PharmaOS
Security and data

Built to protect patient data

Pharmacies handle health information. PharmaOS is built so that protecting it is the default, not an option.
Your data

Kept in the UK, kept apart

Patient information is health data, so it gets the strictest handling from the start.

  • Stored and processed in LondonThe database and the servers that use it run in London, and data is encrypted in transit and at rest.
  • Each pharmacy's data is separateSeparation is enforced by the application and again by the database itself, and tested automatically on every change.
  • Staff see only what their role needsOwners, managers, pharmacists and other staff get different permissions, limited to the branches they work at.
  • Card details never touch PharmaOSOnline payments are handled by Stripe and paid straight into your pharmacy's own Stripe account.
Signing in

No passwords to steal

Most breaches start with a stolen or reused password. PharmaOS doesn't use them.

  • One-time codes by emailEveryone signs in with a short-lived code sent to their email, so there's no password to guess, reuse or phish.
  • A second step for staffPharmacy staff also enter a code from an authenticator app. Five wrong codes lock the second step for 15 minutes.
  • Sessions that end on their ownStaff are signed out after 30 minutes without activity, and after 12 hours at most, so an unattended counter screen doesn't stay open.
  • Limits on repeated attemptsSign-in and other sensitive requests are rate-limited, and requests from other websites are refused.
Accountability

A clear record of who did what

When something needs checking, the answer is in the record, not in someone's memory.

  • Tamper-evident audit logChanges to patients, appointments, payments and settings are recorded. Each entry is linked to the one before, so a missing or edited entry shows.
  • Subject access requestsOwners can export everything held about a patient in one step when they ask for a copy of their data.
  • Deletion requestsPatients can ask for their data to be deleted. Owners review each request within the legal one-month deadline, and approved requests are anonymised.
  • Nothing kept longer than neededStaff notifications are removed after 90 days, and notifications never include patient names.

Built to UK rules from the first line of code

PharmaOS is designed to follow UK GDPR and the Data Protection Act 2018, PECR, accessibility standards (WCAG 2.2 AA) and recognised security practice, including NCSC guidance and the OWASP application security standard. Card payments stay with Stripe.

Questions

Security questions

  • Your pharmacy is the data controller for its patients. SiteGrowth, which runs PharmaOS, processes that data on your behalf under a data processing agreement. A patient's PharmaOS sign-in account is SiteGrowth's responsibility.

  • Other pharmacies can't: the database itself keeps each pharmacy's data apart. SiteGrowth's admin tools show pharmacy claims and branch checks, not patient records.

  • No. It isn't a clinical record, a PMR, an EPS or prescribing system, or a medical device, and it doesn't make clinical decisions. Those stay with your pharmacists and the systems you already use.

  • As little as possible. Confirmation and reminder emails give the pharmacy, date and time, but not the name of the service, so a shared inbox doesn't reveal why someone is visiting.

  • Every pharmacy and every new branch is checked by a person against the GPhC register before patients can book, including a call to the pharmacy's NHS-listed phone number.

Found a security issue? Email info@pharmaos.co.uk with the details and we'll look into it straight away.

Get your pharmacy's booking page

Find your pharmacy in the NHS list, confirm your GPhC details and create your account. No password, and no card needed for the 14-day trial.

Claim your pharmacy