_Last updated: 16 September 2026_
These Terms of Use are the agreement between you and the operator of the CareClinic platform ("the platform", "we", "us") covering every way the platform can be used: a clinic's management system, the mobile app for doctors, the employer/HMO portal, and the patient portal.
Which parts apply to you. Sections 1 to 9 apply to everyone. Then read the one section for how you use the platform
— Clinic management system, Doctor mobile app, Employer and HMO portal,
or Patient portal. Sections 14 to 23 cover payment and the legal terms, and matter mainly to the clinic that holds the account.
1. Who we are
The platform is operated by ACCESS Software Solutions, with registered address at San Luis, Baguio City, Philippines and DTI registration number 3377044 ("the operator").
You can reach us through the contact form on the public portal or through [email protected]. If you are a patient, your clinic is your first point of contact for anything about your records.
2. Who these Terms apply to
These Terms apply to everyone who uses the platform:
- Clinics that hold an account, and their owners and administrators.
- Doctors, nurses and clinic staff who sign in to the management system or the mobile app.
- Employers and HMOs given access to a portal, and their staff.
- Patients who use a clinic's patient portal or book an appointment online.
- Visitors to the public portal and to a clinic's public website.
2.1 The clinic is our customer
The clinic holds the account. Everyone else — its staff, an associated employer, a patient — uses the platform through that clinic's account. If you are not the clinic, your access exists because a clinic granted it and can be changed or withdrawn by that clinic.
2.2 How you accept these Terms
Where you sign up yourself, we ask you to tick a box. There is one checkbox — "I have read and agree to the Terms of Use and the Privacy Policy" — and it must be ticked before the form will go through. You will see it in two places:
- Registering as a doctor, whether you are joining an existing clinic or opening your own.
- Requesting an appointment, on the last step of the booking form, whether you book from a clinic's own page or from the public portal.
We record the date and time you ticked it, so both you and we can tell when the agreement was made. We do not keep a copy of the documents as they stood that day; the current version is always the one on this page.
Everywhere else — a member of staff signing in to an account the clinic created for them, for example — no box is presented and using the platform means accepting these Terms. If you do not accept them, do not use the platform.
3. What the platform is, and what it is not
The platform is software for keeping records and running a clinic's day-to-day work. That is the whole of what it does, and the following is worth stating plainly:
- It is not a medical device and is not certified as one.
- It does not give clinical advice and does not practise medicine. It does not check dosages, flag drug interactions, suggest diagnoses, or review anything a clinician enters. The prescribing checks described in section 10.15 are formal ones — is a generic name present, is a licence number on file — and are not a clinical review.
- It is not a substitute for professional judgement. Every clinical decision recorded through the platform is the decision of the clinician who made it.
- It is not for emergencies. Nothing on the platform — a message, an upload, a notification — should ever be relied on to get urgent help. In an emergency, contact the clinic directly or your local emergency services.
- It is not a payment gateway. The platform records payments that clinic staff enter as a record of money received. It does not process, hold or transfer funds, and it never stores card numbers.
- It is not a pharmacy. A clinic can use it to run a dispensing counter — recording what was sold, taking the money and deducting the stock — but the platform does not itself dispense medicine, hold stock, or decide that a sale is appropriate. Every one of those is the clinic's act, performed by its own staff under its own licence. See section 10.12.
- It does not check that a clinic may lawfully sell what it is selling. It does not verify a pharmacy licence, a registered pharmacist's supervision, or whether a medicine may be sold over the counter at all.
- It is not an accredited receipting system. A receipt it prints is the clinic's own record of a transaction, not a BIR-registered official receipt or sales invoice. See section 10.13.
4. Accounts and credentials
- Accounts are personal. Each person who signs in must have their own account, and must not share their password or let anyone else use their account.
- What is done through an account is attributed to the account holder in the clinic's audit trail.
- You must use a strong password and tell the clinic immediately if you think your account has been used by someone else.
- The clinic decides who gets which role and therefore who can see what. We supply the roles and permissions; configuring them, and reviewing them as people join and leave, is the clinic's responsibility.
- A clinic account must be linked to an active doctor or staff profile at that same clinic before it can sign in. The first administrator created for a new clinic is linked as a doctor and administrator. Add later administrators through the staff-management screen so the account and staff profile stay linked.
- A pharmacy counter PIN is a credential, not a shortcut around one. It signs you into your own account on a machine the clinic has enrolled, and everything you then do is attributed to you exactly as if you had typed your password. It is personal, it must not be shared or written down where the counter can be seen, and the machine it works on is the clinic's to enrol and to revoke. A clinic administrator may set or remove one for you; if you did not ask for it, or you believe somebody else knows it, change it at once. See section 10.14.
- We may suspend an account we reasonably believe is compromised or is being used in breach of these Terms.
5. Acceptable use
You must NOT:
- Access, or try to access, records you have no authorisation to see.
- Use another person's account, or let anyone use yours.
- Probe, scan or test the security of the platform without our written permission.
- Use automated tools to extract data, or exceed the request limits that apply to your plan.
- Upload malware, or a file whose stated type misrepresents what it actually is.
- Upload or record personal information you have no lawful basis to hold.
- Copy, resell or make the platform available to anyone outside the account it was provided for.
- Interfere with the platform's operation or with anyone else's use of it.
- Use the platform to break any law, or any professional or licensing obligation that applies to you.
6. Personal information and data protection
Our Privacy Policy explains what information is collected and how it is protected. It forms part of these Terms.
Under the Data Privacy Act of 2012 (Republic Act No. 10173):
- The clinic is the Personal Information Controller for its patients' and staff's information. It decides what is collected and why.
- The operator is a Personal Information Processor, handling that information on the clinic's documented instructions and for no other purpose.
- An employer or HMO with portal access is a separate Personal Information Controller for the information it receives. It needs its own lawful basis for holding and using that information.
- Patients should direct requests about their records to the clinic that holds them.
Sections 6.3 to 6.11 are the written data processing agreement that the Implementing Rules and Regulations of RA 10173 require between a Personal Information Controller and its Personal Information Processor (IRR, Rule X — Outsourcing and Subcontracting Agreements). No separate signature is needed: accepting these Terms puts that agreement in place. Where a clinic and the operator sign a separate data processing agreement covering the same ground, the signed document prevails.
Any data sharing agreement between a clinic and an employer or HMO is a matter between those two parties — see section 6.12.
6.1 What is encrypted, and what encryption is not
Patient information is stored encrypted, with keys belonging to your clinic alone. Since 6 August 2026 this covers not only the medical record but the details that identify the person: name, email address, phone number, home address and date of birth. Somebody who obtains the stored files — a copy of the database, a backup, a disk — cannot read them.
Two limits are worth stating plainly, because a security measure described loosely is worse than one described honestly:
- Encryption at rest does not protect information from an account that can see it. Anyone signed in sees what their role allows, in readable form. Password discipline, roles and sessions remain yours to manage under section 4.
- Sex, civil status and year of birth are not protected to the same standard, so that a clinic can still count and group patients by them. They are stored as a fixed code or, for the year, in the clear. Somebody studying a stolen copy could work out what the codes mean. Every other identifying field, including the full date of birth, is not stored in a form that allows this.
This section describes how we hold the information. It does not narrow our obligations under section 6 or under the Privacy Policy.
6.2 If personal data is breached
If we become aware of a personal data breach affecting a clinic's information, we will notify that clinic without undue delay and in any case within 24 hours of becoming aware, so that the clinic can meet its own duty to notify the National Privacy Commission and affected data subjects within 72 hours of knowledge of the breach, as NPC Circular 16-03 requires. The notice will contain, so far as it is then known: the nature of the breach, the personal data possibly involved, the measures taken to address it, and the name and contact details of the person from whom more information can be obtained.
We will assist the clinic with its notification and with any subsequent investigation, and we will not make a notification to the Commission or to data subjects on a clinic's behalf unless the clinic asks us to or the law obliges us directly.
We also keep a breach register: every security incident we consider is recorded, including the ones we judge do not require notification, together with the reasons for that judgement and the date it was made. Circular 16-03 asks for the register as well as the notification, and a decision not to notify is only worth anything if it was written down while it was being taken. The register is what our annual report to the Commission is produced from, and what a clinic's own auditor is shown under section 6.10.
6.3 Subject matter of the processing
- What we process on your behalf: the personal and sensitive personal information a clinic records on the platform.
- Categories of data subject: the clinic's patients, its doctors, nurses and staff, people who request appointments, and users of an associated employer or HMO portal.
- Types of data: identity and contact details; date of birth, sex and civil status; health information including consultation notes, diagnoses, treatment, prescriptions, laboratory results, imaging studies with their image files and radiology reports, and dental charts; messages between a patient and clinic, with sender, time and read status; health entries recorded by an associated employer or HMO through its portal; billing and payment records; uploaded documents; and account and access records. Health information is sensitive personal information under section 3(l) of RA 10173.
- Nature and purpose: hosting, storing, transmitting, backing up and making available that information so the clinic can run its practice and care for its patients, and nothing else.
- Duration: for as long as the clinic's account is open, and thereafter only as section 6.9 provides.
6.4 We process only on your documented instructions
We process personal data only on the clinic's documented instructions, which for these purposes are these Terms, the clinic's configuration of the platform, and the actions its authorised users take in it. We do not use a clinic's data for our own purposes, we do not sell it, and we do not use health information for advertising or for training any model.
If an instruction from a clinic appears to us to breach RA 10173 or any other law, we will say so before acting on it, and we may decline to act on it.
6.5 Confidentiality and the people who handle data
Everyone we allow near a clinic's data — employees and contractors alike — is bound to confidentiality, is granted access only to what their work requires, and keeps that duty after they leave. Access to a live clinic's data by our personnel happens only for support, maintenance or fault diagnosis.
6.6 Security measures
We maintain the organisational, physical and technical measures required by section 20 of RA 10173, described for a general reader in the Privacy Policy and, for the encryption specifically, in section 6.1 above. We will not weaken those measures during the term of a clinic's subscription.
Two of those measures are worth naming here, because a clinic can act on them:
- Two-factor sign-in is available to every account, not only to our own administrators. A clinic can require it of whichever roles it chooses, from
Settings › Privacy & Security. Encryption protects the stored files and does nothing against someone holding a member of staff's password; this is the control that addresses that, and it is the single most useful thing a clinic can switch on. - The record of changes is cryptographically chained, so altering or removing an earlier entry is detectable rather than merely against our rules. Stated with its limit: this makes tampering visible, not impossible. Someone with direct access to the database could recompute the chain, which is why each period is additionally sealed with a key held outside the database, and why those seals are exported to storage we cannot rewrite.
6.7 Sub-processors
We use a small number of sub-processors to run the platform: hosting infrastructure, an email delivery provider, a push-notification provider and an anti-spam provider. They are listed and described in the Privacy Policy, which is the current list.
- Each is bound by terms no less protective than these.
- We remain answerable to the clinic for what a sub-processor does with the data, as section 21 of RA 10173 requires of us.
- We will give clinics 30 days' notice in the application before adding or replacing a sub-processor that handles patient data. A clinic that objects on reasonable data-protection grounds may terminate under section 17 without penalty for the unexpired term.
6.8 Helping you meet your own obligations
We will assist each clinic, at no additional charge and within the time the law allows:
- With data subject requests — access, correction, objection, erasure, blocking, and portability under sections 16 to 18 of RA 10173. Where a request reaches us instead of the clinic, we forward it to the clinic and do not answer it ourselves.
This assistance is built into the platform rather than offered on request. A clinic has a register for these requests (Settings › Data requests) that records what was asked, when it arrived, when the answer is due, whether the person asking was identified, and what was done — with the deadline counted in working days from receipt. It can produce a patient's whole record on demand, as a readable PDF and as a structured data file another system can import, which is what section 18 contemplates. Erasure runs through the existing reviewed workflow, and the register keeps the link to it.
- With breach notification and investigation, as section 6.2 provides.
- With a privacy impact assessment, by describing how the platform processes data and what it stores.
- With an enquiry from the National Privacy Commission that concerns our processing.
6.9 Return and deletion at the end
When a clinic's account closes, its data is retained unopened for 30 days so the clinic can retrieve it, and is then permanently destroyed along with the keys protecting it (see section 7 and the Privacy Policy). A clinic can obtain a complete archive of its data at any time before then under section 8.
The archive and the export are different things, and a clinic leaving usually wants both. The archive is a faithful copy of what was stored, which means the encrypted fields come out as ciphertext without the keys — a restore file, not something a person or another system can read. The per-patient export (section 6.8) is the readable one. Take the export for the records you need to hand on or hand back; take the archive for completeness.
We keep nothing afterwards, with two stated exceptions: billing and tax records we are required to keep, and document verification records, which never contained a full patient name or any health information (Privacy Policy section 2.7).
6.10 Demonstrating compliance
On a clinic's written request, and no more than once a year unless the National Privacy Commission or a breach makes it necessary:
- we will provide the information reasonably needed to show that we are meeting this section; and
- we will cooperate with an audit or inspection of our processing conducted by the clinic or by an auditor it appoints, on reasonable notice, during business hours, subject to confidentiality and to not disrupting other clinics.
6.11 Where the platform stores and processes data
The IRR requires an outsourcing agreement to state where processing takes place, so:
- We will tell any clinic, on request, the country and provider of the infrastructure holding its data, and we will give 30 days' notice in the application before moving it to another country.
- Some sub-processors named in section 6.7 — email delivery, push notification and anti-spam checks — necessarily process outside the Philippines.
- Wherever processing happens, we remain accountable for the data under section 21 of RA 10173 and use contractual means to secure a comparable level of protection.
A clinic that requires its data to remain within the Philippines should raise this with us before subscribing, as it constrains which infrastructure we can use for that clinic.
6.12 What remains the clinic's own duty
As the Personal Information Controller, each clinic — not the operator — is responsible for:
- designating its own Data Protection Officer and, where the thresholds apply, registering its data processing system with the National Privacy Commission. The platform provides a place to record and publish that officer's contact details (
Settings › Privacy & Security), which appears on the clinic's public page; recording it is not the same as designating and registering, and the second part remains the clinic's; - having a lawful basis for what it records, and obtaining consent where consent is the basis it relies on;
- its own privacy notice to its patients and staff;
- any data sharing with an employer, HMO, insurer or another clinic — including the data sharing agreement and the data subject's consent that such sharing requires. The employer and HMO portal is a tool for a sharing arrangement the clinic has decided upon; providing the tool is not us assessing the arrangement.
The platform now asks the clinic to record, per patient, on what authority it shares with a company, and to record a withdrawal of consent — which it then enforces, by refusing that company any further access to that patient. Associations made before this existed show honestly as no basis recorded. Recording the basis is not the same as having one, and the choice of basis remains the clinic's own judgement;
- deciding retention in line with medical record-keeping and PhilHealth requirements; and
- who holds which role in its own account (section 10.4).
6.13 Which requirements these provisions meet
For a clinic's compliance file, this section, together with the Privacy Policy, addresses:
- RA 10173 §11 — transparency, legitimate purpose, proportionality → Privacy Policy sections 3 and 12.1.
- RA 10173 §12 and §13 — a lawful basis for personal information, and one of the narrow grounds for health information → Privacy Policy section 3.1.
- RA 10173 §16 to §18 — the rights of the data subject → Privacy Policy section 8, and section 6.8 above for how we help a clinic answer them.
- RA 10173 §20 — organisational, physical and technical security measures → sections 6.1, 6.5 and 6.6 above, and Privacy Policy section 5.
- RA 10173 §20(f) and NPC Circular 16-03 — breach notification within 72 hours → section 6.2 above, and Privacy Policy section 5.4.
- RA 10173 §21 — accountability for personal data transferred to a third party → sections 6.7 and 6.11 above.
- IRR of RA 10173, Rule X — the required contents of an outsourcing agreement between a controller and a processor → sections 6.3 to 6.11 above.
- JAO No. 2016-0002 (Department of Health, PhilHealth and the DOST) — confidentiality of health information, access confined to those providing care, secure retention and disposal, and breach management → sections 6.1, 6.2, 6.6 and 6.9 above, and Privacy Policy sections 5 and 7.
Section 12.2 of the Privacy Policy states, in the same terms, what these documents do not yet cover.
7. Records, retention and deletion
Clinics keep patient and health records for as long as care and the law require. Deleting records on the platform is a reviewed request, not an immediate erasure:
- Someone raises a request and gives a reason.
- Someone else reviews it. Requests a clinic raises are reviewed by the operator; requests an employer or HMO raises are reviewed by the clinic.
- On approval the records stop being visible straight away, and stay recoverable for a limited recovery period.
- After that period they are permanently removed and cannot be recovered by anyone, including us.
Two things survive a deletion, deliberately:
- Billing records, with the patient de-identified. The clinic's accounts still balance and the entries no longer identify anyone.
- Authorship of clinical records. Closing a clinician's account destroys their sign-in but keeps their name on the prescriptions, certificates and notes they issued, because those are medical records.
The clinic warrants that it may lawfully delete what it asks us to delete. Medical records are subject to retention duties, and we act on the clinic's instruction rather than assessing those duties for it.
8. Exporting your data
A clinic can request an archive of its own data at any time, and one is prepared automatically before records are deleted. Two things about that archive matter:
- It is delivered as a secret link that expires, with no sign-in behind it. Anyone holding the link can download the file until it expires. Treat the link as confidential and think before forwarding it.
- The archive contains encrypted fields as stored, without the keys that unscramble them. It is a restore file, not a readable export.
9. Availability and things outside our control
We work to keep the platform available and to protect it, but we do not promise uninterrupted service. Maintenance, upgrades and faults happen.
The platform depends on services we do not control — internet and mobile networks, email delivery, push-notification delivery, app stores and hosting infrastructure. We are not responsible for their failures, and message or notification delivery is never guaranteed.
Where a plan carries a service level, it is stated at Pricing. No service level applies to the Free plan.
9.1 Messages the platform sends
Using the platform means receiving messages from it. They fall into two kinds, and the difference matters:
- Messages your clinic's system sends on the clinic's behalf — appointment confirmations, the reminder emailed about a day before a visit, portal links, notifications to staff. The clinic decides who is on its records and therefore who receives these. Some are essential to the service and are not optional while you are using it.
- Notices from us, the operator — a change to these Terms or to the Privacy Policy, planned maintenance, or a security matter. We may send these to account holders, to employer and HMO portal users, and, where the notice genuinely concerns the service being provided, to patients of clinics on the platform. They are service notices, not marketing: we do not use these addresses to advertise and we do not pass them to anyone else for their own use.
Delivery is never guaranteed. Email and push notifications depend on providers we do not control (section 9), and a message may be delayed, filtered as spam, or not arrive at all. Do not treat the absence of a reminder as evidence there is no appointment, or the absence of a notice as evidence nothing has changed. The record held in the clinic system, and the current version of these documents on this site, are what govern.
A clinic is responsible for keeping the contact details on its records accurate, and for telling its patients what its own privacy notice requires about the messages they will receive.
10. Clinic management system
This section applies to clinic owners, administrators, doctors, nurses, receptionists and cashiers using the clinic's management system.
10.1 The clinic is responsible for what it records
The content of medical records, prescriptions, laboratory orders, imaging orders and the radiology reports written from them, dispensing decisions and charges is the clinic's. We do not review it, validate it, or check it for clinical safety. A radiology report is the reading doctor's opinion, not ours — the platform stores and prints what they wrote and never interprets an image.
10.2 A prescription or certificate takes effect only when the doctor marks it reviewed
The platform holds a prescription or certificate as a draft until the responsible doctor marks it reviewed. Only then is it released, and only then does it carry the doctor's signature. Drafts must not be issued to patients.
A certificate carrying laboratory or imaging results reproduces those results as they stood at the moment it was issued, and is not updated afterwards. If a result is later amended, the certificate already handed to an employer or anyone else does not change to reflect it — the clinic must reissue the certificate if the earlier version needs correcting.
The clinic is responsible for the saved template wording, completed blanks and selected clinical content. Before releasing a certificate, review its source dates and the information intended for the recipient. An appointment-linked certificate uses that appointment's records. A standalone certificate can use the patient's latest intake, APE and consultation observations or recommendations, which may come from different dates. Consultation diagnosis and treatment require an appointment-linked medical record.
Notes and results require selection at issuance. Laboratory results must be validated and final or amended; imaging reports must be signed, final or amended, with no unreviewed amendment pending. The corresponding module and viewing permission are also required. Eligibility to select a record does not establish its relevance to the certificate or replace the clinic's decision about disclosure.
Automatic fit-to-page is a formatting aid, not a guarantee of a single-page document or a clinical review. It reduces only the body text and preserves the designed size of the letterhead, signature block and verification QR. If the content cannot fit at the smallest supported size, the platform keeps the full-size output across multiple pages and warns the issuer. Explicit page breaks bypass automatic fitting. Review the finished PDF for completeness and readability before release; the final page count depends on its content.
10.3 The e-signature is the doctor's own act
A doctor's captured signature is applied to documents as that doctor's own act, and is intended to operate as an electronic signature under the Electronic Commerce Act (Republic Act No. 8792). A doctor must keep their account secure, and nobody may apply a doctor's signature on their behalf.
10.4 Roles are the clinic's to configure
We provide the permission model. Which staff member holds which role — and therefore who can open a medical record — is decided by the clinic, which is answerable for granting more access than a role needs.
10.5 Deleting records is a request
See section 7. Requests go to the operator for review, the recovery period applies, and billing history is retained de-identified.
10.6 Uploaded files are not scanned
Files uploaded to the platform are not checked for malware, and a file's type is taken from what the uploading browser reports. The clinic is responsible for what its staff and patients upload.
10.7 Calendar invitations leave the platform
Confirming an appointment can send the patient a calendar invitation, which their own email provider — Google, for a Gmail or Workspace address — adds to their calendar. The same invitation travels with the reminder emailed to the patient about a day before the visit, which reaches any mailbox rather than only Google-handled ones. The clinic controls this under Settings → Calendar Invitations; switching it off stops the attachment, not the reminder email itself. Two things follow from it.
The entry lives outside the platform. Once delivered, the calendar entry belongs to the recipient and their provider. We cannot read it, change it or remove it. Rescheduling and cancelling send follow-up messages that normally update or withdraw the entry, but whether they take effect is the recipient's provider's to decide, not ours. The calendar entry is a convenience and not the record — the appointment as held in the clinic system is authoritative, and neither the clinic nor a patient should rely on a calendar entry being present, current or absent.
Enabling doctor invitations is the clinic's decision. A clinic may separately choose to send its doctors a calendar entry for the appointments they are booked for. That entry names the patient the doctor is due to see, which means a patient's name is passed to whichever provider handles that doctor's email — including a personal mailbox, where the clinic has not issued one. This is off unless the clinic turns it on. A clinic that turns it on is responsible for having decided that this disclosure is appropriate, for telling its patients where its own notice requires it, and for the mailboxes its doctors use.
Invitations carry the appointment's time, the clinic's contact details, and the name of the doctor or patient. They carry no clinical content.
10.8 Verification codes confirm issuance, not clinical correctness
Documents the platform prints carry a QR code and a separately printed reference. Both must be supplied to the public page before it confirms the clinic issued that document. Its limits matter:
- It confirms that a document with those details was issued by that clinic on that date. It says nothing about whether the content is clinically correct, still current, or applicable to any decision a reader is making.
- It is not proof of identity. It shows the subject's initials only, and does not establish that the person presenting the paper is the person it was issued to.
- It does not detect an altered page. Someone who edits a printed document and reprints it keeps a valid code. The code proves a document of that description exists; comparing the paper against what the page reports is the reader's job.
- A clinic may revoke a document it issued in error or that it has withdrawn, after which it no longer passes verification. The response remains generic and revocation does not alter or recall any paper already handed out.
- The verification page is deliberately public and unauthenticated, because it has to work for whoever is holding the paper. Anyone with the printed document, or a photograph of it, can scan the code.
Clinics remain responsible for the accuracy of what they issue, and for handling printed documents with the care any medical document deserves.
10.9 Searching by name returns a limited number of matches
Because patient names are encrypted, searching them is done by the platform rather than by the database, and a search returns a bounded number of matches — by default the first 200, in surname order. A search broad enough to exceed that is telling you to narrow it, not telling you the remaining patients do not exist. Where an exact patient matters — billing, a clinical decision, a deletion request — open the patient's own record rather than relying on a list.
10.10 What an employer or HMO records is not a clinical record
A company with portal access can record health entries about a patient it is linked to, and can mark them visible to your clinic (section 12.6). Those entries are that company's account of what it has been told. They are not a diagnosis, a prescription or an order, and nothing acts on them automatically.
Treat them as you would information given over the phone by a relative: potentially useful, worth asking about, and worth verifying before it changes anything clinical. If your clinician decides an entry belongs in the medical record, they record it themselves, as their own act.
10.11 Registering people in bulk from a list
The platform can create patients from a spreadsheet a clinic uploads — for example a list of employees an employer provides. The details taken can include name, date of birth, sex, email, phone number, address, civil status, a record ID number and the clinic's own custom patient fields. The clinic reviews what was read from the file and chooses which rows are registered; nothing is created until it confirms.
The clinic is responsible for the list. That means having the authority to hold the details on it, and checking what was read before confirming. We do not verify that the people on a list consented to be registered, that the details are correct, or that the organisation supplying it was entitled to.
Examination results can be imported the same way. Staff permitted to manage the clinic's settings can upload a spreadsheet of examination results — for example from an annual physical examination carried out for an organisation. For each row the clinic keeps, the platform can register the person, record a visit on the date and under the examining doctor the clinic chooses — in progress when the row has results, pending when it has none, and not added again when an earlier import made one for that person in the 15 days before — file blood count, urinalysis and hepatitis B screening findings as laboratory results, and save a findings summary to the person's medical record. Linking the examinees to an organisation is optional. Several things follow:
- Imported results take effect as recorded. Laboratory results created by the import are marked validated by the staff member who ran it, and the findings summary is saved to the record. They are not held back as drafts for separate review. The visits are left in progress for a doctor to complete, but completing them is not a check the platform enforces: the on-screen review before import is the clinic's check, and it must be done by someone able to judge the results.
- The platform reads the spreadsheet mechanically. It interprets common shorthand — body-mass-index codes, blood-pressure readings, "non-reactive" screening results — and sorts remarks into complaints or an employment status such as resigned or on leave. We do not guarantee that every entry is read as the person who wrote it intended. The clinic is responsible for checking the grid, correcting or removing rows, and for the records that result.
- People are matched to existing records by record ID or by name. A row can be added to someone already on file who shares that ID or name. The review screen shows which rows it will add to existing patients; the clinic must check those before importing.
- Re-importing a file does not undo anything. Running the same file again within 15 days of the examination date adds only what is missing; with a later date it adds a new visit. It does not change or remove results already recorded, and correcting a mistake afterwards is done in each patient's record.
- Linking to an organisation can make data visible to it. Where the named organisation uses the employer portal, what it can then see about each examinee is governed by section 12. The clinic decides whether to make the link and is responsible for having a basis to do so.
10.12 The pharmacy counter records a sale, it does not authorise one
A clinic can sell medicine and supplies over the counter, to a registered patient or to a walk-in who is not one. The platform records the order, takes the money, deducts the stock and prints a receipt. What it does not do is decide that any of that was allowed.
- The clinic must be entitled to sell what it sells. Holding the right licence, having a registered pharmacist supervise where the law requires one, and knowing which medicines may be sold without a prescription are the clinic's obligations. We do not check any of them, and enabling the module is not a representation that a clinic may operate a pharmacy.
- The prescription check is a control, not a clinical review. Where an item is marked as requiring a prescription, the platform will not let the sale be confirmed without one attached and current. That enforces the clinic's own setting. It does not read the prescription, check that it is for the medicine being sold, that the quantity matches, that it has not already been filled elsewhere, or that dispensing is safe for that person. It also checks nothing at all for items the clinic has not marked as requiring a prescription — that marking is the clinic's to get right.
- No interaction, allergy or dosage checking is performed. As section 3 says of the platform generally, and it is worth repeating at the point where medicine changes hands.
- A walk-in is identified only by what they say. Where a name is recorded, it is what the customer gave; nothing verifies it. A sale can be recorded with no name at all.
- Stock figures are only as good as what was encoded. The platform deducts what it is told was sold from what it was told was received. It does not count your shelves.
10.13 What a counter receipt is, and is not
The receipt the counter prints, and the tracking number on it, are the clinic's own record of a transaction.
- It is not a BIR-registered official receipt or sales invoice. Whatever a clinic must issue for tax purposes, and registering the system that issues it, remain the clinic's responsibility. Nothing here is tax advice; a clinic unsure of its obligations should take its own.
- The tracking number identifies an order, not a payment. It is issued when the sale is started, before anything has been paid, and it stays the same afterwards. Quoting it proves nothing about whether money changed hands.
- A number is unique within one clinic, not across the platform. Two clinics can legitimately hold the same tracking number.
- A receipt is not a prescription and confers no authority to obtain the same medicine again.
10.14 Counter sign-in with a PIN
Because a counter is a shared machine with people waiting, staff can sign in there with a short PIN instead of a password. What that does and does not mean:
- It signs in a person, not a terminal. Each sale is attributed to whoever entered their PIN, and the session is that person's own with exactly their usual permissions. Nothing is attributed to "the counter".
- It only works on a machine the clinic has enrolled, and only while that enrolment is active. Revoking a terminal takes effect immediately, which is what to do if a device is lost — the clinic does not have to wait for anything to expire.
- A PIN is weaker than a password, and is meant to be. It is short, it is entered in public, and it is protected mainly by only working on clinic hardware and by locking the account after repeated wrong attempts. Enrolling a terminal is the clinic accepting that trade for that machine; enrolling a device that leaves the premises defeats it.
- Signing in at a counter ends that person's session elsewhere. One person holds one session at a time, so a PIN sign-in displaces one they left running at another screen.
- Where a clinic separates duties, the platform follows it. Someone who is not permitted to take payments cannot settle an order at the counter, and the order goes to the cashier instead. Whether to grant one person both roles is the clinic's decision, and section 10.4 applies to it.
- An administrator may set a PIN for a pharmacist or cashier, and this is a serious act. It exists for the practical case — somebody new on their first shift, somebody locked out with a queue in front of them — but the PIN it produces signs that person in as themselves, so every sale made with it carries their name. The platform therefore records who set each PIN and when, notifies the person that it was set or removed, sends them the digits in a notification that destroys them once read, and signs them out so a superseded PIN cannot remain in use. It is the clinic's responsibility to use this only where the staff member cannot reasonably set their own, and the staff member may change it at any time. Where a sale's attribution is later disputed, the record of who set the PIN is part of what the clinic has to work from — it is not proof of who stood at the counter.
10.15 Prescribing checks are formal, and the clinic sets them
The platform checks a prescription against a small set of rules before it is saved — that a generic name is present (Generics Act, RA 6675), that a dangerous drug carries a Yellow Prescription Form serial and comes from a prescriber with an S2 number on file, and that a PRC licence number is recorded so it can be printed. Each rule's strength is a clinic setting: block, warn, record only, or off.
The same rules apply however the prescription is written — the prescription screen, the in-visit box on an appointment, or the API. A clinic that integrates with the API does not thereby get a route around its own rules.
What that does and does not mean:
- These are formal checks, not clinical ones. They test whether a required
fact is present. They do not read the prescription, check dosage, flag interactions or allergies, judge whether a medicine is appropriate, or verify that a prescription matches what is being dispensed.
- The platform cannot verify any licence. PRC, PTR and S2 numbers are
entered by the doctor and are not checked against any register. A recorded number means a number was typed, not that a licence exists, belongs to that person, or is current.
- We do not classify medicines for you. The platform ships a starter list of
substances that are internationally controlled, purely as a prompt. Nothing on it is enforced until a pharmacist at the clinic confirms it, and the classification a clinic records is the clinic's own. Classifying the medicines it holds, and keeping that current against the Dangerous Drugs Board's issuances, is the clinic's responsibility.
- We do not check limits that carry a number — validity periods, quantity
caps, days-supply limits, one-drug-per-form. Those are set by issuances we do not track, and we would rather check nothing than check it wrongly.
- Turning a rule down is the clinic's decision, and it is recorded. The
severity in force is written into each prescription's compliance record, so what was checked, and how strictly, is visible afterwards.
- A clean check is not a statement that a prescription is lawful. It means
the facts the platform can see were present. The prescription remains the prescribing physician's act and responsibility.
Where a clinic has classified a medicine as a dangerous drug, the printed prescription carries a plain marking to that effect. The marking reflects the clinic's own classification, read at the time of printing — it is not a legal determination by the operator, and where a clinic has not classified a medicine nothing is marked. A prescription without the marking is not a statement that the medicine is uncontrolled.
Yellow Prescription Forms are issued by PDEA. The platform records the serial a prescriber enters and prints it; it does not supply, serialise or account for the forms themselves.
10.16 Following a patient is an alert, not a safeguard
A member of staff can ask to be notified when something happens to a particular patient, choosing which kinds of event they want to hear about.
- It grants no access. The choice is offered to whoever may already open
that patient's record, and the link in an alert opens that record with the permissions the person already holds — and is written to the record access log like any other look.
- It carries no clinical content. An alert says what kind of thing happened
and nothing more: no name, no diagnosis, no figure, whether it appears in the clinic system or on a phone.
- Only what happens afterwards is sent. Nothing already on the record is
re-notified when the choice is saved, and nothing is sent to the person whose own action caused the event.
- Delivery is not guaranteed, for the reasons in section 9.1. An alert that
does not arrive is not evidence that nothing happened, and the absence of one must never stand in for reading the record, for clinical handover, or for any step a clinic's own procedure requires. Do not rely on it for anything time-critical or clinically material.
Who has asked to follow whom is a record held for the clinic, visible to its administrators. Deciding whether a member of staff may follow a given patient is part of the clinic's own access control (section 10.4), not something the platform judges.
10.17 Offering patient messaging is the clinic's decision
Patient messaging is optional and off unless the clinic switches it on, under Settings → Patient Messaging. A clinic that turns it on takes on what the channel implies:
- It creates an expectation of a reply. There is no monitoring, no routing
and no response-time guarantee in the platform. A clinic that opens the channel is responsible for reading what arrives and for telling its patients how it is used — including that it is never for emergencies (section 13.6).
- What arrives may be clinical. Patients are asked to keep the channel to
administrative questions, but a message is whatever the patient writes. It is kept as part of the patient's record, and the clinic answers for it as it does for the rest.
- Switching it off hides, it does not erase. Turning messaging off withdraws
the channel from staff, from the patient portal and from the mobile app; the messages already exchanged remain part of the record and reappear if it is switched on again. A clinic that switches it off should tell patients who were using it how to reach the clinic instead.
- The platform operator may also set this switch for a clinic, on the
clinic's request or in the course of supporting it. That does not make the operator a party to any conversation.
10.18 Using the waiting-room Health Board
A clinic can run a live queue at its /today address on a TV or tablet. The clinic decides whether to use it, where to place the screen and how each waiting visit appears. The encounter reference is the recommended default. The two name-based choices disclose more: a first name and initial, or a first initial and surname.
- Use the least identifying label that works. A screen in a public or
patient-facing area can be read by anyone nearby. The clinic must consider the room, viewing distance and people present before choosing a name-based label.
- Protect the PIN and kiosk link. Either can authorize a display without a
staff account. Keep the PIN and kiosk link within the clinic, rotate a link that was shared improperly, and use Sign out all screens when a device is lost, replaced or moved. Authorization lasts for up to 90 days unless the clinic revokes it first.
- The board is informational. It reflects appointment status and doctor
availability recorded in the clinic system. It does not triage patients, decide clinical priority or guarantee a waiting time. Staff remain responsible for calling and prioritizing patients safely.
- Clinic media is the clinic's responsibility. Uploaded images and clips,
headlines, titles and linked videos must be suitable for the waiting room and must not expose patient information or infringe another person's rights.
- External video contacts its provider. Choosing a YouTube or Vimeo slide
makes the display device load that provider's player. The provider's own terms and privacy policy apply to that connection. The platform does not send the queue to the provider.
10.19 Whether online booking is offered is the clinic's decision
A clinic's public page offers an appointment request form unless the clinic switches it off, under Settings → Public Visibility. Either state is the clinic's own choice, and either is available on any plan.
- Switching it off closes the form, not the clinic. Every booking button is
withdrawn from the clinic's public pages and from its card in the public directory, and anyone reaching the form is shown the clinic's own message. The clinic is responsible for what that message says and for keeping it current — including telling patients how to reach it instead. Where the clinic writes nothing, a neutral default is shown.
- Requests already made are unaffected. Closing the form stops new requests
only. Requests already submitted, the appointments made from them, and the portal links already issued to patients continue to work; a link is withdrawn by revoking it, not by this switch.
- A request was never a booking. As set out in section 12.9 for campaigns
and throughout this section, an appointment exists only once the clinic makes one. Closing the form removes a way of asking; it creates no entitlement and cancels nothing already agreed.
- The platform operator may also set this switch for a clinic, on the
clinic's request or in the course of supporting it. The clinic may set it back at any time.
11. Doctor mobile app
This section applies to doctors using the Care Doctor Android app, distributed through Google Play under the application id net.accessph.clinic.doctor1. Google Play's own terms apply in addition to these.
11.1 One device at a time
You can be signed in on one mobile device at a time. Signing in on a second device is refused while the first session is live — the existing session wins. Sharing an account therefore does not merely breach section 4; it will lock a colleague out mid-consultation.
11.2 There is no offline mode
The app holds no local copy of clinical data. Everything is fetched while you use it and is gone when the app closes. Do not rely on the app where you may have no connectivity. Only your sign-in session is stored on the device.
11.3 Sharing a document takes it off the platform
When you send a prescription or certificate to your phone's share or print sheet, that file leaves the platform and our protections. From that point you and your clinic are responsible for where it goes.
11.4 Notifications can show patient names
Push notifications may display a patient's name on your lock screen. Use a device lock, and turn off notification previews if your phone is shared or is seen by others.
11.5 Biometric unlock is convenience, not identity
Unlocking the app with a fingerprint or face reopens a session that is already signed in. Anyone whose biometrics are enrolled on that device can open the app. It does not replace signing in and does not prove who is using the phone.
11.6 Writing from the phone is not a draft
Medical records, prescriptions, laboratory orders, imaging orders and charges created in the app are recorded exactly as they would be on a desktop. Section 10.2 applies to prescriptions and certificates written from the app in the same way.
11.7 Keeping the app current
We may require a minimum supported version. Older versions may stop working when the platform changes.
12. Employer and HMO portal
This section applies to companies, employers and HMOs given portal access, and to their staff.
12.1 What you may use this information for
You may use what you see only for the purpose the access was granted for — administering the healthcare benefit or coverage you provide.
You must not use it to make employment or coverage decisions about an individual — including hiring, dismissal, promotion, discipline, reassignment, denial of benefits, or insurance underwriting or pricing — beyond that stated purpose.
12.2 You are a controller in your own right
For the information you receive you are a Personal Information Controller under Republic Act No. 10173, and you need your own lawful basis for holding and using it. Putting a data sharing agreement in place with the clinic is a matter between you and the clinic.
12.3 You see only what a clinic has associated
Your access covers only the patients a clinic has explicitly linked to you, at that clinic. A clinic can end an association at any time, which removes your visibility of that person.
12.4 The view is deliberately partial
The portal is read-only and shows a limited set of fields. A patient's insurance information and a clinic's private medical notes are never exposed to you. You must not attempt to reconstruct or infer what the portal withholds, and must not ask clinic staff to supply it outside the portal.
12.5 You may ask a clinic to delete records, but the clinic decides
You can raise a request to delete an associated patient's records. It goes to the clinic, which decides and may decline with a reason. A request covers that patient's records at that one clinic. If the association ends before the clinic decides, the request is withdrawn.
12.6 Health entries and identity documents
You can record health entries about an associated patient — a medical note, reported medication, a medical undertaking, or other health information. Three things about them:
- They are not a clinical record. Recording medication or an undertaking does not prescribe anything, does not order anything, and does not instruct the clinic. Only the clinic's own clinicians create clinical records, and they decide what to make of what you record.
- You choose who sees each entry — your portal only, the clinic only, or both. Once an entry has been shared with a clinic it cannot be un-shared; you can still correct or delete your own entries going forward.
- You need a lawful basis for what you write, as section 12.2 provides, and section 12.1 limits what you may use it for.
You warrant that you may lawfully upload any employee identity document you provide.
12.7 No onward disclosure
You must not pass what you see to anyone else without a lawful basis and the individual's knowledge.
12.8 Verifying a document an employee gives you
A document issued through the platform carries a QR code and a printed reference. Scan the code, then enter the reference to confirm the clinic issued it. What that confirms is narrow, and section 10.8 sets out the limits in full: it does not tell you the content is clinically correct or current, it does not identify the person presenting it, and it does not detect a page that has been altered and reprinted.
Scanning is subject to section 12.1: verifying a document does not widen what you may use it for.
12.9 Bulk booking campaigns are requests, not appointments
Only a Company Administrator may submit a bulk-booking campaign. A campaign is sent to one clinic already linked to your company and may identify people already associated with that company or people you ask the clinic to register. You must have a lawful basis and authority to provide each person's details, and must keep those details accurate.
A campaign asks the clinic to consider appointments within a requested date window. It does not create a patient, reserve a slot, or confirm an appointment. The clinic decides whether to accept each request and, through its authorized staff, selects the patient record, doctor, date and time. Do not tell a person that an appointment is confirmed until the clinic confirms it.
You must not submit a campaign for a person whose association with your company has ended or whose consent has been withdrawn where consent was the recorded basis for sharing. The platform may refuse that request, but you remain responsible for the authority on which you use and provide the information.
13. Patient portal
This section applies to patients using a clinic's patient portal.
13.1 Your link and your code both arrive by email
Access needs two things: a secret link and a one-time code. Both are sent to the same email address. Anyone who can read that mailbox can therefore reach your records. Keep your email account secure, and do not forward the link.
The address used is the one your clinic holds on your record, whether you gave it when booking online yourself or gave it to the clinic, which may enter or correct it when it books a visit for you — including a visit booked as an online appointment, where the link is how you attend. Tell your clinic promptly if your address changes or is wrong on their record: a link sent to an address you no longer control is a link to your records in someone else's mailbox.
13.2 Access is time-limited
An appointment portal link stops working shortly after your appointment is completed. The scheduled expiry leaves a short period in which you can keep reading and replying to the patient conversation. Cancelling an appointment does not erase that conversation. The clinic can issue or revive a grant if you need access later. Within a session, you are signed out after a period of inactivity. Do not use the portal on a shared or public device.
13.3 Uploading a receipt is not a payment
Uploading a photo of a receipt tells the clinic you say you have paid. It does not settle a charge and it is not a payment channel. Nothing is settled until clinic staff verify it.
13.4 There is a window when you can add things
You can upload laboratory results and medical records and fill in your part of a health questionnaire from the moment your appointment is booked until the moment your visit is completed. You do not have to wait for the clinic to confirm.
Once the visit is completed, its forms, uploads, and other appointment-bound content are fixed. If something needs to be added or corrected afterwards, ask the clinic. Its staff can re-open the visit while your portal grant remains valid, or issue a new grant when needed.
If an appointment is cancelled, there is no visit to add to and the portal will not accept anything further for it.
Separately, the parts of a health questionnaire you fill in also lock once the clinic generates the final document, even if the visit is still open.
Messaging is offered only by clinics that have switched it on, so your portal may have no message box at all.
Messages follow the patient rather than one appointment. You may keep reading and replying while your portal grant remains valid, including after a visit is completed or cancelled. The clinic sees the same conversation from your profile and from a current appointment.
13.5 Documents appear only after your doctor has reviewed them
Prescriptions and certificates become available for download once the doctor has reviewed and signed them. If a document is not there, that is not a clinical statement — it may simply not be ready. Ask the clinic.
13.6 Messages are not clinical advice, and not for emergencies
Messaging your clinic through the portal is for administrative questions. It is not a consultation, there is no guaranteed response time, and nobody is monitoring it continuously. In an emergency, contact the clinic directly or your local emergency services.
A clinic decides whether to offer messaging at all, and may stop offering it. If your clinic has not switched it on, or switches it off, there is no message box on your portal and you cannot reach the clinic that way — use the clinic's own phone number or email address. Turning it off does not delete what was already sent; the clinic keeps it as part of your record.
The clinic keeps the conversation as part of your patient record. Do not send information about another person unless you have authority to act for them.
13.7 The clinic sees what you do
Opening the portal, sending a message, or uploading a file may notify clinic staff. A message alert inside Clinic IMS can show your name and a short preview to authorized staff. Email and push alerts do not contain your name or message text. The portal is a channel to your clinic, not a private space.
13.8 What you may upload
Uploads are limited in size and to common image and PDF formats; the portal will tell you if a file is rejected. Upload only documents relating to your own care, or the care of someone you are lawfully entitled to act for, and only files you have the right to share.
13.9 The code printed on your documents
Documents your clinic gives you carry a QR code next to the doctor's signature and a printed reference. Anyone you hand the document to can scan the code and enter the reference to confirm your clinic really issued it — useful when an employer or a pharmacy needs to trust the paper.
The page it opens shows your initials only and no medical information at all. But it is public and needs no sign-in, because it has to work for whoever is holding the paper. Treat the printed document, and any photo of it, the way you would any other medical document.
14. Plans and limits
The platform is offered on the Free, Starter, Professional and Enterprise plans. Each plan sets limits on the number of patients, the number of user accounts, the amount of stored files, and how many API requests may be made per hour.
Current prices and limits are published at Pricing and form part of these Terms. Reaching a limit prevents new records being created; it never deletes anything you already have.
15. Fees and taxes
- Fees are stated and payable in Philippine Pesos, on a monthly or yearly term as chosen by the clinic.
- Taxes are treated as stated at Pricing.
- We do not store card numbers. A payment recorded in the system is clinic staff recording money received, not a transaction processed by us (see section 3).
16. Renewal, non-payment and downgrade
For a paid plan:
- We send renewal reminders 15 days and 7 days before the term ends.
- If the term ends unpaid, the subscription becomes past due and continues to work for a grace period of 7 days.
- After the grace period the clinic is moved to the Free plan and paid features switch off.
Your data is not deleted when this happens. It stays as it is, subject to the Free plan's limits, and paid features return when the plan is renewed.
17. Suspension and termination
- A clinic may stop using the platform at any time and may request deletion of its account under section 7. Export your archive first (section 8) — the download link expires well before the data itself is destroyed.
- We may suspend or terminate access for non-payment, for a breach of these Terms, or where required by law. Except where the breach is serious or the law requires otherwise, we will give notice and a reasonable chance to put it right.
- Sections 6, 7, 15, 18, 19, 20 and 21 survive termination.
18. Warranties and disclaimers
The platform is provided "as is". To the fullest extent the law allows, we make no warranty that it will be uninterrupted, error-free, or fit for any particular purpose, and we disclaim all warranties not expressly stated in these Terms.
Nothing in these Terms excludes any warranty or right that Philippine law does not permit us to exclude.
19. Limitation of liability
To the fullest extent the law allows, we are not liable for indirect or consequential loss, loss of profits, loss of goodwill, or loss or corruption of data arising from your use of the platform. Our total liability arising out of or in connection with these Terms is limited to the fees paid for the platform in the twelve months before the claim arose.
Nothing in this section limits liability for fraud, for death or personal injury caused by negligence, or for anything else that Philippine law does not permit to be limited. We do not limit, and cannot limit, a clinician's own responsibility for clinical decisions.
20. Indemnity
The clinic will indemnify us against claims arising from information it records on the platform, from its instructions to us, from its staff's use of the platform, or from its breach of these Terms — except to the extent the claim arises from our own breach.
21. Governing law and venue
These Terms are governed by the laws of the Republic of the Philippines. The courts of Baguio City have exclusive jurisdiction, without prejudice to any right to bring a complaint before the National Privacy Commission or another regulator.
22. Changes to these Terms
We may change these Terms. When we make a material change we will update the date at the top of this page and notify the clinic's account contact by email and in the application, at least 30 days before it takes effect. Continuing to use the platform after that date means accepting the change. If you do not accept it, stop using the platform and, if you are the clinic, ask us to close the account.
23. General
- Entire agreement and precedence. These Terms, the Privacy Policy and the Pricing page are the whole agreement. Where a signed order form or data processing agreement covers the same ground, that signed document prevails.
- Force majeure. Neither party is liable for failure caused by events beyond its reasonable control, including typhoons, earthquakes, floods, fire, power failure, telecommunications or internet failure, government action, or civil disturbance.
- Feedback. If you suggest an improvement, we may use it without obligation to you.
- Severability. If any provision is unenforceable, the rest continues in force.
- No waiver. Not enforcing a provision is not a waiver of it.
- Assignment. You may not assign these Terms without our consent. We may assign them as part of a merger, acquisition or sale of the business, on notice to you.
24. Contact
- Patients: please contact the clinic where you are seen.
- Everyone else: please use the contact form on the public portal, or reach out to the operator at the address in section 1.