Remedial massage that changes how you move through the day.

Data Security

as of 27th July 2026

Client File Data Security

Ultra-secure facilities

Cliniko is hosted in state-of-the-art datacenter facilities. Physical access is controlled at the perimeter and building entry points by professional security staff using video surveillance, intrusion detection systems, and other electronic means.

High availability

We use datacenter facilities that are built in clusters. In case of failure, automated processes move customer data traffic away from the affected area and into other sites that are functioning properly. It all occurs behind the scenes, and you won’t even notice when it’s happening.

Encryption

Whenever your data is sent between us, it’s encrypted using HTTPS (end-to-end encryption). We use a 2048-bit SSL certification for encryption in transit. All data is also encrypted at rest and backed up daily, using the industry-standard AES-256 encryption algorithm.

If that sounds like a bunch of jargon nonsense to you, here’s what it means: all data shared between you and Cliniko is transmitted and stored securely. No one can read the information except for you and us. Plus, we refresh your backup every day to make sure it stays current.

Accreditations and Certifications

We choose our partners carefully. Our hosting partner, Amazon Web Services (AWS), has achieved the following accreditations and certifications:

  • ISO 27001 (Information Security Management System)
  • FIPS 140-2 (United States Federal Information Processing Standard)

    Cliniko uses the payment processor, Stripe, which has PCI DSS Level 1 (Payment Card Industry Data Security Standard)

      4/7/365 Monitoring

      Cliniko is monitored 24 hours a day, 7 days a week, 365 days a year. If something goes wrong, we’ll be the first to know about it, and our team will jump into action straight away—no matter when it happens!

      Backups

      Cliniko data is backed up daily. Backups are redundantly stored in multiple physical locations. Data is also constantly streamed to replica databases for up to the second redundancy.

      In other words, we’ve got backups for your backups and a contingency in place to handle any potential interruptions to the storage process. Don’t forget that you can also export your data at any time and create your own backups too.

      Data stored close to home

      New Cliniko accounts based in Australia will have their data stored safely in Australia. Creating your account in the UK? Brilliant! Your data will stay in the UK. O Canada? Your account data will be stored securely in Canada, eh! For those of you creating your account in Europe, we’ve got you covered with data storage in Ireland—keeping it in the EU. And if you're located anywhere else in the world, your data will be securely housed on servers right here in Australia.

      Cliniko meets or exceeds all regulations of the Australian Privacy Principles, GDPR, PIPEDA, and HIPAA.

      https://www.cliniko.com/security/

      Secure Payments
      HICAPS has obtained ISO 27001 certification for its Digital portal from November 2019 to help protect our customers partners and communitiesISO 27001 is an internationally recognised standard for information security management systems (ISMS). The certification process involves a comprehensive assessment of a company's information security management practices, policies, and procedures. This certification validates that a company has taken necessary steps to secure their data and mitigate risks. ISO27001 provides a framework for organisations to effectively manage security risks and implement appropriate technical and procedural controls.

       

      What does it mean for HICAPS and our customers?

      HICAPS is a health claims and payment solution provider that processes a vast amount of sensitive data, including personal and financial information. As such, HICAPS has a responsibility to protect this data from potential cyber threats. A security breach could have catastrophic consequences for HICAPS and our customers, including financial losses, damage to reputation, and loss of customer trust.

      "The ISO 27001 certification is a crucial aspect of data security for companies like HICAPS. With the constant threat of cyber-attacks and changing threat landscape, it's more important than ever to implement and maintain a comprehensive information security management system. We continue to make Cyber security a top priority for our customers’ peace of mind, and when you deal with us you know your data is secure" says Steven Taub, HICAPS CISO (Chief Information Security Officer).

      Certification means we have robust systems, technical controls, procedures and monitoring in place to protect the data that we process and store, so our customers and partners can have a very high degree of confidence in the security of our technical services and how we handle their data.

      HICAPS is a subsidiary of NAB and as such leverages NAB information risk framework and security controls where appropriate for our Digital portal, for example, pen testing and vulnerability scanning.

      https://www.hicaps.com.au/news/blog/making-cybersecurity-our-top-priority

      Loading...
      Verified by MonsterInsights