Data Ownership
Your clinic owns 100% of the health records and operational data you create in Sigma Health HMIS. Sigma claims no ownership over customer data and never sells, licenses, or monetises it in any form. You are the data controller; Sigma acts only as a processor on your behalf, following your instructions to store, organise, and retrieve your information.Encryption
All data in Sigma HMIS is encrypted at every stage — whether it is sitting in storage or moving between your device and our servers.At rest — AES-256 encryption: Every record stored in Sigma HMIS, including invoices, claim documents, payment reconciliation data, and patient identifiers, is encrypted using AES-256, the same standard used by financial institutions and government agencies worldwide.
In transit — TLS 1.3: All data transmitted between your browser or mobile device and Sigma’s servers is protected by TLS 1.3, the most current and secure version of the Transport Layer Security protocol. Connections that do not meet this standard are rejected automatically.
Tenant Isolation
Sigma HMIS is a multi-tenant platform, but your data is never commingled with another organisation’s. Each clinic operates inside a strictly isolated environment with dedicated logical boundaries. Access controls ensure that no other organisation — including other Sigma customers — can read or modify your data. Your environment behaves as if it were exclusively yours.Access Control
Sigma enforces role-based access control (RBAC) on every request made to the platform. When a staff member attempts to view a billing record, submit a claim, or reconcile a payment, the system checks their assigned role before granting access. Staff can only see and act on the data their role explicitly permits. Every access event is logged and audited. This means your administrators have a complete trail of who accessed what and when — essential for compliance reviews and incident investigations.Data Retention
Sigma retains your data for the duration of your active subscription. Here is what happens at each stage:Active Subscription
All data is retained in full and accessible to your team at any time. No data is purged while your account remains active.
After Cancellation
You have a 30-day export window from your cancellation date to download your full dataset. After this window closes, Sigma initiates permanent, irreversible deletion of your data.
Backup Rotation
Encrypted backup archives are maintained on a 90-day rolling rotation. Older backups are overwritten automatically, ensuring historical snapshots do not persist beyond this window.
Sub-processors
Sigma works with a limited set of third-party sub-processors to deliver the platform. These include cloud hosting and storage providers, transactional email services, and monitoring tools. Every sub-processor is bound by a Data Processing Agreement (DPA) that mandates security standards equivalent to or stricter than those Sigma applies to its own systems. Sigma does not engage sub-processors that are not contractually obligated to protect your data. You may request a current list of sub-processors by contacting privacy@sigmaconnect.org.International Data Transfers
If your clinic operates in a region where data may be processed or replicated across international borders, Sigma uses Standard Contractual Clauses (SCCs) — the legally recognised mechanism for lawful international data transfers — along with region-specific compliance protocols where required by local regulation. Your data is never transferred internationally without appropriate legal safeguards in place.Your Rights
As a Sigma HMIS account holder, your clinic administrator has the following rights over your data:- Data export: Request a complete export of all your clinic’s data at any time during your active subscription.
- Correction: Request the correction of any inaccurate account-level or operational records held by Sigma.
Sigma Health HMIS is an operational platform for licensed healthcare organisations. Pediatric data governance — including parental consent, minor record access, and age-appropriate data handling — is the responsibility of the treating institution under the applicable laws of its operating jurisdiction.