Skip to content
by Caresoft
Security & governance

Built to survive an audit, not just a demo

Two questions decide whether a hospital IT head says yes: can this slow down or corrupt our clinical system, and who can see patient data. Both are answered below without hedging.

1

Read-only by design

The login Prism uses on your hospital system has read rights and nothing more. It is not technically capable of writing to a clinical system. Your DBA creates it and can verify the grant.

2

A separate reporting database

Analysis never runs against the database your wards and billing counters depend on. Month-end reporting cannot slow down a discharge.

3

Role-based access, enforced not trusted

A department head sees their department, a unit head their unit. The restriction is applied by the platform to every query, including queries produced by the Ask box.

4

Patient identity masked by default

Names and contact numbers are hidden unless a user is specifically cleared, and each time they are viewed it is recorded. Most management dashboards work on aggregates and never need identity at all.

5

Credentials encrypted at rest

Hospital database passwords are encrypted with a key held outside the database and are never displayed again after entry. A database dump alone does not yield access to your system.

Everything is logged

Every login, every report run, every question asked and the exact query it produced — recorded with the user, the time and the result count. When an auditor asks who saw what, there is an answer rather than an assurance.

  • Access and authentication log
  • Report and dashboard run log
  • Ask box query log with the generated query
  • AI token and cost log per user and per dashboard
  • Import and connection history
  • Support access log — if we open your console, it is recorded with a reason

Caresoft's own certifications

CMMI Level 5ISO 27001PCI DSS

Twenty years, bootstrapped, still owned by the people who built it. 1,000+ hospitals across India and 12+ countries.

The AI question

What the model can and cannot reach

Worth being precise about, because most vendors are vague here.

It never sees your raw schema

The model is shown a curated set of business views with clean names and written definitions — not your hospital tables, and not patient identity columns for users who are not cleared.

It cannot be talked out of your access rules

Unit and department restrictions are applied by the platform after the query is generated. The model is never asked to add a filter, because anything that can be asked can also be persuaded.

It cannot write anything

The Ask box connects through a database account with read permission only. Even if every other safeguard failed, that permission holds.

Evidence, not assurance

Every change is on the record

The audit trail is a dashboard, not a table nobody opens.

Prism audit control dashboard showing who changed which bill and why

Illustrative data shown.

See it on your own numbers

One hospital, one month of your data, and the exception list from your own billing.

Book a pilot