Secure homeopathy practice software: what to look for
"Secure" is the most overloaded word in clinical-software marketing and the least useful when it stands alone. A clinic choosing practice software is not buying a slogan; it is buying a specific set of technical and contractual controls that, taken together, let it meet its duties under HIPAA's Security Rule at 45 CFR 164.312 and the GDPR's security-of-processing obligation at Article 32 of Regulation (EU) 2016/679.
The dimensions that actually decide security
Security for a practice is a stack, not a feature. Eight dimensions cover almost every clinic's risk surface, and any evaluation that omits them is incomplete. Each row names a dimension, its legal anchor, and what Similia (cloud-native, subscription) and RadarOpus (desktop-native, licence) publicly state or imply. Gaps in the vendor columns are not confirmed absences but items to verify directly with the vendor.
| Dimension | Legal anchor | Similia (published documentation) | RadarOpus (public sources) |
|---|---|---|---|
| Encryption in transit | 45 CFR 164.312(e); GDPR Art. 32 | TLS 1.3 stated | TLS standard for cloud/web; desktop local storage — confirm with vendor |
| Encryption at rest | 45 CFR 164.312(a)(2)(iv); GDPR Art. 32 | AES-256 stated | Local-first desktop; encryption of local DB — confirm with vendor |
| Access control and authentication | 45 CFR 164.312(a),(d) | Password-protected accounts; explicit opt-in case sharing | Per-device desktop access; confirm multi-user role separation with vendor |
| Audit logging | 45 CFR 164.312(b) | Access-event logging — confirm scope with vendor | Not publicly documented; confirm with vendor |
| Processor contract (BAA / Art. 28) | 45 CFR 164.504(e); GDPR Art. 28 | BAAs signed with AI subprocessors (OpenAI, Deepgram); clinic BAA/Art. 28 available on request | Desktop-local model reduces cloud-processor exposure; confirm any cloud-sync or AI subprocessors with vendor |
| Consent management | GDPR Arts. 6, 9; ePrivacy Art. 5(3) | Separate privacy/GDPR consent and AI-processing consent in Settings | Not publicly documented; confirm with vendor |
| Data portability and export | GDPR Art. 20 | Full data export available in-app | RTF/PDF/Word export confirmed |
| Deletion and retention control | GDPR Art. 17 | Account deletion removes cases and data server-side, subject to legal requirements | Local data under clinic's own control; confirm cloud-backup deletion with vendor |
The table is a due-diligence checklist, not a verdict. A product that ticks encryption but offers no audit log, or encrypts data but provides no Article 28 contract, is not secure for a regulated practice — it is partially secure in a way that leaves the clinic carrying the gap.
Encryption: necessary, not sufficient
Almost every credible vendor now encrypts data in transit with modern TLS and at rest with AES-256. That is the floor, not the differentiator. Under the HIPAA Security Rule, encryption at rest is technically an "addressable" specification at 45 CFR 164.312(a)(2)(iv), meaning a clinic must implement it or document an equivalent safeguard; in practice, absence of at-rest encryption is hard to defend. Under GDPR Article 32, encryption is named as an example of an appropriate measure "taking into account the state of the art," which makes strong, current ciphers the expected baseline rather than a premium.
Similia documents TLS 1.3 in transit and AES-256 at rest. Those are current, defensible primitives. The questions worth asking any vendor: who holds the keys, whether backups are encrypted to the same standard, and whether the export path preserves that protection. Encryption is where comparison shopping starts, not where it ends.
Access control, authentication, and audit logging
The Security Rule's technical safeguards at 45 CFR 164.312 require access control, person-or-entity authentication, and audit controls — the ability to record and examine activity in systems that contain electronic PHI. The practical test for a homeopathic practice is whether each user has an individual account, whether case sharing is explicit and revocable, and whether the system records access events.
Similia uses password-protected accounts with opt-in case sharing handled by a secure invitation to a named colleague. Explicit, revocable sharing is the correct default for confidential records. A practice with multiple practitioners should additionally confirm how individual accountability is maintained across shared cases and whether an access log is available for review, since audit controls are a named Security Rule standard.
The contract layer: BAAs and Article 28 agreements
Technical controls are only half of security; the other half is contractual. The moment a vendor stores or processes patient data on a clinic's behalf, HIPAA requires a business associate agreement under 45 CFR 164.504(e), and GDPR requires a controller–processor contract under Article 28, each binding the vendor — and, critically, its subprocessors — to defined obligations. AI providers that touch case notes are subprocessors and must be covered.
Similia states it has signed BAAs with its AI subprocessors (OpenAI, Deepgram), runs zero-retention processing for covered AI data, does not let submitted patient data train AI models, and requires a separate AI-processing consent toggle in Settings > Privacy before AI features touch any record. A clinic relying on these features should obtain its own BAA or Article 28 contract from the vendor, request the current subprocessor list, and confirm zero-retention terms in writing. A claim on a help page is the starting point of a contract negotiation, not a substitute for one.
Consent, portability, and deletion
GDPR adds obligations that pure-security framing can miss. Processing lawful bases must be separated: clinical processing may rely on Article 9(2)(h) in its own right; marketing and AI processing each require a distinct basis — typically explicit consent under Article 9(2)(a). The ePrivacy Directive's Article 5(3) governs cookies on the practice website separately. Portability under Article 20 and erasure under Article 17 mean a clinic must be able to export the full record and delete it on request.
Similia separates privacy/GDPR consent from AI-processing consent, supports a full in-app export of patient data, and removes account data server-side on deletion subject to any retention obligations imposed by law. Configurable consent plus a working export path is exactly what these articles require of the controller's tooling. The clinic still owns the obligation; the software either makes it operable or it doesn't.
Where vendor claims end and configuration begins
The recurring pattern across every dimension above is that a vendor supplies capability and the clinic supplies compliance. "HIPAA-ready" and "GDPR-compliant" are statements about what a platform can do; a clinic becomes compliant only when it has run a Security Rule risk analysis, signed the contracts, configured access and consent correctly, and documented a breach-response plan keyed to HIPAA's 60-day and GDPR's 72-hour clocks. No purchase discharges those duties. Any vendor security page — including the ones cited in the references below — is a checklist of items to verify, not a certificate to rely on.
Verdict
Secure practice software is the product that lets a clinic satisfy 45 CFR 164.312 and GDPR Article 32 without fighting the tool — strong current encryption, individual access control, audit logging, a signed processor contract covering AI subprocessors, granular consent, and clean export and deletion. Score any candidate against the eight-row table above before committing a single patient record. Then verify every claim with the vendor and your own legal counsel, because the clinic, not the software, carries the legal duty. Practitioners evaluating one cloud-native option against this rubric can read Similia's own published security documentation directly.
References
U.S. Department of Health and Human Services (2013) Security Standards for the Protection of Electronic Protected Health Information (HIPAA Security Rule), 45 CFR Part 164 Subpart C, §§164.308(b), 164.312, and Privacy Rule §164.504(e), https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164.
European Parliament and Council (2016) Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 6, 9, 17, 20, 28, 32, Official Journal L 119, https://eur-lex.europa.eu/eli/reg/2016/679/oj.
European Parliament and Council (2002) Directive 2002/58/EC (ePrivacy Directive), Article 5(3), as amended by Directive 2009/136/EC, Official Journal L 201, https://eur-lex.europa.eu/eli/dir/2002/58/oj.
Similia (2026) "Is my patient data secure?", Similia Help Centre, https://similia.crisp.help/en/article/is-my-patient-data-secure-sxmdfd/, fetched 2026-04-22.
Similia (2026) "Managing Cases and Follow-ups", Similia Help Centre, https://similia.crisp.help/en/article/managing-cases-and-follow-ups-1k32vr2/, fetched 2026-04-22.
RadarOpus / radar-uk.co.uk (2026) "RadarOpus Software — Features", https://www.radar-uk.co.uk/software/, fetched 2026-06.
Zeus Soft (2026) "RadarOpus AI — Homeopathic Practice Partner", https://ai.zeus-soft.com/, fetched 2026-06.
Verdict
Ready to act on this?