1. Home
  2. Features
  3. Medical data security — in the architecture, not in promises

Levion features

Medical data security — in the architecture, not in promises

Medical data is the most sensitive information a clinic holds — and Israel's Privacy Law Amendment 13 has made the responsibility for it more binding than ever. That's why security in Levion is not a layer added at the end: it is enforced in the database itself, automatically tested on every change, and designed so that even we — the platform operators — cannot see your medical data.

Last updated: 2026-08-11

How Levion protects your clinic's data

What is Row Level Security — and why does it matter to your clinic?

In most systems, separation between customers happens in application code: the developer adds an "only this clinic" condition to every query. That works — until the one line someone forgot. In Levion, isolation lives inside the database itself: every record belongs to a clinic, and the database physically refuses to return another clinic's data. Even a bug in the application code cannot expose another clinic's data. On top of that, the browser never holds direct access to the database or storage — and this isolation is automatically tested for every module, as part of 388 automated tests that run on every change to the system.

Who can see the medical data? Not even us

Patients' medical data is visible only to your clinic's staff, according to role permissions — and it ends there. Levion platform administrators are structurally blocked from patient data: the system is built so they see aggregates only, never records. This is not an internal policy that can be bypassed — it is the architecture. Alongside it, every action on a record is automatically written to an append-only audit log: there is always a complete, unrewritable trail of who did what and when.

Does Levion meet Amendment 13 requirements?

Levion is designed around the requirements of Israel's Privacy Law Amendment 13 — which imposes heightened security, documentation and oversight duties on medical databases — and around GDPR and HIPAA principles: recorded consent with a stored consent version, patient rights, audit logging and lawful record retention. Data-processing agreements are signed as part of onboarding. We word this deliberately: we don't present certificates — we present an architecture built around the regulation's principles, and you can examine it in any demo.

Security & privacy FAQ

How is data separated between clinics?

Every record belongs to a clinic, and isolation is enforced at the database layer (Row Level Security) — not in code. Even an application bug cannot expose another clinic's data, and isolation is automatically tested per module.

Who can see patients' medical data?

Only your clinic's staff, according to their role permissions. Levion platform administrators are structurally blocked from medical data — they see aggregates only.

What if a patient is deleted by mistake?

Patients can't be deleted — only archived. Every action is written to an append-only audit log, so there is always a complete record of who did what and when.

Does Levion meet Amendment 13 requirements?

Levion is designed around Israel's Privacy Law Amendment 13 and GDPR and HIPAA principles: recorded consent, patient rights, audit logging and record retention. Data-processing agreements are signed as part of onboarding.

How are patient files and documents stored?

In private storage, never public. A file is accessed only through a signed link with a short expiry, according to the user's permissions — and the browser never gets direct access to the storage itself.

Want to see it up close?

Book a personal demo — we'll walk through your own clinic's scenarios together.

WhatsApp