
Trust & Security
Trust is architecture, not a promise.
Every action accountable. Every record protected. Every audit ready — built to the highest healthcare-security standards the world has to offer, and deployed in Iraq.
Every control below is built, tested across 3,782 automated tests, and documented in a government-inspection evidence folder updated with every release.
Security architecture
Every control, enforced in code — not in a policy no one reads.
RBAC + ABAC — role × context
Access decisions combine six dimensions: role, organization, employee credential, patient consent, data category, and purpose. A doctor outside a care relationship is blocked even with the right role. This is the model Epic and Cerner use — the gold standard for clinical access control.
Append-only audit trail — 229 event types
Every sensitive action writes a permanent, tamper-evident log entry: who acted, which role and organization, which resource, what changed, IP, device, timestamp, and purpose. 229 distinct event types are registered and tested. No one can quietly look at a record and disappear.
Patient-controlled consent
Patients grant or revoke consent per provider and per purpose. A provider without active consent is blocked from the record — and every consent change is itself logged. Patients are genuinely in control of their own health information.
Encrypted Identity Vault
National ID numbers, passports, civil-status IDs, and refugee certificates live in an isolated vault schema — separated from medical records, encrypted at rest, with every single access individually logged. A breach of the medical layer cannot expose identity documents.
Healthcare Intelligence Mesh — AI guardrails
AI assists — summarize, score, flag, translate; humans approve. AI never diagnoses, prescribes, approves results, or overrides consent.
Three-layer separation of duty
Across prescription, lab, and radiology workflows, no single employee can both initiate and approve a sensitive action. Entering a lab result and approving it require two distinct credentialed roles. The same control that prevents bank fraud prevents result falsification.
FHIR R4 interoperability
Patient data, prescriptions, lab results, and radiology reports are modeled against HL7 FHIR R4 — the international standard for healthcare data exchange. When Iraq’s national EHR goes live, Dijla Health records can connect to it without re-entering a patient’s history.
Government-inspection readiness
A dedicated evidence folder is maintained continuously — architecture diagrams, data flows, permission matrix, audit policy, security controls, test reports, and incident-response plan. Inspection readiness is built in, not assembled in a panic when the Ministry calls.
Automated safety sweeps
Background workflows run credential and license-expiry checks on a schedule. The organization admin is notified 60 days before a professional license expires; at expiry, that employee’s sensitive actions — dispensing, lab approval, prescription signing — are automatically blocked until renewal.
Engineered to be inspected.
Questions about security
What patients and inspectors ask us most.
Who can see my medical records?
Only providers with an active care relationship and your explicit consent. Every access is permanently logged, and you can review who accessed your records, when, and why.
What if a doctor needs my records in an emergency without my consent?
Emergency break-glass access is permitted but never silent. Every break-glass event requires a documented reason, creates an elevated audit-log entry, and is reviewed by the platform administrator.
Can a pharmacist change my prescription?
No. The platform enforces this in code. A pharmacist can fulfill, reject, request clarification, or suggest an approved alternative. Editing a prescription is a hard block, not a warning.
Are my government ID documents stored securely?
Yes. National ID numbers and identity documents are stored in an isolated, encrypted Identity Vault — separate from your medical records. Every access to the vault is individually logged and classified as Highly Restricted data.
What is FHIR R4 and why does it matter?
HL7 FHIR R4 is the international standard for healthcare data exchange. It means your data is structured so Iraqi government systems — and any FHIR-compatible provider — can read it. When Iraq’s national EHR goes live, your records can connect to it seamlessly.
Does the platform meet government inspection requirements?
Yes. A dedicated inspection evidence folder is maintained and updated with every release — architecture diagrams, audit policies, permission matrices, test reports, and incident-response plans — ready for Ministry of Health inspection at any time.
What does “append-only audit log” mean?
It means audit records can be added but never edited or deleted — not even by an administrator. This tamper-evident design ensures the record of who accessed what cannot be quietly erased after the fact.
Does the AI access my data without permission?
No. The AI layer inherits the exact permission scope of the requesting user; it cannot see records the user cannot see. Every AI action is logged with the model used, data accessed, and whether human review was required. AI assists — summarize, score, flag, translate; humans approve. AI never diagnoses, prescribes, approves results, or overrides consent.
Want the full security overview?
Request a walkthrough of the architecture, the audit model, and the government-inspection evidence folder — in Arabic or English.
Request the security overview