Skip to content
New sleep apnoea agreement announced for 1 January 2027. What changes for your centre

Security and hosting

PneumoTrack is installed in your hospital. Your patients’ data stays on your servers, under the control of your IT department.

Who gets in, and how

  • Hashed passwordsPBKDF2-SHA256 with 100,000 iterations and a per-user salt. The password is never stored in plain text.

  • Password policyAt least eight characters, with at least one uppercase letter, one lowercase letter and one digit.

  • Brute-force protectionAfter five failed login attempts, the account is locked for fifteen minutes.

  • Screen lockTwenty minutes of inactivity and the session locks. One click lets you switch user.

  • Limited sessionsA session lasts eight hours and is only extended while the user is working.

pneumotrack.hopital.local
Screen lock · sample data

Data kept safe, even when the network falters

Your server, your database

PneumoTrack is installed on a Windows server at the hospital and writes to your SQL Server. Backups, access and retention stay with your IT department.

Monitored connection

The database is checked every 15 seconds. If it stops responding, a red banner warns the user before any entry is lost.

Automatic recovery

A brief network outage triggers up to five retries. At startup, the software waits until the database is available.

Web protections

HTTPS enforced with HSTS, protection against request forgery, security headers against embedding in other pages and content sniffing.

pneumotrack.hopital.local
Manage agreements · sample data
Database connection lost, your changes will not be saved. (for 2 min)

Management software, not a medical device

PneumoTrack organises the administrative follow-up of agreements: dates, approvals, devices, providers. It makes no diagnosis and adjusts no device. The medical decision remains entirely with the doctor.

On the security roadmap

  • Role-based permissions by profile: doctor, technologist, admin staff, administrator
  • Sign-in with the hospital’s Active Directory accounts
  • Full audit log: who changed what, and when
  • Managed hosting in Belgium for centres without an available server

Everything else on this page works today.

Your IT department’s questions

Who is responsible for the data under the GDPR?

Your hospital, as the data controller. Installed on your premises, PneumoTrack sends us no patient data: we have no access to it, except during a support session that you request and control.

Does the software send data outside the hospital?

No patient data. The server occasionally queries our update channel and checks the licence. Without a connection, it keeps working for thirty days.

What infrastructure is needed?

A Windows server on the hospital network, with IIS or the built-in web server, and a SQL Server instance. Workstations simply use a recent browser.

Is PneumoTrack a medical device?

No. It handles the administrative follow-up of agreements and makes no diagnosis. It does not fall within the scope of European Regulation 2017/745 on medical devices.

Does your IT department have questions?

We answer your IT department directly: architecture, server requirements, backups, updates. Write to us or request a technical demo.