SECURITY BY DESIGN

Hospital access built around identity, roles and tenant boundaries

ZelaHMS uses layered application controls for hospital workspaces. Security claims on this page describe platform controls rather than external certifications.

Tenant isolation

Hospital-owned records are scoped to the resolved tenant so one organisation cannot use another organisation's workspace identity.

Role permissions

Staff access is controlled by roles and granular panel permissions for clinical, financial and administrative work.

Two-factor security

2FA enrollment, challenge flows, recovery controls and step-up checks are available for sensitive actions.

Session controls

Security sessions, trusted devices and session revocation reduce risk when credentials or devices change.

Audit-aware actions

Clinical and administrative workflows retain user attribution and audit information where supported by each module.

Domain ownership

Custom domains use a hospital-controlled DNS TXT verification token before the domain can become a verified workspace.

Custom-domain security lifecycle

Add the hospital hostname, publish the generated DNS verification record, verify ownership, point the hostname to the server, configure it in Plesk and provision SSL. ZelaHMS does not claim SSL is issued automatically unless the hosting layer is configured to do so.

TXT _zelahms-verification.hms.hospital.org
zelahms-verification=<unique-token>