My-Cliniq has a deep and uncompromising commitment to information security, confidentiality, and privacy. This principle is embedded in the platform from its inception and throughout all its development processes.

Accordingly, among other measures, all patient data is encrypted at rest and in transit using the highest industry-standard encryption protocols. Two-factor authentication is required on every login from an unrecognised device, application penetration testing is carried out on a regular basis to identify and remediate vulnerabilities, and more.

My-Cliniq is certified under ISO 27001 for organisational information security and ISO 27799 for medical information security, both by ARS Assessment Private Limited, and complies with the Patient Rights Law, the Israeli Privacy Protection Law including Amendment 13 (broadly aligned with the European GDPR), the Ministry of Health Director-General Circular on electronic medical records, and all other applicable laws, regulations, and standards — under the supervision of DNA-Q.

To this end, the platform does not synchronise with external services that do not meet these standards, such as Google Calendar, and exercises great caution in the use of AI tools, ensuring as far as possible that patient data does not leave its secure environment.


This page covers

This page covers My-Cliniq’s security certifications, data encryption standards, two-factor authentication, penetration testing practices, compliance with Israeli medical privacy law, and guidance for practitioners on using the platform securely.


Security certifications

My-Cliniq holds two international security certifications relevant to the storage and handling of sensitive medical data:

  • ISO 27001 — organisational information security management, issued by ARS Assessment Private Limited. Compliance with ISO 27001 satisfies the requirements of the Israeli Privacy Protection Regulations and partially satisfies European GDPR requirements.
  • ISO 27799 — information security in health organisations, issued by ARS Assessment Private Limited. This standard extends ISO 27001 specifically to medical data and satisfies the security requirements defined in the Ministry of Health Director-General Circular on electronic medical records.

Certification documents issued by ARS Assessment Private Limited are available for download on the Hebrew version of this page.


Technical security measures

  • End-to-end encryption of all patient data at rest and in transit using the highest available encryption standards
  • Two-factor authentication required on login from any unrecognised device, and as a random periodic control, as part of ongoing security measures
  • Regular application penetration testing to verify resistance to unauthorised access and external attacks
  • Automatic session timeout after a configurable period of inactivity
  • No integration with external applications, services, or calendars (Google Calendar, Outlook, etc.) that do not meet the required standards; patient data is kept as far as possible exclusively within the platform
  • High caution in the use of AI tools, given the security and privacy risks they entail

Frequently asked questions — Security

Is My-Cliniq secure?

Yes. My-Cliniq is certified under ISO 27001 and ISO 27799 by ARS Assessment Private Limited, encrypts all data at rest and in transit, requires two-factor authentication on unrecognised devices, and conducts regular penetration testing. These measures satisfy the requirements of applicable information security laws and regulations, including the Ministry of Health Director-General Circular on electronic medical records and the Privacy Protection Law including Amendment 13, under the supervision of DNA-Q.

Can My-Cliniq be accessed by more than one person on a single account?

A personal account is designed for a single user. A multi-user version is available, ranging from adding a single secretary to a full multi-therapist and multi-staff system. Multi-user systems allow individual passwords for each user, role-based access permissions with the option for individual customisation, a personal interface and physician log tailored to each user’s permissions, income and payment management for different users within the system, internal communication, referral management, and more. Multi-user systems are priced at ₪79 plus VAT per user per month. Sharing access (a shared password) among users does not comply with legal requirements and creates security and privacy vulnerabilities.

Can the subscription be cancelled at any time and the data exported?

Yes. My-Cliniq charges monthly with no minimum commitment. The subscription can be cancelled at any time with one week’s advance notice. Patient records and all other data can be exported to Excel files at any time through the platform.

Does My-Cliniq support app-based two-factor authentication (2FA)?

My-Cliniq supports two-factor authentication via SMS or via authenticator apps such as Google Authenticator. Use of an authenticator app is required when accessing the system from abroad, and can be switched to temporarily for that period. The two-factor authentication method (SMS or app) is configured through Settings > Security within the system.

Skip to content