01
Perimeter
AWS WAF, DDoS protection, and TLS 1.3 stop malicious traffic before it reaches the application.
02
Identity
Role-based access, multi-factor authentication, and immutable audit logs on every action.
03
Network
Patient data services run in private VPC subnets — never exposed to the public internet.
04
Consent
An ABDM-compatible consent engine gates every share, under the DPDP Act 2023.
05
Storage
AES-256 encryption at rest, with keys rotated separately from the data they protect.
Standards we build against
| Standard | How it applies |
|---|---|
| ABDM | ABHA-linked identity and record linkage, built in from the start rather than retrofitted. |
| HL7 FHIR | Records and diagnostic results exchanged in a standard interoperable format. |
| DPDP Act 2023 | Consent captured before processing, versioned, and withdrawable. See our Privacy Notice. |
For hospital IT and diligence
This page describes the architecture HealthOS is built to. It is not a certification claim:
we hold no third-party security audit or ISO/SOC attestation at this stage, and we would
rather tell you that directly than let it surface later. If your team needs a security
questionnaire completed or wants to review the architecture in detail,
get in touch and we will work through it.