Compliance
Clinith OS provides technical controls aligned with India's DPDP Act and US HIPAA-style requirements. Compliance is a shared responsibility between your clinic, the platform, and your vendors.
Clinics are typically the Data Fiduciary; Clinith OS acts as a Data Processor on their instructions. Use a Data Processing Agreement with each customer.
- Privacy notice + consent at booking and portal
- Configurable retention and automated anonymization cron
- Patient JSON export and erasure (with audit logging)
- HTTPS, bcrypt, tenant isolation, and RBAC
For US clinics handling PHI, you are typically a Business Associate. Execute a BAA with each customer and subprocessors that touch PHI.
- Access control, audit logs, and minimum necessary via RBAC
- Optional staff MFA (TOTP) and session idle timeout
- Encrypted integration secrets; TLS in transit
- Patient export supports access requests
Encryption & safeguards
| Layer | In Clinith OS |
|---|---|
| In transit | HTTPS; secure cookies in production |
| Passwords & OTPs | bcrypt hashed; OTPs not logged in production |
| Integration secrets | AES-256-GCM field encryption |
| Database PHI | Rely on Postgres/Supabase encryption at rest + network controls |
Important
Software alone is not “HIPAA certified” or “DPDP compliant.” Your legal, operational, and vendor contracts complete the program. This page is technical guidance, not legal advice.
