Oracle Healthcare
Oracle Healthcare Compliance & Trust
Security, privacy and data-governance principles for a connected digital healthcare platform.
Last updated: 28 August 2026
Overview
Oracle Healthcare is designed with security, privacy and data-governance principles appropriate for a connected digital healthcare platform. This page provides an overview of the compliance and trust framework that underpins the platform.
Oracle Healthcare is designed to support applicable data protection and privacy requirements, including the Zimbabwe Cyber and Data Protection Act and applicable telemedicine guidelines. We do not claim certifications or regulatory approvals that have not been obtained. Where applicable, we work towards alignment with recognised healthcare data protection standards.
Data Protection
Oracle Healthcare processes personal and health information in accordance with applicable data protection principles. We practise data minimisation — collecting only the information necessary for providing healthcare services. Personal data is processed lawfully, fairly and transparently, with appropriate consent mechanisms in place.
Patients have control over their data through consent settings, access permissions and account deletion options. Health information is treated as sensitive data and is subject to additional protections.
Privacy
Our Privacy Policy, available at /privacy-policy, provides detailed information about how personal information is collected, used and protected. We do not sell personal or health information. Information is shared only where necessary to provide services, where consent has been given, or where required by law.
Security
Oracle Healthcare uses encryption to protect data in transit and at rest. Authentication is required to access the platform, and sensitive health records are protected through additional access controls. We monitor for security threats and respond to potential incidents in accordance with our incident management procedures.
While no system can guarantee complete security, we take appropriate technical and organisational measures to protect your information and continuously work to improve our security practices.
Role-Based Access
Access to information on Oracle Healthcare is controlled through role-based permissions. Each user role (patient, doctor, institution administrator, pharmacy, laboratory, government, super admin) has defined access rights appropriate to its function. A patient can only access their own health information. A doctor can only access records of patients they are treating. An institution administrator can only manage their own institution. Government users can only access aggregated, anonymised data.
Patient Consent
Patients control who can access their health information through consent settings. Consent can be granted or withdrawn for AI processing, data sharing, family proxy access and healthcare provider access. Consent choices are respected across the platform and can be managed through the patient dashboard.
Audit Trails
Oracle Healthcare maintains audit trails that log access to sensitive health information. These logs record who accessed what information, when and through what action. Audit trails support accountability, enable investigation of unauthorised access and help maintain the integrity of health records.
Healthcare Data Governance
Oracle Healthcare follows data-governance principles designed for a healthcare platform. Health data is classified according to sensitivity level, with sensitive information (such as HIV status, mental health information and genetic data) subject to additional access controls. Data governance policies define how information is collected, stored, accessed, shared and retained.
Access Controls
Access to the platform requires authentication. Sensitive health records require additional authorisation. Institution administrators manage staff access within their institutions. Super administrators oversee platform-wide access and can review audit logs. Access permissions are regularly reviewed and updated.
Data Minimisation
We collect only the information necessary to provide healthcare services. Where data is no longer needed, it is deleted or anonymised in accordance with our data retention policy. We avoid collecting unnecessary personal information and limit data collection to what is required for the stated purpose.
Secure Authentication
Oracle Healthcare uses secure authentication methods, including password-based login and two-factor verification where enabled. Account credentials are stored securely using appropriate hashing and encryption. Users are encouraged to use strong passwords and enable two-factor verification where available.
AI Governance
AI-powered features on Oracle Healthcare, including symptom assessment, are designed to provide preliminary, indicative information only. AI outputs do not constitute a medical diagnosis and must not be relied upon as a substitute for professional medical advice. AI assessments are stored in the patient record and may be reviewed by a qualified healthcare professional. We are transparent about the limitations of AI features and provide clear disclaimers.
Clinical Responsibility
Oracle Healthcare is a technology platform and does not itself provide medical services. Clinical decisions — including diagnosis, treatment and prescription decisions — are the responsibility of qualified, licensed healthcare professionals. The platform facilitates the delivery of healthcare services but does not direct or supervise clinical practice. Healthcare professionals using the platform are responsible for maintaining valid licences and complying with applicable healthcare regulations.
Incident Management
Oracle Healthcare maintains procedures for identifying, investigating and responding to security and data incidents. Where a data breach occurs that may affect your personal information, we will take appropriate steps to investigate, mitigate and notify affected users in accordance with applicable legal requirements.
Business Continuity
We maintain measures to support the continued availability of the platform, including data backups and recovery procedures. While we cannot guarantee uninterrupted service, we work to minimise downtime and recover quickly from any disruptions.
Interoperability
Oracle Healthcare is designed to connect patients, doctors, pharmacies, laboratories and institutions through a single platform. Where available, the platform supports the electronic exchange of prescriptions, laboratory orders and results, and health records between connected providers. Interoperability depends on the participation and capabilities of connected providers.
Government and Public Health Data Principles
Government and public health users access aggregated, anonymised data through dedicated dashboards. This data is used for population health monitoring, healthcare access analysis and service planning. Government dashboards are designed to show population-level statistics and should not expose identifiable patient information. Access to government dashboards is restricted to authorised personnel and is subject to role-based permissions.
Contact Us
For any compliance or trust-related enquiries, please contact us:
Email: support@oraclehealthcare.com
Phone: +263 (24) 274 5000
Location: Harare, Zimbabwe
