Security

Patient data, protected by design.

Health records are among the most sensitive data a clinic holds. DeskMed is built so every clinic’s data stays encrypted, isolated, and in India — with security baked into the architecture, not bolted on.

Encryption
AES-256
Data residency
India only
Uptime SLA
99.9%
Compliance
DPDP-aligned

How we protect you

Security at every layer

From the database to the browser, here’s what keeps your clinic’s data safe.

Encryption everywhere

Traffic is protected with TLS 1.3 in transit and AES-256 at rest. Backups and file attachments — lab reports, scans, documents — are encrypted with the same standard.

Tenant isolation

Every clinic is a separate organization, and every record is scoped to it at the query layer. One clinic can never read or write another clinic's data — it's enforced on every request, not just the UI.

Role-based access

Admins, doctors, receptionists, and lab technicians each see only what their role needs. Least-privilege access keeps prescriptions, billing, and reports in the right hands.

Audited & accountable

Every change to a patient or appointment writes an immutable audit log — who did what, and when. If a record is touched, there's a trail.

Secure authentication

Passwords are hashed with bcrypt and never stored in plain text. Sessions use short-lived access tokens with rotating refresh tokens, so a leaked token expires fast.

Backups & recovery

Encrypted backups run automatically every day with point-in-time recovery. We test restores regularly, so your records are recoverable — not just backed up.

Compliance & residency

Built for Indian healthcare rules

Your data is hosted in India and handled to the standards regulators and patients expect.

DPDP Act 2023

Aligned

Built to India's Digital Personal Data Protection Act for consent, access, and erasure.

ISO 27001

In progress

Information-security management certification, currently underway.

SOC 2 Type II

On roadmap

Independent audit of our security and availability controls.

HIPAA-aligned

Practices

We follow HIPAA-style safeguards for handling protected health information.

Hosted in India

Data residency

All clinic and patient data is stored and processed on AWS infrastructure in the Mumbai region (ap-south-1). Your records never leave the country.

Found a vulnerability?

We welcome responsible disclosure from security researchers. Report an issue and we’ll acknowledge it within two business days.

security@deskmed.in