Data security

Dr Fox (Index Medical Ltd) uses high-level data encryption to ensure our customer's data is not compromised in transit or 'at rest' on the server.

Data entry and retrieval is encrypted using an SSL certificate from Sectigo, a leading SSL Certificate Authority. This ensures that no one else can read or change information as it travels over the internet. Click the logo to verify.

Look for the locked padlock in your browser address bar to indicate a secure and encrypted connection to

Our server software is continually monitored and updated by our hosting company Linode.

Qualys SSL Labs rate the server security as A+.

Personal online security

Patients using the Dr Fox service take responsibility for their own personal online security. For advice please visit the Get Safe Online service.

  • If your email account(s) is compromised it can be used to gain access to your Dr Fox account. Dr Fox does not send sensitive personal details by email, but it is recommended to delete any emails no longer needed.
  • Use unique passwords, with a mix of numbers, letters (lower and uppercase), preferably at least 12 characters long.
  • Change passwords regularly.
  • Install anti-virus software on your computer and keep up-to-date.
  • Keep operating system and browser software up-to-date.
  • Do not save passwords on the web browser on shared computers.
  • Remember to log-out of your Dr Fox account when finished.
  • Use a pin code or fingerprint ID to access your personal devices.
  • Check your security and privacy settings on your browser, paying particular attention to saving of websites visited.
  • Carefully check the URL (shown in browser address bar) of any website you visit to determine it is authentic.

PCI Compliant

PCI logo is 'Payment Card Industry Data Security Standards' (PCI DSS) compliant and is regularly scanned for server vulnerabilities that could be exploited by hackers in security audits by Security Metrics. Click the logo to verify.

SecurityMetrics for PCI Compliance logo

Customer's payment card details are not stored on our servers (payment security).

Personal and private information

We fully understand our customers are concerned with the security of their personal and private data and we take every measure possible to ensure it is never at risk.

Index Medical Ltd abides by the Data Protection Act - our Information Commissioner's Office's Register Entry Report certificate registration number is Z258592X (renews 15 March annually).

The new GDPR directive came into force in May 2018 and remains in effect, and Index Medical Ltd is fully compliant.

Please also see our Privacy Policy statement.