How we protect data

How Helix keeps patient data secure

Encryption in transit and at rest

Patient and financial data is encrypted as it moves and where it is stored. Credentials for connected systems are stored encrypted, too.

Role-based access

Around 700 granular permissions, with role templates, per branch and per module — so each person sees exactly what their job requires, and nothing more.

Full audit trail

Every change is logged and attributable to a person. Records are never truly erased — deletions are soft, so history can always be reconstructed.

Approvals and period locks

Refunds, write-offs and other sensitive actions go through approval workflows, and closed financial periods are locked against edits.

Full GCC data residency

Patient data stays in the GCC, meeting regional residency expectations for clinics in the UAE, Saudi Arabia and beyond.

Governed, private AI

Verto's models are hosted in Helix's own cloud and never trained on your data. Every AI action needs human approval, is logged immutably, and a platform-wide switch can pause all AI at once.

Standards & frameworks

Compliance at a glance

HIPAACompliantAdministrative, physical and technical safeguards for patient health information
SOC 2CompliantSecurity, availability and confidentiality controls
GDPRCompliantLawful basis, data-subject rights and processor terms
GCC data residencyFullPatient data stays in the GCC
NABIDH · Malaffi · RiayatiIntegratedDubai, Abu Dhabi and MOHAP health information exchanges
eClaimLink · Shafafiya · NPHIESConnectedUAE e-claims (DHA, DOH) and Saudi NPHIES via Waseel
ZATCA Phase 2IntegratedSaudi e-invoicing: reporting and clearance

We share the details of our controls, data flows and compliance scope with practices evaluating Helix.

Request our security pack

Evaluating Helix? Ask us for our security documentation — data flows, residency, access controls and AI governance — and we’ll answer your IT and compliance team’s questions.

Request our security packBook a demo
FAQ

Security questions, answered

Bring any other question from your IT or compliance team — we'll answer it in writing.

Talk to us
Related guides
Is Helix HIPAA compliant?

Yes. Helix is HIPAA, SOC 2 and GDPR compliant. Patient data is encrypted in transit and at rest, access is role-based, and every action is logged to a full audit trail.