Legal
Data Processing
Draft for review by Fahtel Digital Hub before public launch. This document will be updated as FAHMS develops.
Roles
For patient and clinical data, the professional or healthcare organization using FAHMS decides what is processed and why. FAHMS acts as a service provider for account and workflow data and is designed so it cannot read patient content.
Customer-controlled patient data
DICOM imaging is processed locally in the browser. Case details, reports, consultation questions and messages are encrypted before storage or transfer, with keys only the authorized people hold.
Security measures
- Encryption in transit and browser-side encryption of clinical content
- Database-enforced access rules and role checks
- Time-limited, revocable case access
- Audit records without patient content
Sub-processors
Hosting and database, authentication, scheduled jobs and payment processing (Paystack). A full list is available on request.
Retention and deletion
Encrypted transfers are deleted after delivery or expiry. Account data is deleted on request when the account is closed, except where records must be kept.
Access requests
Requests about account data can be sent to support. Requests about patient data should go to the healthcare organization that holds it.
Security incidents
If we become aware of a security incident affecting account data, we will investigate and notify affected users and organizations without undue delay.
International processing
Providers may process account data in other countries. Patient content is encrypted before it leaves the device.
Contact
Questions about this document: supportdicom@fahteldigitalhub.com. See also our Privacy Policy and Terms of Service.