Compliance

Clinith OS provides technical controls aligned with India's DPDP Act and US HIPAA-style requirements. Compliance is a shared responsibility between your clinic, the platform, and your vendors.

India DPDP (2023)

Clinics are typically the Data Fiduciary; Clinith OS acts as a Data Processor on their instructions. Use a Data Processing Agreement with each customer.

  • Privacy notice + consent at booking and portal
  • Configurable retention and automated anonymization cron
  • Patient JSON export and erasure (with audit logging)
  • HTTPS, bcrypt, tenant isolation, and RBAC
US HIPAA

For US clinics handling PHI, you are typically a Business Associate. Execute a BAA with each customer and subprocessors that touch PHI.

  • Access control, audit logs, and minimum necessary via RBAC
  • Optional staff MFA (TOTP) and session idle timeout
  • Encrypted integration secrets; TLS in transit
  • Patient export supports access requests

Encryption & safeguards

LayerIn Clinith OS
In transitHTTPS; secure cookies in production
Passwords & OTPsbcrypt hashed; OTPs not logged in production
Integration secretsAES-256-GCM field encryption
Database PHIRely on Postgres/Supabase encryption at rest + network controls

Important

Software alone is not “HIPAA certified” or “DPDP compliant.” Your legal, operational, and vendor contracts complete the program. This page is technical guidance, not legal advice.

Security overview →

Need a security questionnaire?

Email security@clinithos.com for architecture details and subprocessors.