Record-by-record protection
Protected by default
Each health record is protected separately, so one problem cannot expose everything.
Every Fastclinic product inherits secure identity, an auditable ledger, and patient-controlled records from one shared platform.
Shared infrastructure
Product surfaces stay distinct. Their security primitives do not.
FastLogin
Identity
FastCredits
Ledger
OneHealth
Records
Doorcta
Care delivery
Every product inherits
Each product solves a distinct healthcare problem. Identity, payments, records, and audit remain one shared foundation.
Shared foundation
Build the care surface once. Inherit the controls underneath.
Identity
FastLogin
Ledger
FastCredits
Records
OneHealth
The technology stays in the background. You get clearer control, safer access, and records that can move with you.
Record-by-record protection
Each health record is protected separately, so one problem cannot expose everything.
Time-limited permission
Access is granted for a specific reason and time, and can be withdrawn when it is no longer needed.
Tamper-evident history
Fastclinic records when protected information is viewed and keeps a history that cannot be quietly rewritten.
Open healthcare format
Your records can be prepared in a recognised healthcare format for another provider or system.
Patients, providers, and developers use different surfaces while inheriting the same platform guarantees.

Grant access
Authorise a verified provider for a stated purpose and duration.
Review activity
Every permitted read appears in the patient-visible audit history.
Revoke or expire
Consent closes immediately at revocation or scheduled expiry.

Open a scoped session
The session checks identity, purpose, consent, and available credits.
Read what is permitted
Each record access is scoped, timestamped, and hash-chained.
Close and reconcile
Completed usage is captured and unused held credits are released.

Register one OAuth2 client
Send users to FastLogin and receive standards-based scoped tokens.
Call shared services
Use the same identity context for balances, sessions, and record export.
Inherit the controls
Authentication, billing semantics, consent, and audit arrive together.
Moving provider or keeping a personal copy? Request your records and download a secure package you can use outside Fastclinic.
Step 1
Choose the health information you want to include.
Step 2
Your care history, results, documents, and access history are collected into one protected package.
Step 3
Keep it for yourself or provide it to another healthcare provider.
Organised for people, not file systems
Protected while it is prepared. Organised so another compatible health system can understand it. Includes a simple guide.
The controls are part of the platform architecture, not optional integrations added after clinical data arrives.
Every record has its own AES-256-GCM key, sealed by a KMS-held master key. A compromise cannot cascade across the record store.
Append-only events reference the previous hash. Daily roots are retained in write-once storage for seven years.
Passkeys, TOTP, and one-time backup codes protect every account without an SMS fallback.
Each DSAR archive includes an Ed25519 signature so patients can verify its manifest independently.
Access grants are purpose-bound, time-boxed, revocable, and enforced before protected records are returned.
Nigerian governance, implemented in the platform
Fastclinic Limited (RC 1919428) operates under the Nigeria Data Protection Act 2023 and NDPR-aligned controls for identity, consent, audit, retention, and data-subject access.
Direct answers about identity, credits, records, audit, compliance, and hosting.
Bring one facility, one care path, and your integration requirements. We will map the identity, billing, and records flow.