Law 172-13 · Personal data

Your patients' data, protected as Dominican law requires

A clinical record is the most sensitive data a practice handles: Law 172-13 treats health information as sensitive data and requires protecting it. This is what Sonrisario builds underneath — verifiable mechanisms, not trust badges.

What Law 172-13 asks of your practice

Law 172-13 on personal data protection classifies health information as sensitive data: it requires consent to process it, security measures proportional to the risk, and honoring the patient's rights — access, rectification, cancellation and objection.

The data controller is the practice; Sonrisario acts as processor, with the obligations that role carries. The practical difference: the software you choose IS part of your security measures, and answering “the data is in the system” only protects you if the system actually protects.

That's why every mechanism on this page exists: they aren't premium features or boxes someone must remember to tick — they come enabled on every plan, because the law doesn't distinguish by plan.

Your records, treated as what they are

Bank-grade encryption
AES-256-GCM for ID numbers, phones and addresses; the master key never leaves our servers — not even in a backup.
One practice cannot see another
Row-level policies in the database engine itself: a malformed query returns nothing, never someone else's data.
Every access is recorded
Append-only audit log, as the clinical record regulation requires: no one edits or deletes a line — not us either.
Two-step sign-in, required
Two-step sign-in for all clinical access, enabled by default — not a checkbox anyone has to remember.
A signed agreement with every provider
DPA in force with all four operating providers, archived with an integrity hash.
Leaving is as easy as joining
Full and per-patient copy in one click; revoking the data consent stops the processing.

For auditors and regulators

We tell you where your data lives and on what legal basis: it resides in the United States (AWS, us-west-1 region) and that transfer rests on consent, not on an adequacy decision we neither hold nor invoke. The practice is the controller and we are the processor, with the obligations that entails. And the rights of access, rectification, erasure and objection are not a promise in the legal text: they are built into the product and exercised without asking us.

The full technical detail of encryption and processing lives in the Privacy policy — written to be read, not to hide.

Protect the records without thinking about it

Everything on this page ships by default, on every plan.