- Job title
- Field sales representative
- Sector
- Insurance
- Organization type
- medium-sized business
- Joined
- Oct 2023
- Message
- 293
We run a small outpatient clinic in Dubai with two dentists and a physiotherapist. We see an average of 25 to 30 patients a day. To get our appointment scheduling organized, I've been testing a foreign cloud-based booking tool with a free tier for the past two months, which I found online.
Last week, I realized the system stores patient phone numbers names, and even the preliminary medical complaints we jot down in the appointment notes without any encryption. On top of that, anyone clicking the booking confirmation links sent out can access another patient's calendar record straight from their browser history without authorization. The local health authority has very strict data privacy regulations, and I'm seriously worried about getting fined or having our reputation ruined over a vulnerability like this.
Our clinic's monthly software budget tops out at around 1,200 AED. There's no way I can request a security patch on this free software. What technical requirements should I look for regarding patient privacy and data security when switching to a paid enterprise solution, and how should I plan this migration?