Data Trust Architecture

Built for Trust.
Engineered for Security.

How Cliniqwise protects patient privacy and ensures 100% compliance with India's Digital Personal Data Protection (DPDP) Act 2023.

DPDP Act 2023 Compliant
ISO 27001 Certified
ABDM M1-M4 Aligned
HIPAA Ready

India DPDP Act 2023 Compliance for Healthcare Organizations

The notification of the Digital Personal Data Protection (DPDP) Act, 2023 has introduced fundamental changes to healthcare data storage and management in India. Hospitals, clinics, diagnostic centers, and pharmaceutical fiduciaries must implement strict compliance measures. Patient records, diagnostics, billing summaries, and treatment histories represent highly sensitive personal details that require comprehensive technical protections.

Under the DPDPA 2023, legacy bundled consent forms (where clinical consent, insurance sharing, and promotional messages are signed with a single checkmark) are legally invalid under Section 6. Consent must be free, specific, informed, unconditional, and unambiguous, preceded by a prior compliance notice. Crucially, Section 6(4) mandates that withdrawing consent must be as simple as giving it, requiring modern hospital management software to implement granular, purpose-level consent registries.

Additionally, Section 9(1) imposes strict regulations on pediatric personal data, requiring verifiable parental or guardian consent before processing any data for minors under 18. Cliniqwise HMS addresses this directly by implementing patient age gating and automated guardian consent collection pathways.


Data Erasure vs. Statutory Retention

Section 12(3) grants patients the right to erasure of their clinical records. However, this must be balanced with the Clinical Establishments Act and Consumer Protection Act mandates requiring hospitals to retain medical histories for 3 to 5 years. Cliniqwise resolves this conflict by putting a temporary statutory hold on erasure requests, logging the legal justification, and deleting the data automatically once the retention period ends.

Significant Data Fiduciary (SDF) Mandates

Large private hospital chains and health-tech platforms processing high volumes of patient details may be designated as Significant Data Fiduciaries (SDFs). This requires board-level accountability with a Data Protection Officer (DPO) reporting directly to the directors, conducting periodic Data Protection Impact Assessments (DPIAs), and performing external audits.

Data Sovereignty

Hosted exclusively on Tier-4 Microsoft Azure & AWS regions in Mumbai and Hyderabad. No clinical data leaves Indian soil, strictly conforming to national data residency laws.

Cryptographic Protection

AES-256 bit encryption at rest and TLS 1.3 in transit. Integrates with Hardware Security Modules (HSMs) for advanced cryptographic key rotation and lifecycle security.

Access Governance

Granular Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) to restrict medical records to authorized healthcare professionals based on least-privilege principles.

FHIR R4 Interoperability

Standardized HL7 FHIR R4 JSON schema configurations to facilitate secure, encrypted, and consent-based health data transfers across the national ABDM gateway.

DPDP Data Custodianship & Rights

100% Clinical Data Ownership

Your healthcare facility owns every patient record. Cliniqwise acts strictly as a Data Processor under a board-governed SaaS agreement.

Verifiable Consent Architecture

Replaces bundled admission forms with purpose-segregated notices (clinical, insurance, research) in regional languages, satisfying Section 6 mandates.

Right to Erasure & Correction

Built-in workflows to process erasure requests under Section 12(3), balanced with statutory medical record retention obligations (Clinical Establishments Act).

Hosted in Mumbai

Redundant Failover to
Hyderabad Data Centers.

99.9%

Uptime

0%

Data Loss

DPDP Security Safeguards & Audit Trails

Section 8 of the DPDPA mandates reasonable security safeguards to prevent personal data breaches.

Permanent Tamper-Proof Audit Logs

Logs every record read/write operation with attending professional ID, system IP, and cryptographically verified timestamp.

Pediatric Verification Branching

Detects minors under 18 during registration and routes the workflow to collect verifiable parental or guardian consent under Section 9(1).

Secure Tokenization Manager

Tokenizes sensitive identifiers (Aadhaar, mobile numbers) for research, clinical trial analytics, and third-party laboratory exchanges.

Trust & Compliance FAQs

Security isn't a feature.
It's our foundation.

Need a deep dive into our VAPT results and infrastructure audit? Request our Cloud Security Manifesto.

Support Online Now

Live Consultation

Have questions about ABDM, billing, or features? Talk to our health-tech experts instantly.