ZelaHMS uses layered application controls for hospital workspaces. Security claims on this page describe platform controls rather than external certifications.
Hospital-owned records are scoped to the resolved tenant so one organisation cannot use another organisation's workspace identity.
Staff access is controlled by roles and granular panel permissions for clinical, financial and administrative work.
2FA enrollment, challenge flows, recovery controls and step-up checks are available for sensitive actions.
Security sessions, trusted devices and session revocation reduce risk when credentials or devices change.
Clinical and administrative workflows retain user attribution and audit information where supported by each module.
Custom domains use a hospital-controlled DNS TXT verification token before the domain can become a verified workspace.
Add the hospital hostname, publish the generated DNS verification record, verify ownership, point the hostname to the server, configure it in Plesk and provision SSL. ZelaHMS does not claim SSL is issued automatically unless the hosting layer is configured to do so.