Data security & privacy
Clinics trust Healui with the most sensitive records they hold. This page explains, in plain language, where that data lives, who can see it, what protects it, and what we have not finished building yet.
Built for the DPDP Act, 2023Patient data held in IndiaHIPAA-grade safeguards
The short version
kept by architecture, not policy.
Records, documents, images, recordings and backups all live in AWS Mumbai. The one exception, AI processing, is named further down this page rather than buried in a policy.
TLS 1.3 on every connection. AES-256 at rest. Sensitive fields encrypted individually before they are written, with keys held in a hardware security module.
Patients you add belong to your clinic. We never sell data, never market to your patients, and never surface them in the Healui marketplace.
Where we actually are
and what is not.
Most security pages describe an aspiration. This one separates the two lists, because you are going to find out either way, and it is better that you find out here.
Live today
In production, and demonstrable to your team.
In development
Not in place yet. Nothing above depends on it.
The DPDP Act's substantive obligations become enforceable in May 2027. Our roadmap is built around having your clinic well ahead of that date, not scrambling towards it.
Residency
Every layer of Healui runs from AWS Mumbai (ap-south-1), the same cloud infrastructure trusted by leading banks and hospitals. The DPDP Act does not currently require health data to stay in India. We keep it here anyway, because it removes a question your patients and your own governance will reasonably ask.
One exception you should know about
Where a clinician uses our AI features, consultation transcription and clinical documentation support, audio and clinical text are processed by AI providers whose servers are outside India, primarily in the United States. This is named in the patient consent notice and requires the patient's agreement. If it matters for your clinic, those features can be discussed before onboarding.
Isolation
to your clinic. Full stop.
The fear we hear most from clinic owners: 'will my patient list leak to the platform, or to other clinics?' Here is exactly what stops it.
Can other clinics see my patients?
No.
Every request is authorised on the server against the clinic that owns the record, on every endpoint, not by the interface hiding options. And the database itself enforces the same boundary through row-level security: even a query that slipped past application checks would come back empty.
Does the Healui marketplace see them?
Never.
Marketplace patients are a separate population with their own direct consent to Healui. Your EMR patients are never matched, surfaced, or marketed to.
Can Healui staff browse records?
Only to serve you.
We process records solely on your instructions as your Data Processor. There are no patient-browsing tools, identifiers are masked internally, patient names never enter diagnostic logs, and every access is recorded.
And the simplest guarantee of all: we never sell data. Not to insurers, not to pharma, not to advertisers. It is written into every patient consent notice we serve.
Safeguards
The same control families HIPAA's Security Rule demands, applied under Indian law and verifiable in our architecture.
Every connection uses TLS 1.3, from browser and app to our servers, and from our servers to the database. Nothing is transmitted unprotected.
AES-256 across database storage, automated backups and uploaded files. This is what protects you against physical theft of storage media.
Names, contacts, history, medications, complaints, assessments, transcripts and message content are encrypted individually with AES-256-GCM before being written. Search still works, through blind indexing.
Keys live in AWS KMS, never beside the data. If our database were copied, the copy would be unreadable. Reading it would need a second, separately controlled compromise.
Every request is authorised on the server against the clinic that owns the record. Hiding a button is not access control. And beneath the application, row-level security inside the database enforces the same boundary independently: a query without a legitimate clinic context returns no rows at all.
Who touched which record, when, from where, and whether it was allowed or refused, including how many records a list view returned. Retained 13 months, so a report always covers a full preceding year.
What the access log covers, and what it does not
It records access through the application, which is how clinical staff reach patient data. It does not record scheduled background processing, or direct database access by our own engineers under emergency maintenance. Those are governed by the infrastructure audit trail and by restricted, individually issued credentials. We would rather state that boundary than let “full access logging” imply more than it delivers.
Patient rights
and erasure that means it.
Consent is requested through a link sent to the patient's own phone, so the person agreeing is the person the record belongs to. Every consent action is written to an append-only, hash-chained log: records are never edited, each entry is cryptographically linked to the one before it, and the exact notice the patient saw is stored alongside it. If you are ever asked to prove consent was properly obtained, that is the evidence.
What withdrawal does, stated plainly
A patient may withdraw at any time, in whole or for a single purpose, and it is written to the same tamper-evident log as the original consent. But it records the decision; it does not switch anything off by itself. Acting on it, stopping treatment or stopping messages, is a clinical decision for you, and the record exists so that decision is documented and provable. The self-service screen a patient would tap is still in development, so withdrawal today goes through a person. The record it produces is the same either way.
When a patient deletes their account
A patient can delete their Healui account themselves at healui.com/delete-account, without signing in, which matters because most people asking have already removed the app. They enter their mobile number, confirm a one-time SMS code, and the account is erased. The page shows exactly what goes and what stays first, because the part people do not expect is the part that is kept.
Removed
Kept
Why records are anonymised rather than destroyed. Erasure strips the identifying data and leaves the clinical and financial records standing, unlinked from a person. Destroying them outright would take with it the invoices you are required to keep, the treatment history a future clinician may need, and, most importantly, the consent record and access log that together prove the patient's data was handled properly. Deleting those would erase the evidence that protects the patient, which is the opposite of what an erasure request is for.
Clinical records follow the statutory minimum of three years from the start of treatment, with ten years recommended in line with national health-record guidance. Consent and withdrawal evidence is retained separately, as proof of lawful processing.
Sub-processors
A small number of established providers, each under data-processing terms as part of our agreements with them. Each receives only what its function requires. We store no card details, and notification messages are written to avoid clinical detail: sensitive content stays behind an authenticated link rather than in the message itself.
Amazon Web Services
Hosting, database, file storage, encryption keys
India (Mumbai)
DPA in place
Google Firebase
Phone-number verification at sign-in
Outside India
DPA in place
Meta (WhatsApp)
Appointment and care notifications
Outside India
DPA in place
Razorpay
Payment processing
India
DPA in place
AI providers
Transcription and clinical documentation support
Outside India
DPA in progress
Incidents
On becoming aware of a personal data breach we contain it, assess what was affected, and notify you without undue delay with what we know, what we are doing, and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions.
Under the DPDP Act, the obligation to notify the Data Protection Board and your affected patients sits with your clinic as Data Fiduciary. Our role is to give you the facts quickly enough to meet it.
The access log is what makes that possible in practice. Without a record of who reached which records, a clinic facing an incident must either notify every patient it holds or estimate the scope. With it, the affected set can be identified and named. That is the difference between a contained disclosure and a letter to your entire patient list.
Compliance & control
with the controls in your hands.
Under the DPDP Act, 2023, your clinic is the Data Fiduciary for its patients and Healui (Alleda Lifestyle Private Limited) is your Data Processor. The legal duty stays with you. Our job is infrastructure that makes meeting it straightforward.
Under the DPDP Act your clinic needs a contract with its processor. We are rolling these out to every clinic partner now. Email support@healui.com and we will send you ours, without making you chase it through a sales team.
Patients receive a bilingual consent notice on their own phone when added. Every grant and withdrawal is recorded in a tamper-evident log you can produce as evidence.
Who accessed a given patient's records, and what a given staff member accessed, now a screen in your clinic settings, admin-only, with CSV download for handing a patient their report. Opening a report is itself written to the access log, so the watchers are watched. support@healui.com still produces reports on request if you prefer.
Patients and clinics can raise any data concern directly, and escalate to the Data Protection Board of India if we do not resolve it.
FAQ
HIPAA is a United States law that applies to US healthcare providers, so no software operating in India can be "HIPAA certified". Anyone claiming that is overselling. What we do instead is implement the same safeguards HIPAA's Security Rule requires: encryption in transit and at rest, role-based access control, audit logging, and breach procedures. And we build for the law that actually governs your clinic: India's Digital Personal Data Protection Act, 2023.
Not yet, and we would rather say so than imply otherwise. ISO 27001 matters in India for a specific reason: it is the standard named in the SPDI Rules under the IT Act as evidence of "reasonable security practices". Certification is under evaluation and we have not committed to a date. Everything on this page is implemented and can be demonstrated to your team today; none of it is audited by an independent third party yet.
In India. Your database records, uploaded documents, clinical photos, voice recordings and backups are all held in AWS Mumbai (ap-south-1). There is one exception you should know about: our AI features send audio and clinical text to AI providers whose servers are outside India, primarily in the United States. That is disclosed in the consent notice every patient signs, and a clinic that would rather not use those features can tell us before onboarding.
No. Every request is authorised on the server against the clinic that owns the record, so staff reach only their own clinic's patients. Healui has no patient-browsing screens, identifiers are masked in our internal tools, and every access is logged. We never use your patient list for marketing or for the Healui marketplace. Marketplace patients are a separate population who consent to Healui directly.
Consultation transcription and clinical documentation support are processed by AI providers whose servers sit outside India, primarily in the United States. Structured records are stripped of name, phone number and email before processing. Consultation audio is different, because a recording contains whatever was said aloud, so we treat those recordings as identifiable and protect them accordingly rather than pretending they are anonymous. Providers are contracted to use the data only to return the result, never to train models. All of this is named in the consent notice every patient signs, in English and Hindi.
Yes, and there is no lock-in clause or waiting period. Your dashboard has one-click export of a patient's record in PDF and JSON, the document a patient asking "what do you hold about me?" is entitled to, generated instantly and logged in the access trail like any other disclosure. For a complete clinic export when leaving, email support@healui.com and we produce your clinic's full records in standard formats. Your data is yours either way; our job is to be worth staying for.
Under the DPDP Act, your clinic is the Data Fiduciary for patients you add, and Healui is your Data Processor. We process records only on your instructions. To make consent easy, Healui builds it in: when you add a patient, they receive a consent notice on their own phone in English or Hindi, and their response is recorded in a tamper-evident audit log you can produce at any time.
We contain it, assess what was affected, and tell you without undue delay what we know, what we are doing and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions. Under the DPDP Act, the duty to notify the Data Protection Board and your affected patients sits with you as Data Fiduciary. Our access log is what makes that survivable: without a record of who reached which records, a clinic facing an incident has to notify every patient it holds. With it, the affected set can be named.
Questions
Our Grievance Officer answers every question, from a one-line doubt to a full security review for your clinic's governance or procurement lead. For a data processing agreement, an access report, or an export of your records, write to support@healui.com.
Trust isn't a page. It's an architecture.