Back to home
CliniRec
US (HIPAA) & India (DPDP Act) Compliance Policy

How we protect your data — and what we do if it's ever compromised

CliniRec is built to comply with both U.S. federal health-privacy law — the HIPAA Privacy, Security, and Breach Notification Rules (45 CFR Parts 160 & 164) — and India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Ayushman Bharat Digital Mission (ABDM) framework, and the EHR Standards, 2016. This page explains, in plain language, the rules we follow and the exact steps we take to notify and protect you in the event of a data breach.

Privacy Rule

Governs the use and disclosure of PHI, and guarantees your right to access your own health records.

Security Rule

Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI).

Breach Notification Rule

Mandates timely notification to individuals, HHS, and the media following a breach of unsecured PHI.

Three layers of protection

The HIPAA Security Rule requires three categories of safeguards. CliniRec implements all three.

Technical Safeguards

AES-256 encryption at rest and TLS 1.2+ in transit, unique user authentication, automatic logoff, and audit controls on every PHI access event.

Administrative Safeguards

Designated security officer, workforce training, role-based access controls, contingency planning, and periodic risk assessments.

Physical Safeguards

Facility access controls, secure workstation placement, device and media disposal policies, and physical intrusion protection.

Breach Response Protocol

If your data is ever compromised, here's exactly what happens

Federal law (45 CFR §§ 164.400–414) sets strict timelines. We follow them — and hold ourselves accountable.

Within 1 business day

Discovery & Risk Assessment

Upon discovering a potential breach of unsecured Protected Health Information (PHI), our security team immediately confirms and scopes the incident. A four-factor risk assessment is conducted — the nature and extent of PHI involved, the unauthorized person who accessed it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. A breach is presumed unless the assessment demonstrates a low probability that PHI was compromised.

Within 1–5 business days

Containment & Investigation

We isolate affected systems, revoke compromised credentials, and mitigate ongoing harm. Every incident is logged in our internal Breach Incident Tracking System with its severity, affected record count, data types exposed, and containment actions — creating a defensible audit trail.

No later than 60 calendar days

Notify Affected Individuals

Per the HIPAA Breach Notification Rule (45 CFR § 164.404), written notice is sent to each affected individual by first-class mail within 60 calendar days of discovery. Each notice includes: a description of what happened, the types of information involved, steps individuals can take to protect themselves, what CliniRec is doing to investigate and mitigate, and contact procedures. If contact information for 10 or more individuals is out of date, substitute notice is posted on our website and through major media.

Within 60 days / Annually

Notify the U.S. Dept. of Health & Human Services

Breaches affecting 500 or more individuals are reported to the HHS Secretary immediately, and no later than 60 days after discovery, via the HHS Breach Portal. Breaches affecting fewer than 500 individuals are logged and submitted to HHS annually, within 60 days of the end of the calendar year (45 CFR § 164.408).

Without unreasonable delay

Media Notification

For breaches affecting more than 500 residents of a state or jurisdiction, notice is provided to prominent media outlets serving that area without unreasonable delay and no later than 60 calendar days after discovery (45 CFR § 164.406).

Ongoing

Remediation, Sanctions & Prevention

A documented corrective action plan is implemented. Workforce members involved in the breach are sanctioned per our policies. Security controls are updated to prevent recurrence, and all breach records are retained for a minimum of six years (45 CFR § 164.414).

India Compliance

Compliant with India's digital health & data protection laws

For users in India, CliniRec additionally complies with the Digital Personal Data Protection Act, 2023, the Ayushman Bharat Digital Mission (ABDM) framework, and the EHR Standards, 2016 issued by the Ministry of Health & Family Welfare.

DPDP Act, 2023

India's data protection law. Health data is personal data requiring explicit, verifiable consent, purpose limitation, data minimisation, and strong security safeguards. We act as a Data Fiduciary and honour all Data Principal rights.

ABDM & ABHA

Aligned with the Ayushman Bharat Digital Mission framework — supporting ABHA (Health ID) linked records and consent-managed health information exchange through the National Health Authority.

EHR Standards, 2016

Follows MoHFW standards for electronic health records, including interoperability, data ownership by the patient, privacy and security requirements, and record retention norms.

IT (SPDI) Rules, 2011

Implements reasonable security practices and procedures for sensitive personal data, including medical and health information, under the Information Technology Act, 2000.

Breach Response Protocol — under the DPDP Act

If your data is ever compromised in India, here's exactly what happens

Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025 set the duties of a Data Fiduciary. We follow them — and hold ourselves accountable.

Immediately

Discovery & Risk Assessment

Upon becoming aware of a personal data breach — any unauthorised access, collection, disclosure, alteration, or loss of personal data — our security team confirms and scopes the incident. We assess the nature and categories of data involved, the number of Data Principals affected, and the likelihood of significant harm, which determines our notification obligations.

Within 1–5 business days

Containment & Mitigation

We isolate affected systems, revoke compromised credentials, and mitigate ongoing harm. Every incident is logged in our Breach Incident Tracking System with its severity, affected record count, data types exposed, and containment actions — creating a defensible audit trail.

Without delay

Notify the Data Protection Board of India

Per Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025, CliniRec notifies the Data Protection Board of India (DPBI) without delay. The notice includes the facts of the breach, the measures taken to mitigate it, and the measures proposed to be taken in response.

If significant harm likely

Notify Affected Data Principals

Where the breach is likely to result in significant harm to affected individuals, we notify each affected Data Principal without delay. The notice describes the breach, the likely impact, the protective steps they can take, and our remediation efforts, and is sent through the contact details available with us.

If contact details insufficient

Public Notice

Where we do not have adequate contact details to reach affected Data Principals directly, or where the breach affects a large number of individuals, a public notice is published on our website and through appropriate public channels so affected individuals can take protective action.

Ongoing

Remediation, Grievance Redressal & Retention

A documented corrective action plan is implemented and security controls are updated to prevent recurrence. Data Principal grievances are addressed per the DPDP Act's grievance redressal mechanism, and all breach records are retained to demonstrate compliance with the DPDP Act, 2023 and the IT (Reasonable Security Practices) Rules, 2011.

Your rights — under HIPAA & the DPDP Act

We don't just meet the minimum — we make sure you know what you're entitled to, in the U.S. and in India.

Right to receive breach notification within 60 calendar days of discovery (HIPAA).

Right to be notified of a personal data breach by the Data Fiduciary (DPDP Act, India).

Right to access and obtain a copy of your health records in electronic form.

Right to request correction, updating, or erasure of your personal data (DPDP Act).

Right to request corrections to inaccurate or incomplete records (HIPAA).

Right to request restrictions on how your PHI is used or disclosed.

Right to an accounting of certain disclosures of your PHI.

Right to confidential communication about your health information.

Right to nominate another individual to exercise your rights in case of death/incapacity (DPDP Act).

Right to grievance redressal and a right to approach the Data Protection Board (DPDP Act).

Legal Notice

CliniRec is operated as a HIPAA-compliant health information platform. This policy is provided for informational purposes and summarizes our practices under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164, including the Privacy Rule, Security Rule, and Breach Notification Rule. In the event of any conflict between this summary and the governing federal regulations, the regulations control.

"Protected Health Information" (PHI) has the meaning given in 45 CFR § 160.103. "Breach" has the meaning given in 45 CFR § 164.402. Notification timelines referenced on this page are drawn from 45 CFR §§ 164.404 (individual notice), 164.406 (media notice), 164.408 (notice to the Secretary of HHS), and 164.414 (documentation retention, minimum 6 years).

For users in India, CliniRec additionally complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made thereunder, including the obligation under Section 8(6) to notify the Data Protection Board of India and affected Data Principals in the event of a personal data breach. We also align with the Ayushman Bharat Digital Mission (ABDM) framework and the Electronic Health Record (EHR) Standards, 2016 issued by the Ministry of Health & Family Welfare, and implement reasonable security practices under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. "Data Fiduciary", "Data Principal", and "personal data breach" have the meanings given in the DPDP Act, 2023.

CliniRec is not a covered entity's substitute for professional medical advice. For questions about this policy or to report a suspected privacy incident, contact our Privacy Officer via the Contact page.

© 2026 CliniRec · Your Personal Health Intelligence Platform

CliniRec is not a substitute for professional medical advice, diagnosis, or treatment.