Straight answers to the questions we're most often asked by NHS and healthcare IT and information governance teams during procurement. If your question isn't answered here, get in touch and we'll answer it directly.
Medilitix is hosted entirely in the United Kingdom, on infrastructure dedicated to Medilitix - not a shared, multi-tenant cloud platform belonging to a third party we don't directly manage. Both the application and the database sit on UK-based infrastructure, and any off-site backup copy stays within the UK/EU. Nothing is processed or stored outside the UK or European Economic Area.
Back to topAll traffic between your browser and Medilitix is encrypted using HTTPS/TLS - any request over an unencrypted connection is automatically redirected to a secure one, and the certificate renews itself automatically rather than relying on anyone remembering to do it manually.
Passwords are never stored in plain text or in any reversible form. They're protected using an industry-standard, iterated, salted hashing algorithm designed specifically to resist brute-force attacks, with every comparison performed in a way that avoids leaking information through timing.
Session authentication uses an HttpOnly cookie, meaning it cannot be read by page scripts - this closes off one of the most common routes an attacker would use to steal a session even if they found another vulnerability on the page.
Back to topMedilitix is a multi-tenant platform - many separate organisations use one shared application - so keeping each organisation's data strictly separate from every other's is a foundational design requirement, not an afterthought. Every record belongs to exactly one organisation, and every request is scoped to the organisation of the person making it, resolved server-side from their authenticated session. A user can never see or act on another organisation's data by supplying a different ID or guessing a link.
A small number of platform-level administrative functions - such as setting up a new customer organisation - are restricted to a named, audited administrative role, gated by a control that cannot be granted through the ordinary permissions system. These actions go through a time-limited, single-use, fully logged process rather than a standing "all access" credential.
Back to topAccess within Medilitix is permission-based and configurable down to the individual user - over two dozen distinct permissions cover stock, purchasing, assets, procedures, maintenance, reporting and administration, so a user's access can be tailored precisely to their actual role rather than a single fixed "level." Role presets (such as Administrator or Ward Staff) exist to speed up setting up a new user, but the permissions actually enforced are always whatever is set on that individual account.
Access can also be scoped by physical location, independent of what a user is otherwise permitted to do - useful for larger, multi-site organisations who want staff confined to their own site or ward.
Supported sign-in methods include standard email/password, a PIN-based flow suited to shared devices such as ward kiosks, and passkey (WebAuthn) authentication. Login attempts, password resets and similar authentication events are rate-limited to reduce the risk of automated credential-guessing attacks.
Back to topEvery significant action in Medilitix is recorded in a dedicated audit trail - who did it, what organisation they belong to, what changed, and a record of the data both before and after the change, along with the time and originating IP address. This covers sensitive actions specifically, including user account changes, permission changes, and any administrative access to another organisation's data.
We apply two different retention periods, matched to what each type of record is actually for:
Medilitix undergoes independent third-party penetration testing on a quarterly basis. Alongside this, we run continuous internal vulnerability scanning and provide ongoing cyber security awareness training for our team, so assurance doesn't rest on a single point-in-time test alone.
We are actively working towards Cyber Essentials certification. If Cyber Essentials, Cyber Essentials Plus, or a specific compliance framework is a requirement for your organisation, please raise it with us directly and we'll confirm our current position.
Back to topData is backed up regularly and copied to a separate, off-site location distinct from the primary hosting environment, so a single point of failure does not put customer data at risk of permanent loss. We hold cyber insurance, and maintain internal protocols for data breach reporting under UK GDPR, with a named individual holding responsibility for that process.
As with any software supplier, our liability is governed by our standard terms and conditions, available on request. This sits alongside - not instead of - the preventative measures described throughout this page, which are what we consider the more meaningful protection for your data in practice.
Back to topThis page is intentionally a summary. If you're carrying out a formal security or information governance assessment - a Data Protection Impact Assessment, a Data Processing Agreement, or a supplier due diligence questionnaire - we're happy to work through it directly and provide more specific detail than is practical to publish here.
For our approach to personal data more broadly, see our Privacy Policy. Medilitix is a brand name of Williams Medical Supplies. More details about our approach to data protection at a group level can be found at wms.co.uk/privacy-policy.
Who are we?
Medilitix is a brand name of Williams Medical Supplies, one of the leading providers of medical supplies and services to the UK healthcare market.
How to contact us
Williams Medical Supplies LtdWe aim to respond to security and data protection enquiries within 2 working days.
Back to top