WORLDWIDE PATIENT DATA PROTECTION
Global compliance
Last updated · 10 February 2026
Physiogenic operates across the globe. Wherever your clinic and patients are based, we map the platform's behaviour to the strictest privacy + medical-record laws that apply. This page summarises the frameworks we comply with — and what each means for you in practice.
Privacy frameworks we comply with
- European Union — GDPR (Regulation 2016/679). Articles 7, 12, 15, 17, 20 are all self-service from
/account/security. - United Kingdom — UK GDPR + Data Protection Act 2018. Equivalent to EU GDPR; ICO is the supervisory authority.
- United States — HIPAA + HITECH for protected health information; CCPA / CPRA for California residents; state-level breach notification laws.
- Canada — PIPEDA federally + provincial laws (Quebec Law 25, Ontario PHIPA, Alberta PIPA).
- Australia — Privacy Act 1988 + Australian Privacy Principles (APPs), My Health Records Act 2012.
- New Zealand — Privacy Act 2020 + Health Information Privacy Code 2020.
- Brazil — LGPD (Lei Geral de Proteção de Dados). Equivalent self-service rights to GDPR.
- Switzerland — Federal Act on Data Protection (FADP, 2023 revision).
- Singapore — PDPA (Personal Data Protection Act 2012).
- UAE — DIFC Data Protection Law No. 5 of 2020.
- South Africa — POPIA (Protection of Personal Information Act 4 of 2013).
- India — Digital Personal Data Protection Act 2023.
- Japan — APPI (Act on the Protection of Personal Information).
Medical record retention — varies by country
Patient records cannot be deleted before the retention window expires, even on a patient's request. We honour the strictest applicable law:
- 🇵🇱 Poland: 20 years (Act on Patient Rights, Art. 29)
- 🇫🇷 France: 20 years (Code de la santé publique R.1112-7)
- 🇩🇪 Germany: 10 years (Patientenrechtegesetz §630f)
- 🇬🇧 UK: 8–10 years (NHS Records Management Code 2021)
- 🇪🇸 Spain: 5 years (Ley 41/2002 Art. 17)
- 🇺🇸 US: 6 years (HIPAA minimum); 7–10 years in most states
- 🇨🇦 Canada: 10 years (varies by province; Ontario PHIPA: 10)
- 🇦🇺 Australia: 7 years (adult); until 25 (child)
- 🇳🇿 New Zealand: 10 years (Health (Retention of Health Information) Regulations)
- 🇮🇪 Ireland: 8 years (HSE Health Records Management Code)
What we do — regardless of jurisdiction
- Data residency: every clinic's data sits in the EU (Frankfurt) by default; US/UK/AU regions are available on request for sovereignty-sensitive contracts.
- Encryption: TLS 1.3 in transit; AES-256 at rest. Patient documents + AI scribe audio are bucket-encrypted with per-clinic keys.
- Granular consent (7 keys): marketing email, AI scribe, anonymised research, GP outcome sharing, internal clinical audit, photo/video, emergency contact sharing.
- Self-service: every patient on every plan can download all their data + delete their account from
/patient/account. - Breach notification: 72 hours for EU/UK/CH/BR; "without unreasonable delay" for US/CA/AU/NZ. We notify clinics in <6 hours regardless.
- Sub-processors: Stripe (payments), Resend (email), Backblaze B2 (backups), OpenAI/Anthropic/Google (AI). All under DPAs.
- No data sale, ever: patient health information is never sold, traded, or used for marketing outside your clinic.
Country-specific clinic features
Invoice formats, tax exemptions, and government ID fields auto-render based on your clinic'scountry_code. Examples:
- PL: NIP/REGON on invoices, KSeF-ready footer, VAT-exempt under VAT Act Art. 43(1)(19), PESEL on patient profile.
- DE: USt-IdNr on invoices, VAT-exempt under UStG §4 Nr. 14, Versichertennummer on patient profile.
- FR: SIRET on invoices, VAT-exempt under CGI Art. 261-4-1°, INS-NIR on patient profile.
- UK: VAT Reg # on invoices, generally VAT-exempt for medical care, NHS number on patient profile.
- US: EIN on invoices, state-by-state sales tax handling, SSN/Medicare # on patient profile.
- ES: NIF/CIF on invoices, VAT-exempt under Ley 37/1992 Art. 20.Uno.3°.
If your country isn't listed, contact us — we add new jurisdictions on a 7-day SLA for paying clinics.
DATA PROTECTION CONTACT
For questions, rights requests, or to revoke consent, email our Data Protection Officer.
dpo@physiogenic.pl