Legal

Data Processing

This page describes how FAHMS processes data. It is not a signed data processing agreement; organizations needing one should contact us.

Draft for review by Fahtel Digital Hub before public launch. This document will be updated as FAHMS develops.

Roles

For patient and clinical data, the professional or healthcare organization using FAHMS decides what is processed and why. FAHMS acts as a service provider for account and workflow data and is designed so it cannot read patient content.

Customer-controlled patient data

DICOM imaging is processed locally in the browser. Case details, reports, consultation questions and messages are encrypted before storage or transfer, with keys only the authorized people hold.

Security measures

  • Encryption in transit and browser-side encryption of clinical content
  • Database-enforced access rules and role checks
  • Time-limited, revocable case access
  • Audit records without patient content

Sub-processors

Hosting and database, authentication, scheduled jobs and payment processing (Paystack). A full list is available on request.

Retention and deletion

Encrypted transfers are deleted after delivery or expiry. Account data is deleted on request when the account is closed, except where records must be kept.

Access requests

Requests about account data can be sent to support. Requests about patient data should go to the healthcare organization that holds it.

Security incidents

If we become aware of a security incident affecting account data, we will investigate and notify affected users and organizations without undue delay.

International processing

Providers may process account data in other countries. Patient content is encrypted before it leaves the device.

Contact

Questions about this document: supportdicom@fahteldigitalhub.com. See also our Privacy Policy and Terms of Service.