Support & Security Policy

(Version 2.1 — 28 July 2026)

About This Policy

This Support & Security Policy provides a high-level overview of how Medscape (Pty) Ltd t/a HealthAccess ("HealthAccess", "we", "our") supports its customers, securely operates its platform, protects customer information, and manages operational resilience. It is written for our customers, and for prospective customers, procurement teams, and organisations performing due diligence.

  • Company Registration: 2019/391460/07 (South Africa)
  • Contact: via the Contact Us page on our website.

HealthAccess provides cloud-based software for practices across healthcare, allied health, aesthetics, wellness, and related industries, including optional artificial intelligence capabilities and related services ("AI Features").

This policy describes our support and security practices at a general level. It complements the HealthAccess SaaS Agreement but does not create contractual service levels, credits, or guarantees; any binding commitments are those set out in the SaaS Agreement or a signed order form or addendum.

Related Documents

This policy works alongside the following, each with a distinct purpose:

  • SaaS Agreement — the master agreement governing use of the platform;
  • Privacy Policy — how we process personal information;
  • HealthAccess AI Addendum — contractual terms for AI Features, where used; and
  • AI Trust Centre — operational and technical information about our AI Features.

For how we handle personal information, see the Privacy Policy; for AI governance, see the AI Trust Centre. This policy focuses on support, operations, and platform security.

Scope of Support

Support covers issues related to the HealthAccess platform, including:

  • user access, login, and permissions;
  • system performance, errors, and bugs;
  • standard product configuration and usage guidance; and
  • availability of new features and updates.

This policy also describes the measures we take to protect Customer data, reduce the risk of loss or unauthorised access, and recover from disruption.

Support Channels

Customers can request support through:

  • our in-platform and website ticketing/chat; and
  • email, via the Contact Us page.

All requests are logged and tracked for accountability and resolution.

Support Hours

  • Business hours: Monday to Friday, 08:00–17:00 (SAST), excluding South African public holidays.
  • After hours: Critical availability issues (for example a platform outage) can be raised outside business hours through our support channels.

Response Targets

We aim to respond within the following timeframes:

  • Critical (system unavailable): Response within 4 business hours.
  • High (a major feature not working): Response within 1 business day.
  • General (questions, minor issues): Response within 2–3 business days.

These are targets, not contractual guarantees. Resolution times depend on the complexity of the issue and may require escalation to our development team.

Customer Responsibilities

To help us support you effectively, Customers are responsible for:

  • maintaining stable internet connectivity and working local hardware and devices;
  • nominating a contact person for support queries;
  • providing accurate information and context when logging requests;
  • ensuring their staff follow platform procedures; and
  • safeguarding their own accounts, devices, and access credentials, and controlling who has access.

What Is Not Included

The following are not part of standard support and may be quoted separately:

  • staff training beyond initial onboarding;
  • data migration or imports from other systems;
  • Customer-side hardware or local network issues; and
  • third-party integrations outside the HealthAccess platform, unless separately agreed.

Escalation

If a Customer feels an issue is not progressing within a reasonable time, it can be escalated through our support channels or an assigned account contact.

Platform Security

We take the security of the platform and Customer data seriously and follow recognised security principles. At a high level, our practices include:

  • Encryption. Data is encrypted in transit and, where applicable, at rest.
  • Authentication. Access is protected by authentication controls, including multi-factor authentication where available.
  • Access control. Access is granted on a role-based, least-privilege basis, limited to what each user or staff member needs.
  • Audit logging. System activity is logged to support monitoring, troubleshooting, and accountability.
  • Monitoring. We monitor the platform for availability, performance, and suspicious activity.
  • Secure development & releases. We follow secure development practices and release changes through controlled, tested processes, with review before deployment to production.
  • Change management. Changes to the platform are managed to reduce risk to availability and security.
  • Vulnerability management. We monitor for vulnerabilities and apply security updates and patches on a risk-based basis.
  • Hosting. The platform is hosted with reputable cloud infrastructure providers, in facilities with industry-standard physical and environmental protections.
  • Staff confidentiality. Our personnel are bound by confidentiality obligations and access Customer data only as needed to provide and support the service.
  • Secure operations. We apply secure operational practices across our team and review and improve them over time.

We describe these controls at a high level and do not publish sensitive implementation details or internal security architecture.

AI Features

AI Features are delivered within the HealthAccess platform and are protected by the same platform security controls described above. The contractual terms for AI Features are set out in the HealthAccess AI Addendum, and AI governance and operational information (such as AI providers and processing locations) are maintained in the AI Trust Centre. How personal information is processed when AI Features are used is explained in the Privacy Policy.

Business Continuity & Recovery

  • Backups. Core databases are backed up daily. Backups are encrypted, stored in secure, geographically separate environments, retained on a rolling 30-day basis, and accessible only to authorised staff for recovery.
  • Recovery. We maintain backup and disaster-recovery arrangements designed to restore the platform and data following a significant disruption. Recovery applies to full database snapshots rather than individual records.
  • Planned maintenance. Routine maintenance is carried out within maintenance windows, typically outside business hours, with advance notice where practicable.
  • Emergency maintenance. Occasionally carried out at short notice where necessary to protect security or platform stability.
  • Continuous improvement. Platform updates, fixes, and enhancements are delivered as part of ongoing improvement and are included in the subscription.

We aim to keep the platform available but do not guarantee uninterrupted or error-free operation.

Incident Response

We maintain an incident-response approach for security and availability incidents affecting the platform:

  • Identify. We monitor for and identify potential incidents.
  • Contain. We act to contain and limit the impact.
  • Investigate. We investigate the cause and scope.
  • Remediate. We apply corrective and preventive measures.
  • Recover. We restore normal operation.
  • Communicate. We notify affected Customers without undue delay and cooperate with them.

Where an incident affects personal information, notification follows the process described in our Privacy Policy. Customers must provide accurate contact details and cooperate with incident handling.

Limitations

  • Recovery applies to full database snapshots, not individual records.
  • Special recovery, migration, or customised export requests may incur additional fees.
  • We are not responsible for issues arising from Customer-side misconfiguration, user error, or weak Customer security practices, including poorly managed access credentials.

Updates

We may update this policy from time to time. Updates are posted on this page with a new version number and date. The current version is Version 2.1, dated 28 July 2026.

Version History

  • Version 2.1: Modernised the security section (high-level controls), added Related Documents, AI Features, Business Continuity & Recovery, and Incident Response sections, aligned terminology with the Privacy Policy, corrected the company registration number, and clarified that response targets are not contractual guarantees. (28 July 2026)
  • Version 2.0: Previous published version. (23 September 2025)

Contact

For support, please use the channels above. For any other questions about this policy, contact us via the Contact Us page on our website.

HealthAccess
40 Swart Street
Brackenfell
Cape Town, 7560
Phone: +27 60 087 2136