signs in with their own account and credentials; shared logins are discouraged so that activity on a record can be attributed to the person who actually performed it.

04Encryption

Patient records are encrypted in transit between a clinic's device and Onceva, and encrypted at rest in storage.

05Infrastructure and backups

Onceva's infrastructure is hosted with established cloud infrastructure providers rather than run on-premise, and clinic data is backed up as part of normal operations so that a technical failure does not mean a clinic loses its records. We are still early in formalising and publishing specific backup frequencies, retention windows and disaster-recovery targets, and will publish those specifics here once they are finalised, rather than stating numbers we cannot yet stand behind.

06Monitoring and incident response

We monitor for signs of unauthorised access and unusual activity on the system, and every entry, edit and view of a patient record is timestamped and attributed, giving us and a clinic a complete audit trail to investigate from. If a security incident affecting a clinic's data occurs, we will notify the affected clinic directly and work with them on next steps. Our incident-response process is still maturing alongside the product; we have not yet published a formal, externally audited incident-response policy, and will say so here until we have.

What we do not yet claim. Onceva has not undergone an independent security certification or audit (for example, ISO 27001 or SOC 2), and does not claim compliance with international regulatory frameworks such as HIPAA. We are structuring the product around the clinical information system expectations set out by the Punjab Healthcare Commission and the data protection obligations taking shape under Pakistan's Personal Data Protection Bill, and will update this page as that legislation, and any formal certification we pursue, is finalised.

07Retention and deletion

Records are retained for as long as a clinic's account is active. If a clinic ends its use of Onceva, its data remains exportable and accessible for a reasonable transition period, after which it is deleted from active systems unless retention is required by law or the clinic instructs otherwise. See our Privacy policy for more on how data is handled.

08Your responsibilities

Security is shared. A clinic is responsible for keeping its own staff credentials confidential, assigning roles appropriately, removing access promptly when staff leave, and using Onceva only on devices and networks the clinic trusts. Weak or shared passwords, or credentials left logged in on a shared device, are outside what any system-level control can fully protect against.

09Reporting a security issue

If you believe you have found a security issue affecting Onceva, write to oncevepk@gmail.com with details, and we will respond directly. Please avoid accessing or altering data beyond what is needed to demonstrate the issue.