Trust & Compliance

Accreditations & Certifications

Handing over your medical history to a platform you've never physically walked into takes a certain amount of trust. This page exists to earn that trust honestly, by showing exactly which standards we hold ourselves to, what each one actually means in practice, and how it protects you as a patient or doctor using Doctiplus.

HIPAA Compliant

Patient health information handled under US privacy and security standards

End to End Encryption

TLS 1.2 and above in transit, AES 256 for stored medical data

Verified Doctors

Every provider's license and credentials checked before they see patients

PCI DSS Aligned Payments

Card data processed through PCI compliant payment partners, never stored by us

Independent Security Audits

Regular vulnerability assessments and penetration testing of our infrastructure

GDPR Aware Practices

Data handling designed with EU data protection principles in mind for international users

01

HIPAA Compliance

HIPAA, the Health Insurance Portability and Accountability Act, is the US federal standard for how medical information has to be handled, and it's the baseline we hold ourselves to across the entire platform, not just for US based users. In practice, this shows up as specific engineering and operational decisions rather than a certificate on a wall.

Access Controls

Medical records are visible only to the patient, their treating doctor, and a small number of authorized staff who need access to resolve a support issue. Every access is logged.

Business Associate Agreements

Third party vendors that touch any part of our infrastructure, from hosting to payment processing, are held to HIPAA compliant handling through formal agreements before we work with them.

Staff Training

Anyone with access to patient data goes through privacy and security training before that access is granted, and periodically afterward.

Breach Response Plan

We maintain a documented process for identifying, containing, and disclosing any data incident in line with HIPAA notification requirements, should one ever occur.

For the full detail on what data we collect and how it's used, see our Privacy Policy.

02

Doctor & Provider Licensing

A platform is only as trustworthy as the people practicing on it. Before any doctor is allowed to accept a booking on Doctiplus, they go through a verification process that isn't just a formality.

License Verification

Every doctor's active medical license is checked directly against the issuing medical board or council in their jurisdiction.

Credential Review

Board certifications, residency training, and specialty qualifications are reviewed before a provider is listed under that specialty.

Background Screening

Providers pass a background check as part of onboarding, consistent with standard practice for telehealth platforms.

Ongoing Re-verification

Licenses are periodically re-checked to confirm they remain active and in good standing throughout the time a doctor practices on Doctiplus.

Doctors practice independently. Doctiplus verifies credentials and provides the platform, but each doctor exercises their own clinical judgment. See our Terms of Service for more on how this works.

03

Data Security Standards

Security isn't a single feature, it's a set of layers that each catch what the others might miss. Here's what sits behind the scenes of every consultation, lab result, and message on Doctiplus.

Encryption in Transit and at Rest

All traffic between your device and our servers is encrypted using TLS 1.2 or higher. Stored medical records receive AES 256 encryption on top of that.

Infrastructure Aligned With SOC 2 Principles

Our hosting environment follows the security, availability, and confidentiality principles that underpin the SOC 2 framework, with monitored access and redundant backups.

Vulnerability Testing

We run periodic vulnerability scans and engage independent security reviewers to test our systems for weaknesses before they become problems.

Backup & Disaster Recovery

Encrypted, redundant backups and a documented recovery plan protect against data loss from hardware failure or unforeseen incidents.

04

Payment Security

We never see or store your full card number. Payments for consultations, lab tests, and home care bookings are handled by PCI DSS compliant payment processors, meaning your card details are tokenized and processed in an environment built specifically to meet the Payment Card Industry Data Security Standard. Doctiplus's own servers only ever see a payment confirmation, not your raw card data.

05

International Data Protection

Because Doctiplus serves patients across 33 US states and more than 50 countries, we can't design around a single country's rulebook. Where users interact with us from the European Union or United Kingdom, we apply data handling practices consistent with GDPR principles, including data minimization, purpose limitation, and honoring access and deletion requests as described in our Privacy Policy. In every region we operate, the goal is the same: collect only what a service genuinely needs, and protect it accordingly.

06

Ongoing Monitoring

Compliance isn't something you achieve once and file away. Licenses expire, threats evolve, and regulations change. Our security and compliance practices are reviewed on a recurring basis, not treated as a box checked at launch and forgotten. If you ever notice something that seems inconsistent with what's described on this page, we want to hear about it directly.

07

Contact Us

Questions about our compliance practices, security posture, or a specific certification are welcome.

Email

inquiry.doctiplus@gmail.com

For compliance and security inquiries

Phone

308-140-59-38

Monday - Friday, 9 AM - 6 PM

Address

Uxmal 319-345, Narvarte Poniente

Benito Juárez, 03020 Ciudad de México

CDMX, Mexico

Website

doctipluss.com

Visit our main website