Earning the right to hold medical records: how we hardened ClinLexis
Medico-legal software sits at the intersection of the two most attacked sectors in the UK. This summer we set out to make the security of ClinLexis something that is independently tested and demonstrated, not asserted.
Ahmmad Youssef, PhD
Technical Co-founder & Data Protection Officer, ClinLexis
If you build software that reads medical records for litigation, you sit at the intersection of the two most attacked sectors in the UK.
Healthcare first. The Synnovis ransomware attack in June 2024 forced London hospitals to postpone thousands of appointments and operations because a pathology supplier was compromised. NHS 111 was disrupted in 2022 when Advanced, a software supplier, was hit. The pattern is consistent: attackers no longer go through the front door of the NHS, they go through its suppliers.
The legal sector second. When CTS, a managed service provider to law firms, was attacked in late 2023, property transactions stalled across the country. In 2025 the Legal Aid Agency confirmed a breach affecting applicants’ personal data. The Information Commissioner and the National Cyber Security Centre have both been explicit that law firms are attractive targets precisely because of the sensitivity of what they hold.
Medico-legal work combines the two: clinical records, held for the purpose of litigation. If we expect solicitors, chambers and NHS organisations to put that material on our platform, “trust us” is not an answer. So this summer we set out to make the security of ClinLexis something that is independently tested and demonstrated, not asserted. Here is what that looked like.
Cyber Essentials Plus, the hands-on tier
ClinLexis was certified to Cyber Essentials Plus in July 2026. The baseline Cyber Essentials certification is a self-assessment. Plus is different: an independent assessor tests your systems hands-on, verifying secure configuration, patching, malware protection, access control and boundary protections in practice. We hold both, and both are renewed annually.
A penetration test with an uncomfortable brief
Also in July, a CREST-approved security company tested the platform to CREST and OWASP methodologies. We set them a specific objective: get case data out of an account it does not belong to.
Key insight
Across roles, cases and tenants, no unauthorised access to case data or records was achieved, and the test found nothing of critical, high or medium severity. Our policy is to remediate anything at medium or above; the low-severity observations were fixed anyway.
That brief was deliberate. Tenant isolation is the property our customers actually depend on. A chambers running dozens of cases needs certainty that an expert invited into one case sees that case and nothing else, and that no other organisation on the platform can reach their material at all.
Hardening the front door
Some of the most valuable security work is unglamorous. Over the summer we have also:
- enforced multi-factor authentication across the platform. New accounts enrol at first sign-in, and enterprise tenants can require it for every collaborator they invite;
- added Cloudflare Turnstile and layered rate limiting to our public endpoints. Automated abuse of sign-up and contact forms is a fact of life on the modern internet, and those endpoints now fail closed;
- applied a single strong password policy to every path into the platform, including invitations and resets, and made access tokens revocable the moment a user signs out.
The foundations that do not change
Everything above sits on commitments that predate this summer. All customer data is stored in the United Kingdom: databases, documents, backups and audit logs. Data is encrypted in transit and at rest. Model inputs and outputs are not retained by any AI provider and are never used to train models. The full detail of our infrastructure and sub-processors is shared with enterprise customers under our Data Processing Agreement.
ClinLexis has published Standards Met on the NHS Data Security and Protection Toolkit, maintains clinical safety documentation under DCB0129 with an appointed Clinical Safety Officer, and maintains a Data Protection Impact Assessment that covers the AI pipeline end to end. Enterprise customers contract under our standard Data Processing Agreement.
Why this matters more every month
The threat picture is not improving. The National Cyber Security Centre handled 204 nationally significant incidents in the year to September 2025, more than double the previous year, and health remains one of the top sectors reporting ransomware activity (NCSC Annual Review 2025). Every firm we speak to is being asked harder questions by insurers, regulators and clients about the tools they use. We would rather be the easy answer to those questions.
Security work is never finished. Certifications renew annually, tests repeat, and the hardening backlog never empties. But “enterprise grade” should mean something you can check, not a phrase on a landing page. You can read more on our security page, and our full security and compliance pack is available to enterprise customers and their advisers on request.

