Data security & privacy

Your patients.
Your data. Protected in India.

Clinics trust Healui with the most sensitive records they hold. This page explains, in plain language, where that data lives, who can see it, what protects it, and what we have not finished building yet.

Built for the DPDP Act, 2023Patient data held in IndiaHIPAA-grade safeguards

The short version

Three promises,

kept by architecture, not policy.

  1. 01

    Held in India

    Records, documents, images, recordings and backups all live in AWS Mumbai. The one exception, AI processing, is named further down this page rather than buried in a policy.

  2. 02

    Encrypted in layers

    TLS 1.3 on every connection. AES-256 at rest. Sensitive fields encrypted individually before they are written, with keys held in a hardware security module.

  3. 03

    Yours, and only yours

    Patients you add belong to your clinic. We never sell data, never market to your patients, and never surface them in the Healui marketplace.

Where we actually are

What is live,

and what is not.

Most security pages describe an aspiration. This one separates the two lists, because you are going to find out either way, and it is better that you find out here.

Live today

In production, and demonstrable to your team.

  • Patient data stored in AWS Mumbai (ap-south-1)
  • TLS 1.3 on every connection, including to the database
  • AES-256 encryption at rest, including backups
  • Field-level encryption of names, contact details and clinical content
  • Encryption keys held in a hardware security module (AWS KMS)
  • Role-based access control, scoped to your clinic
  • Row-level security enforced inside the database on core patient tables, a second layer beneath application checks
  • Tamper-evident, hash-chained consent records
  • Per-record access logging across every clinical endpoint, enforced by build checks
  • Refused access attempts recorded, not silently dropped
  • Tamper-evident infrastructure audit trail
  • Access review screen for clinic administrators: who accessed a patient, what a staff member accessed
  • One-click record export from the dashboard (PDF and JSON)
  • Self-service account deletion, verified by SMS code
  • Consent withdrawal written to the tamper-evident log
  • Access reports produced on request

In development

Not in place yet. Nothing above depends on it.

  • Account deletion from inside the patient appIn progress
  • Self-service consent screens for patientsIn progress
  • Patient-facing access historyIn progress
  • Formal data processing agreements with every clinic partnerIn progress
  • ISO 27001 certificationUnder evaluation

The DPDP Act's substantive obligations become enforceable in May 2027. Our roadmap is built around having your clinic well ahead of that date, not scrambling towards it.

Residency

Where your data lives

Every layer of Healui runs from AWS Mumbai (ap-south-1), the same cloud infrastructure trusted by leading banks and hospitals. The DPDP Act does not currently require health data to stay in India. We keep it here anyway, because it removes a question your patients and your own governance will reasonably ask.

Patient records & clinical notes
Encrypted database, Mumbai, India
Documents, imaging & photos
Encrypted object storage, Mumbai, India
Voice recordings & transcripts
Private encrypted storage, Mumbai, India
Backups
Daily, point-in-time recovery, same region
Encryption keys
AWS KMS, Mumbai, held apart from the data

One exception you should know about

Where a clinician uses our AI features, consultation transcription and clinical documentation support, audio and clinical text are processed by AI providers whose servers are outside India, primarily in the United States. This is named in the patient consent notice and requires the patient's agreement. If it matters for your clinic, those features can be discussed before onboarding.

Isolation

Your patients are visible

to your clinic. Full stop.

The fear we hear most from clinic owners: 'will my patient list leak to the platform, or to other clinics?' Here is exactly what stops it.

Can other clinics see my patients?

No.

Every request is authorised on the server against the clinic that owns the record, on every endpoint, not by the interface hiding options. And the database itself enforces the same boundary through row-level security: even a query that slipped past application checks would come back empty.

Does the Healui marketplace see them?

Never.

Marketplace patients are a separate population with their own direct consent to Healui. Your EMR patients are never matched, surfaced, or marketed to.

Can Healui staff browse records?

Only to serve you.

We process records solely on your instructions as your Data Processor. There are no patient-browsing tools, identifiers are masked internally, patient names never enter diagnostic logs, and every access is recorded.

And the simplest guarantee of all: we never sell data. Not to insurers, not to pharma, not to advertisers. It is written into every patient consent notice we serve.

Safeguards

How we protect it

The same control families HIPAA's Security Rule demands, applied under Indian law and verifiable in our architecture.

Encryption in transit

Every connection uses TLS 1.3, from browser and app to our servers, and from our servers to the database. Nothing is transmitted unprotected.

Encryption at rest

AES-256 across database storage, automated backups and uploaded files. This is what protects you against physical theft of storage media.

Field-level encryption

Names, contacts, history, medications, complaints, assessments, transcripts and message content are encrypted individually with AES-256-GCM before being written. Search still works, through blind indexing.

Keys kept apart from data

Keys live in AWS KMS, never beside the data. If our database were copied, the copy would be unreadable. Reading it would need a second, separately controlled compromise.

Clinic isolation

Every request is authorised on the server against the clinic that owns the record. Hiding a button is not access control. And beneath the application, row-level security inside the database enforces the same boundary independently: a query without a legitimate clinic context returns no rows at all.

Audit trails

Who touched which record, when, from where, and whether it was allowed or refused, including how many records a list view returned. Retained 13 months, so a report always covers a full preceding year.

What the access log covers, and what it does not

It records access through the application, which is how clinical staff reach patient data. It does not record scheduled background processing, or direct database access by our own engineers under emergency maintenance. Those are governed by the infrastructure audit trail and by restricted, individually issued credentials. We would rather state that boundary than let “full access logging” imply more than it delivers.

Patient rights

Consent you can prove,

and erasure that means it.

Consent is requested through a link sent to the patient's own phone, so the person agreeing is the person the record belongs to. Every consent action is written to an append-only, hash-chained log: records are never edited, each entry is cryptographically linked to the one before it, and the exact notice the patient saw is stored alongside it. If you are ever asked to prove consent was properly obtained, that is the evidence.

What withdrawal does, stated plainly

A patient may withdraw at any time, in whole or for a single purpose, and it is written to the same tamper-evident log as the original consent. But it records the decision; it does not switch anything off by itself. Acting on it, stopping treatment or stopping messages, is a clinical decision for you, and the record exists so that decision is documented and provable. The self-service screen a patient would tap is still in development, so withdrawal today goes through a person. The record it produces is the same either way.

When a patient deletes their account

A patient can delete their Healui account themselves at healui.com/delete-account, without signing in, which matters because most people asking have already removed the app. They enter their mobile number, confirm a one-time SMS code, and the account is erased. The page shows exactly what goes and what stays first, because the part people do not expect is the part that is kept.

Removed

  • Name, phone, email, date of birth, gender and address
  • Medical history, allergies and medications held on the account
  • Saved addresses, dietary profile, saved physiotherapists
  • Searchability, so the person can no longer be found by name or number

Kept

  • Appointment and treatment records the clinic must retain
  • Invoices and payment records, required for tax
  • The consent record proving data was handled lawfully
  • The access log, which exists to protect the patient

Why records are anonymised rather than destroyed. Erasure strips the identifying data and leaves the clinical and financial records standing, unlinked from a person. Destroying them outright would take with it the invoices you are required to keep, the treatment history a future clinician may need, and, most importantly, the consent record and access log that together prove the patient's data was handled properly. Deleting those would erase the evidence that protects the patient, which is the opposite of what an erasure request is for.

Clinical records follow the statutory minimum of three years from the start of treatment, with ten years recommended in line with national health-record guidance. Consent and withdrawal evidence is retained separately, as proof of lawful processing.

Sub-processors

Who else touches the data

A small number of established providers, each under data-processing terms as part of our agreements with them. Each receives only what its function requires. We store no card details, and notification messages are written to avoid clinical detail: sensitive content stays behind an authenticated link rather than in the message itself.

Amazon Web Services

Hosting, database, file storage, encryption keys

India (Mumbai)

DPA in place

Google Firebase

Phone-number verification at sign-in

Outside India

DPA in place

Meta (WhatsApp)

Appointment and care notifications

Outside India

DPA in place

Razorpay

Payment processing

India

DPA in place

AI providers

Transcription and clinical documentation support

Outside India

DPA in progress

Incidents

If something goes wrong

On becoming aware of a personal data breach we contain it, assess what was affected, and notify you without undue delay with what we know, what we are doing, and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions.

Under the DPDP Act, the obligation to notify the Data Protection Board and your affected patients sits with your clinic as Data Fiduciary. Our role is to give you the facts quickly enough to meet it.

The access log is what makes that possible in practice. Without a record of who reached which records, a clinic facing an incident must either notify every patient it holds or estimate the scope. With it, the affected set can be identified and named. That is the difference between a contained disclosure and a letter to your entire patient list.

Compliance & control

Built for Indian law,

with the controls in your hands.

Under the DPDP Act, 2023, your clinic is the Data Fiduciary for its patients and Healui (Alleda Lifestyle Private Limited) is your Data Processor. The legal duty stays with you. Our job is infrastructure that makes meeting it straightforward.

  1. 01

    A data processing agreement

    Under the DPDP Act your clinic needs a contract with its processor. We are rolling these out to every clinic partner now. Email support@healui.com and we will send you ours, without making you chase it through a sales team.

  2. 02

    Consent, built in

    Patients receive a bilingual consent notice on their own phone when added. Every grant and withdrawal is recorded in a tamper-evident log you can produce as evidence.

  3. 03

    Access reports, self-service

    Who accessed a given patient's records, and what a given staff member accessed, now a screen in your clinic settings, admin-only, with CSV download for handing a patient their report. Opening a report is itself written to the access log, so the watchers are watched. support@healui.com still produces reports on request if you prefer.

  4. 04

    A Grievance Officer who answers

    Patients and clinics can raise any data concern directly, and escalate to the Data Protection Board of India if we do not resolve it.

FAQ

Questions, answered.

HIPAA is a United States law that applies to US healthcare providers, so no software operating in India can be "HIPAA certified". Anyone claiming that is overselling. What we do instead is implement the same safeguards HIPAA's Security Rule requires: encryption in transit and at rest, role-based access control, audit logging, and breach procedures. And we build for the law that actually governs your clinic: India's Digital Personal Data Protection Act, 2023.

Not yet, and we would rather say so than imply otherwise. ISO 27001 matters in India for a specific reason: it is the standard named in the SPDI Rules under the IT Act as evidence of "reasonable security practices". Certification is under evaluation and we have not committed to a date. Everything on this page is implemented and can be demonstrated to your team today; none of it is audited by an independent third party yet.

In India. Your database records, uploaded documents, clinical photos, voice recordings and backups are all held in AWS Mumbai (ap-south-1). There is one exception you should know about: our AI features send audio and clinical text to AI providers whose servers are outside India, primarily in the United States. That is disclosed in the consent notice every patient signs, and a clinic that would rather not use those features can tell us before onboarding.

No. Every request is authorised on the server against the clinic that owns the record, so staff reach only their own clinic's patients. Healui has no patient-browsing screens, identifiers are masked in our internal tools, and every access is logged. We never use your patient list for marketing or for the Healui marketplace. Marketplace patients are a separate population who consent to Healui directly.

Consultation transcription and clinical documentation support are processed by AI providers whose servers sit outside India, primarily in the United States. Structured records are stripped of name, phone number and email before processing. Consultation audio is different, because a recording contains whatever was said aloud, so we treat those recordings as identifiable and protect them accordingly rather than pretending they are anonymous. Providers are contracted to use the data only to return the result, never to train models. All of this is named in the consent notice every patient signs, in English and Hindi.

Yes, and there is no lock-in clause or waiting period. Your dashboard has one-click export of a patient's record in PDF and JSON, the document a patient asking "what do you hold about me?" is entitled to, generated instantly and logged in the access trail like any other disclosure. For a complete clinic export when leaving, email support@healui.com and we produce your clinic's full records in standard formats. Your data is yours either way; our job is to be worth staying for.

Under the DPDP Act, your clinic is the Data Fiduciary for patients you add, and Healui is your Data Processor. We process records only on your instructions. To make consent easy, Healui builds it in: when you add a patient, they receive a consent notice on their own phone in English or Hindi, and their response is recorded in a tamper-evident audit log you can produce at any time.

We contain it, assess what was affected, and tell you without undue delay what we know, what we are doing and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions. Under the DPDP Act, the duty to notify the Data Protection Board and your affected patients sits with you as Data Fiduciary. Our access log is what makes that survivable: without a record of who reached which records, a clinic facing an incident has to notify every patient it holds. With it, the affected set can be named.

Questions

Ask us anything about your data.

Our Grievance Officer answers every question, from a one-line doubt to a full security review for your clinic's governance or procurement lead. For a data processing agreement, an access report, or an export of your records, write to support@healui.com.

Trust isn't a page. It's an architecture.