Compliance & security

Protecting practice data at every step.

Cabinext handles sensitive information. The platform relies on encryption, secure storage, role-based permissions and organizational practices inspired by CNDP guidance and Morocco’s Law 09-08.

Encrypted dataRole-based accessTraceabilityCNDP good practices

A shared-responsibility approach

The practice remains responsible for organizing its processing activities and completing its own formalities. Cabinext protects the platform and acts as a service provider or processor depending on the contractual context.

01

Practice responsibility

The doctor or organization defines purposes, authorized users, retention periods and patient information.

02

Cabinext as provider

Horizon HealthCare supplies the tool, security measures, support and contractual processing terms.

03

Authorized users

Each team member should use an individual account and follow the practice’s confidentiality rules.

Transparency: this page does not claim that Cabinext currently holds ISO 27001 certification, CNSS approval or a specific CNDP authorization number. Any certification, hosting location or official filing must be confirmed by a valid contract or certificate.

Technical and organizational measures

01

Encryption

Communications and storage are protected through encryption mechanisms appropriate to the production architecture.

02

Access control

Permissions are role-based so each user is limited to necessary actions.

03

Logical isolation

Data is associated with the relevant practice and protected against unauthorized cross-practice access.

04

Logging

Important events may be recorded to support control, support and investigation.

05

Backups

Backup and restoration procedures are planned to reduce the risk of data loss.

06

Updates

Security fixes, dependencies and components are monitored through the maintenance cycle.

07

Separated environments

Development, validation and production environments are separated according to technical needs.

08

Internal confidentiality

Technical-team access is limited to necessary situations and governed by internal responsibilities.

09

Incident response

Incidents are qualified, contained, corrected and documented according to severity and applicable obligations.