Security and hosting
PneumoTrack is installed in your hospital. Your patients’ data stays on your servers, under the control of your IT department.
Your hospital network
PneumoTrack
Hospital Windows server
SQL Server
Your database, your backups
No patient dataleaves the network
Updates and licencechecked occasionally, 30-day offline grace period
Who gets in, and how
-
Hashed passwordsPBKDF2-SHA256 with 100,000 iterations and a per-user salt. The password is never stored in plain text.
-
Password policyAt least eight characters, with at least one uppercase letter, one lowercase letter and one digit.
-
Brute-force protectionAfter five failed login attempts, the account is locked for fifteen minutes.
-
Screen lockTwenty minutes of inactivity and the session locks. One click lets you switch user.
-
Limited sessionsA session lasts eight hours and is only extended while the user is working.
Data kept safe, even when the network falters
Your server, your database
PneumoTrack is installed on a Windows server at the hospital and writes to your SQL Server. Backups, access and retention stay with your IT department.
Monitored connection
The database is checked every 15 seconds. If it stops responding, a red banner warns the user before any entry is lost.
Automatic recovery
A brief network outage triggers up to five retries. At startup, the software waits until the database is available.
Web protections
HTTPS enforced with HSTS, protection against request forgery, security headers against embedding in other pages and content sniffing.
Management software, not a medical device
PneumoTrack organises the administrative follow-up of agreements: dates, approvals, devices, providers. It makes no diagnosis and adjusts no device. The medical decision remains entirely with the doctor.
On the security roadmap
- Role-based permissions by profile: doctor, technologist, admin staff, administrator
- Sign-in with the hospital’s Active Directory accounts
- Full audit log: who changed what, and when
- Managed hosting in Belgium for centres without an available server
Everything else on this page works today.
Your IT department’s questions
Who is responsible for the data under the GDPR?
Your hospital, as the data controller. Installed on your premises, PneumoTrack sends us no patient data: we have no access to it, except during a support session that you request and control.
Does the software send data outside the hospital?
No patient data. The server occasionally queries our update channel and checks the licence. Without a connection, it keeps working for thirty days.
What infrastructure is needed?
A Windows server on the hospital network, with IIS or the built-in web server, and a SQL Server instance. Workstations simply use a recent browser.
Is PneumoTrack a medical device?
No. It handles the administrative follow-up of agreements and makes no diagnosis. It does not fall within the scope of European Regulation 2017/745 on medical devices.
Does your IT department have questions?
We answer your IT department directly: architecture, server requirements, backups, updates. Write to us or request a technical demo.