Security and compliance

Built like a payments company, because we are one

What actually protects patient card data and practice accounts on Medipay. Everything on this page is in the product today.

Card data never touches Medipay

Patients type their card into secure fields served by our PCI DSS certified payment partners. Card numbers never reach or rest on Medipay's servers, or on the practice's. That places the practice in the lightest PCI self-assessment category for card-not-present payments, because there is no card data environment to assess.

Regulated acquiring

Transactions are processed and settled by FCA-regulated acquiring banks, direct to the practice's own bank account. Medipay does not hold client funds.

Access to the portal

  • Two-factor authentication (TOTP) on staff accounts
  • Brute-force lockout on sign-in, with the events visible to admins
  • IP allowlisting per workspace, so the staff portal only answers from your premises if you want it to. Patient payment pages are never restricted
  • Admin, supervisor and staff roles with a permission matrix you control, down to who can refund
  • Idle sign-out, configurable per workspace

Every action is logged

A full audit log records who created, sent, refunded or changed anything, with the reason where one is required. Cancelled payments carry why they were cancelled. Exports and the API carry the same record.

Data protection

Medipay is registered with the ICO. Patient data is scoped to the practice that holds it, enforced at the database layer, and every workspace is isolated from every other. Data is hosted in the UK and EU.

Integrations and the API

Accounting and practice-management connections use each provider's own authorisation, with credentials held per practice and revocable from Settings. API keys are scoped and rate limited, webhooks are signed so you can verify every delivery, and the MCP server runs with the same permissions and audit trail as a signed-in user.

Operational monitoring

The platform is health-checked continuously across the app, database and sign-in layers, and the result is published on our status page.

Need this in writing?

We can walk your compliance or IT lead through the controls, or send the detail your procurement process asks for.

Get started Chat with sales