Data Security First

Privacy Policy

Your privacy and the security of healthcare data are our top priorities. This policy outlines how we handle and protect information in compliance with Indian and global healthcare standards.

Compliance status: iHospital365 is actively implementing the practices described below and is not yet certified compliant with the DPDP Act, 2023. See our Compliance Roadmap for current status on each item.

1. Introduction

iHospital365 ("we", "us", or "our") is committed to protecting the privacy of our users, particularly in the healthcare sector. This Privacy Policy is formulated in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000, and describes both our current practices and the practices we are actively building toward.

2. Data Fiduciary Roles

Under the DPDP Act 2023, iHospital365 acts as a Data Fiduciary when we determine the purpose and means of processing personal data. We ensure that data processing is lawful, fair, and transparent.

3. Informed Consent Management

We process personal data only based on "Notice and Consent". Every user or patient has the right to:

  • Receive a clear and concise notice before giving consent.
  • Give consent that is free, specific, informed, and unconditional.
  • Withdraw consent at any time, with the ease of withdrawal being comparable to the ease of giving consent.

4. Data Localization & Sovereignty

In compliance with Indian regulations, all sensitive personal health data of our Indian clients and their patients is stored exclusively within certified data centers located in India. We do not transfer this data outside Indian jurisdiction unless specifically permitted by the Central Government.

5. Patient (Data Principal) Rights

We empower individuals with the following rights as per Indian law:

  • Right to Access: Summary of personal data being processed and the processing activities.
  • Right to Correction & Erasure: Ability to update inaccurate data or request deletion when data is no longer necessary.
  • Right to Nomination: The right to nominate an individual to exercise rights in case of death or incapacity.
  • Right of Grievance Redressal: Access to a robust mechanism for addressing privacy concerns.

6. Data Security & Breaches

We implement AES-256 encryption for data at rest and TLS 1.3 for data in transit. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals (patients/users) within the timelines stipulated by the DPDP Rules.

7. Consent Manager

iHospital365 allows patients to manage their consent through a Consent Manager framework. Patients can grant, manage, or revoke access to their health records at any time, ensuring total sovereignty over their medical history as envisioned by the ABDM framework.

7. Data Protection Officer (DPO)

For any queries or grievances, you may contact our designated Data Protection Officer at:
Email: support@ihospital365.in
India