Practice responsibility
The doctor or organization defines purposes, authorized users, retention periods and patient information.
Cabinext handles sensitive information. The platform relies on encryption, secure storage, role-based permissions and organizational practices inspired by CNDP guidance and Morocco’s Law 09-08.
The practice remains responsible for organizing its processing activities and completing its own formalities. Cabinext protects the platform and acts as a service provider or processor depending on the contractual context.
The doctor or organization defines purposes, authorized users, retention periods and patient information.
Horizon HealthCare supplies the tool, security measures, support and contractual processing terms.
Each team member should use an individual account and follow the practice’s confidentiality rules.
Communications and storage are protected through encryption mechanisms appropriate to the production architecture.
Permissions are role-based so each user is limited to necessary actions.
Data is associated with the relevant practice and protected against unauthorized cross-practice access.
Important events may be recorded to support control, support and investigation.
Backup and restoration procedures are planned to reduce the risk of data loss.
Security fixes, dependencies and components are monitored through the maintenance cycle.
Development, validation and production environments are separated according to technical needs.
Technical-team access is limited to necessary situations and governed by internal responsibilities.
Incidents are qualified, contained, corrected and documented according to severity and applicable obligations.