SECURITY & TRUST

Built for controlled clinical coordination.

MedShift Call focuses on the safeguards clinical teams expect from scheduling software: tenant boundaries, scoped administration, audit trails, and secure deployment defaults.

Tenant Isolation

Organizations, departments, users, schedules, holidays, and settings are scoped by tenant so one department portal cannot read or update another portal by design.

Role-Based Access

System administrators, department administrators, staff, and platform administrators have separate access paths and permissions.

Audit History

Schedule, staff, department, and trade actions are logged so administrators can review operational changes and accountability trails.

Authentication Controls

Sessions are signed with deployment-provided secrets, cookies are HTTP-only, and email MFA can be enabled for additional login verification.

Encrypted Transport

Production deployments should run behind HTTPS and connect to PostgreSQL with certificate-verified TLS where the database provider supports it.

Minimal Operational Data

The service is designed around professional contact information, department roles, qualifications, schedules, notifications, and audit records.

Compliance posture

MedShift Call is a scheduling and coordination tool, not an emergency dispatch system or electronic medical record. Healthcare organizations should confirm their own regulatory requirements, data-processing terms, and internal policies before production rollout.

Ask About Security