CliniRec is built to comply with both U.S. federal health-privacy law — the HIPAA Privacy, Security, and Breach Notification Rules (45 CFR Parts 160 & 164) — and India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Ayushman Bharat Digital Mission (ABDM) framework, and the EHR Standards, 2016. This page explains, in plain language, the rules we follow and the exact steps we take to notify and protect you in the event of a data breach.
Governs the use and disclosure of PHI, and guarantees your right to access your own health records.
Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI).
Mandates timely notification to individuals, HHS, and the media following a breach of unsecured PHI.
The HIPAA Security Rule requires three categories of safeguards. CliniRec implements all three.
AES-256 encryption at rest and TLS 1.2+ in transit, unique user authentication, automatic logoff, and audit controls on every PHI access event.
Designated security officer, workforce training, role-based access controls, contingency planning, and periodic risk assessments.
Facility access controls, secure workstation placement, device and media disposal policies, and physical intrusion protection.
Federal law (45 CFR §§ 164.400–414) sets strict timelines. We follow them — and hold ourselves accountable.
Upon discovering a potential breach of unsecured Protected Health Information (PHI), our security team immediately confirms and scopes the incident. A four-factor risk assessment is conducted — the nature and extent of PHI involved, the unauthorized person who accessed it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. A breach is presumed unless the assessment demonstrates a low probability that PHI was compromised.
We isolate affected systems, revoke compromised credentials, and mitigate ongoing harm. Every incident is logged in our internal Breach Incident Tracking System with its severity, affected record count, data types exposed, and containment actions — creating a defensible audit trail.
Per the HIPAA Breach Notification Rule (45 CFR § 164.404), written notice is sent to each affected individual by first-class mail within 60 calendar days of discovery. Each notice includes: a description of what happened, the types of information involved, steps individuals can take to protect themselves, what CliniRec is doing to investigate and mitigate, and contact procedures. If contact information for 10 or more individuals is out of date, substitute notice is posted on our website and through major media.
Breaches affecting 500 or more individuals are reported to the HHS Secretary immediately, and no later than 60 days after discovery, via the HHS Breach Portal. Breaches affecting fewer than 500 individuals are logged and submitted to HHS annually, within 60 days of the end of the calendar year (45 CFR § 164.408).
For breaches affecting more than 500 residents of a state or jurisdiction, notice is provided to prominent media outlets serving that area without unreasonable delay and no later than 60 calendar days after discovery (45 CFR § 164.406).
A documented corrective action plan is implemented. Workforce members involved in the breach are sanctioned per our policies. Security controls are updated to prevent recurrence, and all breach records are retained for a minimum of six years (45 CFR § 164.414).
For users in India, CliniRec additionally complies with the Digital Personal Data Protection Act, 2023, the Ayushman Bharat Digital Mission (ABDM) framework, and the EHR Standards, 2016 issued by the Ministry of Health & Family Welfare.
India's data protection law. Health data is personal data requiring explicit, verifiable consent, purpose limitation, data minimisation, and strong security safeguards. We act as a Data Fiduciary and honour all Data Principal rights.
Aligned with the Ayushman Bharat Digital Mission framework — supporting ABHA (Health ID) linked records and consent-managed health information exchange through the National Health Authority.
Follows MoHFW standards for electronic health records, including interoperability, data ownership by the patient, privacy and security requirements, and record retention norms.
Implements reasonable security practices and procedures for sensitive personal data, including medical and health information, under the Information Technology Act, 2000.
Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025 set the duties of a Data Fiduciary. We follow them — and hold ourselves accountable.
Upon becoming aware of a personal data breach — any unauthorised access, collection, disclosure, alteration, or loss of personal data — our security team confirms and scopes the incident. We assess the nature and categories of data involved, the number of Data Principals affected, and the likelihood of significant harm, which determines our notification obligations.
We isolate affected systems, revoke compromised credentials, and mitigate ongoing harm. Every incident is logged in our Breach Incident Tracking System with its severity, affected record count, data types exposed, and containment actions — creating a defensible audit trail.
Per Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025, CliniRec notifies the Data Protection Board of India (DPBI) without delay. The notice includes the facts of the breach, the measures taken to mitigate it, and the measures proposed to be taken in response.
Where the breach is likely to result in significant harm to affected individuals, we notify each affected Data Principal without delay. The notice describes the breach, the likely impact, the protective steps they can take, and our remediation efforts, and is sent through the contact details available with us.
Where we do not have adequate contact details to reach affected Data Principals directly, or where the breach affects a large number of individuals, a public notice is published on our website and through appropriate public channels so affected individuals can take protective action.
A documented corrective action plan is implemented and security controls are updated to prevent recurrence. Data Principal grievances are addressed per the DPDP Act's grievance redressal mechanism, and all breach records are retained to demonstrate compliance with the DPDP Act, 2023 and the IT (Reasonable Security Practices) Rules, 2011.
We don't just meet the minimum — we make sure you know what you're entitled to, in the U.S. and in India.
Right to receive breach notification within 60 calendar days of discovery (HIPAA).
Right to be notified of a personal data breach by the Data Fiduciary (DPDP Act, India).
Right to access and obtain a copy of your health records in electronic form.
Right to request correction, updating, or erasure of your personal data (DPDP Act).
Right to request corrections to inaccurate or incomplete records (HIPAA).
Right to request restrictions on how your PHI is used or disclosed.
Right to an accounting of certain disclosures of your PHI.
Right to confidential communication about your health information.
Right to nominate another individual to exercise your rights in case of death/incapacity (DPDP Act).
Right to grievance redressal and a right to approach the Data Protection Board (DPDP Act).
Legal Notice
CliniRec is operated as a HIPAA-compliant health information platform. This policy is provided for informational purposes and summarizes our practices under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164, including the Privacy Rule, Security Rule, and Breach Notification Rule. In the event of any conflict between this summary and the governing federal regulations, the regulations control.
"Protected Health Information" (PHI) has the meaning given in 45 CFR § 160.103. "Breach" has the meaning given in 45 CFR § 164.402. Notification timelines referenced on this page are drawn from 45 CFR §§ 164.404 (individual notice), 164.406 (media notice), 164.408 (notice to the Secretary of HHS), and 164.414 (documentation retention, minimum 6 years).
For users in India, CliniRec additionally complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made thereunder, including the obligation under Section 8(6) to notify the Data Protection Board of India and affected Data Principals in the event of a personal data breach. We also align with the Ayushman Bharat Digital Mission (ABDM) framework and the Electronic Health Record (EHR) Standards, 2016 issued by the Ministry of Health & Family Welfare, and implement reasonable security practices under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. "Data Fiduciary", "Data Principal", and "personal data breach" have the meanings given in the DPDP Act, 2023.
CliniRec is not a covered entity's substitute for professional medical advice. For questions about this policy or to report a suspected privacy incident, contact our Privacy Officer via the Contact page.