Physitrack Group prioritizes the security and privacy of your data, offering global healthcare and wellbeing solutions with strong data protection measures.
Discover the steps we take and features we offer to safeguard your data and keep your information protected.
Learn how our in-house security team approaches information security and fortifies our product.
See the attestations and certifications that ensure our users' data is safe and secure.
Digital physiotherapy and rehabilitation platform connecting patients with licensed practitioners. Provides exercise prescription, progress tracking, and telehealth solutions for musculoskeletal conditions.
* Physitrack is registered with the United Kingdom Information Commissioner's Office under number ZA396165.
Comprehensive workplace wellbeing platform supporting employee mental health, physical wellness, and occupational health services for organizations of all sizes.
* Champion Health is registered with the United Kingdom Information Commissioner's Office under number ZA525188.

Our security team uses top industry frameworks and continuous monitoring to ensure exemplary security practices. Leadership's commitment to security excellence fosters a culture of protection and compliance. We provide regular security training and have clear roles for data access and protection.
Robust security architecture with threat detection, network segmentation, and ongoing vulnerability assessments.
Our network security includes segmentation, firewalls, and threat detection. We use automated CSPM for cloud security and monitor for threats continuously.
Our anti-tampering measures, like code obfuscation and integrity checks, prevent unauthorized access. Regular audits and penetration tests ensure compliance with OWASP and NIST standards.
We maintain security through a Secure Development Lifecycle (SDLC), identifying and addressing vulnerabilities using CVE and CVSS scoring. Regular third-party penetration tests are conducted, with audit summaries available upon request.
Payments are processed securely through PCI-DSS compliant third-party services, with no internal storage of payment data.
Data is encrypted during transmission using TLS 1.2+ and at rest with AES-256. We ensure end-to-end encryption between devices and the cloud.
We use role-based access control (RBAC) to limit user access to necessary information. Multi-factor authentication (MFA) adds an extra security layer.
Comprehensive compliance with international standards including GDPR, HIPAA, and ISO 27001 certifications. Regular third-party audits and assessments ensure continuous adherence to the highest security and privacy standards.

Demonstrating comprehensive information security and privacy management
Adhering strictly to U.S. standards for electronic Protected Health Information (ePHI)
Ensuring adherence to European and UK data protection regulations

Alignment with UK healthcare data security standards
Physitrack Group has an ISMS in place, with roles of Information Security Manager and Data Protection Officer appointed. Our adherence to the ISO requirements has been confirmed by the independent audits and is supported with the ISO27001 (Information Security) and ISO27018 (Data Protection in Cloud) certificates.
Advanced encryption, secure data processing, and comprehensive privacy controls protect sensitive information at every stage.Transparent privacy practices with user control over data usage and clear consent mechanisms for all processing activities.
Physitrack Group is committed to transparency and strict adherence to global data protection regulations, ensuring user rights are respected across all platforms. We prioritize the protection of personal and health information as a fundamental responsibility, building trust with our users.
Physitrack Group processes personal and special category health data strictly for the purpose of delivering secure, effective healthcare and wellbeing services. The types of data processed vary slightly between our two products, Physitrack and Champion Health.
For a complete breakdown of the categories of data processed, please refer to our detailed Data Processing Agreements (DPAs).
Note: We are incorporated under UK law and registered with the ICO (the Information Commissioner's Office). We have clients in more than 100 countries. For these reasons, our DPAs are available in English only.
We ask and store as little as possible and have designed our platform and operations in line with the EU's strict GDPR principles. Non-EU subprocessors have Standard Contractual Clauses in place.
All data sent to and from our platform is encrypted in-transit and encrypted at rest. See our SSL Labs score. All media between the client and server use standard protocols (DTLS/SRTP) encrypted with 256 bit AES.TLS encryption is used for inbound and outbound email.
On top of all the controls that protect the confidentiality, integrity and availability of PHI, we have BAAs in place with third parties and subcontractors who have access to PHI.
Access to patient data is severely restricted, and any person or party that (potentially) has access to patient data is bound by confidentiality agreements.
Physitrack runs physically isolated platforms in different data centers around the world to avoid leaking data outside jurisdictions as much as reasonably possible.
Our infrastructure is hosted inside AWS. Physical and environmental security related controls for our servers, which includes buildings, locks or keys used on doors, are managed by AWS:“Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff. Authorised staff must pass two-factor authentication a minimum of two times to access data center floors."
Your privacy is of utmost importance to us. As part of our commitment to safeguarding your data, we do not store any bank or credit card information on our servers. Instead, we rely on PCI-DSS-certified third-party payment services to handle all transactions. They are industry leaders in payment security and compliance, ensuring that your payment information is processed securely and efficiently.
For payment processing, we utilise the following trusted services:
Our commitment to your data security is further strengthened by our partnerships with these reputable trusted services. Together, we implement a comprehensive array of security measures, ensuring that your financial information is managed with the utmost care and security.
We use industry-best practice development processes both for our applications and our infrastructure.Code is under version control (Git), and features/fixes are developed in separate branches.Before being reviewed by a peer, code has to pass thousands of automated tests and is scanned for known security issues. The fix/feature is then manually tested (QA) and merged to the master code branch.We have separate testing, staging and production environments.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Lorem ipsum dolor sit amet consectetur adipiscing elit Ut et massa mi. Aliquam in hendrerit urna.
Real-time service health status available online with continuous monitoring and transparent incident reporting.
Physitrack Group is committed to maintaining the highest standards of security and privacy for our users. We appreciate the support of the security community in responsibly identifying potential vulnerabilities in our platform.
If you believe you have discovered a security vulnerability in our systems, we encourage you to report it to us at security@physitrack.com. Please include as much detail as possible to help us investigate and resolve the issue efficiently.
Security issues: 24 hours | Privacy requests: 72 hours
Scope
This policy applies to vulnerabilities in services hosted under the Physitrack and Champion Health domains. Vulnerabilities in third-party services should be reported directly to those providers.