Security

Five independent layers. Every one must fail for a breach to succeed.

If the database were stolen tomorrow, the attacker gets encrypted blobs. Nothing readable. Nothing usable.

01

Perimeter

AWS WAF, DDoS protection, and TLS 1.3 stop malicious traffic before it reaches the application.

02

Identity

Role-based access, multi-factor authentication, and immutable audit logs on every action.

03

Network

Patient data services run in private VPC subnets — never exposed to the public internet.

04

Consent

An ABDM-compatible consent engine gates every share, under the DPDP Act 2023.

05

Storage

AES-256 encryption at rest, with keys rotated separately from the data they protect.

Standards we build against

StandardHow it applies
ABDMABHA-linked identity and record linkage, built in from the start rather than retrofitted.
HL7 FHIRRecords and diagnostic results exchanged in a standard interoperable format.
DPDP Act 2023Consent captured before processing, versioned, and withdrawable. See our Privacy Notice.
For hospital IT and diligence This page describes the architecture HealthOS is built to. It is not a certification claim: we hold no third-party security audit or ISO/SOC attestation at this stage, and we would rather tell you that directly than let it surface later. If your team needs a security questionnaire completed or wants to review the architecture in detail, get in touch and we will work through it.