Data security & privacy

Your patients.
Your data. Protected in India.

Clinics trust Healui with the most sensitive records they hold. This page explains, in plain language, where that data lives, who can see it, and what protects it.

All data stored in IndiaDPDP Act, 2023HIPAA-grade safeguards

The short version

Threepromises,

keptbyarchitecture,notpolicy.

  1. 01

    Stored in India

    Records, documents, images, recordings and backups: every byte lives in secure data centres in Mumbai. Nothing is stored outside India.

  2. 02

    Encrypted everywhere

    TLS on every connection. AES-256 encryption at rest with managed keys. Sensitive fields carry a second layer of encryption.

  3. 03

    Yours, provably

    Patients you add belong to your clinic. Export them anytime, in one click. We never sell data and never market to your patients.

Residency

Whereyourdatalives

Every layer of Healui runs from secure data centres in Mumbai, on the same cloud infrastructure trusted by leading banks and hospitals. Data residency isn't a roadmap item. It is how the system is built.

Patient records & clinical notes
Encrypted database, Mumbai, India
Documents, imaging & photos
Encrypted object storage, Mumbai, India
Voice recordings & transcripts
Private encrypted storage, Mumbai, India
Backups
Daily, point-in-time recovery, same region
AI treatment analysis
De-identified and consented. Name, phone and email never shared

Isolation

Yourpatientsarevisible

toyourclinic.Fullstop.

The fear we hear most from clinic owners: 'will my patient list leak to the platform, or to other clinics?' Here is exactly why it can't.

Can other clinics see my patients?

Never.

Isolation is enforced by the database itself (row-level security), not just application code. A bug cannot leak what the database refuses to return.

Does the Healui marketplace see them?

Never.

Marketplace patients are a separate population with their own direct consent to Healui. Your EMR patients are never matched, surfaced, or marketed to.

Can Healui staff browse records?

Only to serve you.

We process records solely on your instructions as your Data Processor. No patient-browsing tools, masked identifiers internally, every access logged.

And the simplest guarantee of all: we never sell data. Not to insurers, not to pharma, not to advertisers. It is written into every patient consent notice we serve.

Safeguards

Howweprotectit

The same control families HIPAA's Security Rule demands, applied under Indian law and verified in our architecture.

Encryption in transit

Every connection, from app to browser to database to storage, is TLS-encrypted. Our storage refuses unencrypted connections outright.

Encryption at rest

AES-256 on the database and file storage, with securely managed keys. Patient contact details carry field-level encryption on top.

Isolation at the database

Row-level security means the database itself, not just the application, refuses to return one clinic's patients to another. Ever.

Identity masking

Names, phone numbers and emails are masked in our internal tools. Role-based access for your staff, and no patient-browsing screens for Healui admins.

Audit trails

Every access to a patient record is logged, and clinic owners can see who on their team viewed what. Consent records are hash-chained and tamper-evident.

Backups & durability

Automated daily backups with point-in-time recovery, versioned file storage, and deletion protection on production databases.

And when AI helps plan treatment, identity never goes with it. Your patient's name, phone number, email and address are stripped before any processing. Only the clinical picture, such as age, symptoms and relevant history, is ever shared.

Compliance & control

BuiltforIndianlaw,

withthecontrolsinyourhands.

Under the DPDP Act, 2023, your clinic is the Data Fiduciary for its patients and Healui is your Data Processor. The product is built so that holding up your side is effortless.

  1. 01

    Export everything, anytime

    One-click export of your clinic's complete records in standard formats. No lock-in, no waiting period.

  2. 02

    Consent, built in

    Patients receive a bilingual consent notice on WhatsApp when added. Every grant and withdrawal is recorded in a tamper-evident log.

  3. 03

    A named Grievance Officer

    Patients and clinics can raise any data concern directly, and escalate to the Data Protection Board of India if we don't resolve it.

  4. 04

    Retention that follows the law

    Clinical records are retained for the statutory minimum of 3 years, aligned with national health-record guidelines.

FAQ

Questions,answered.

HIPAA is a United States law that applies to US healthcare providers, so no software operating in India can be "HIPAA certified". Anyone claiming that is overselling. What we do instead is implement the same safeguards HIPAA requires: encryption in transit and at rest, role-based access control, audit logging, and breach procedures. And we comply fully with the law that actually governs your clinic: India's Digital Personal Data Protection Act, 2023.

In India. Your database records, uploaded documents, clinical photos and voice recordings are all stored in secure data centres in Mumbai, with automated daily backups kept in the same region. Nothing is stored outside India. We run on the same cloud infrastructure trusted by leading banks and hospitals worldwide.

No. Every patient record is bound to your clinic, and isolation is enforced at the database level, so a query from another clinic physically cannot return your patients. Healui staff do not browse patient records, every access is logged, and we never use your patient list for marketing or for the Healui marketplace. Marketplace patients are a separate population who consent to Healui directly.

AI features that help plan treatment, like voice transcription and clinical analysis, process some data with trusted providers under contract, used only for that patient's care and never for training or anything else. Before anything is processed, identity is stripped out: your patient's name, phone number, email and address never leave Healui. Only the clinical details needed for care, such as age, symptoms and relevant history, are shared for processing. All of this is disclosed to every patient in the consent notice they sign, in English and Hindi.

Yes, anytime. You can export your clinic's complete patient records from the dashboard in standard formats. No lock-in, no waiting period, no "contact sales". Your data is yours; our job is to be worth staying for.

Under the DPDP Act, your clinic is the Data Fiduciary for patients you add, and Healui is your Data Processor. We process records only on your instructions. To make consent easy, Healui builds it in: when you add a patient, they receive a consent notice on WhatsApp in English or Hindi, and their response is recorded in a tamper-evident audit log you can produce at any time.

Questions

Askusanythingaboutyourdata.

Our Grievance Officer answers every question, from a one-line doubt to a full security review for your hospital's procurement team.

Trust isn't a page. It's an architecture.