Security at Medigent
Medigent handles sensitive health information, and we build for that from the ground up. This page summarises how we protect your data; it complements our Privacy Policy.
Infrastructure
Medigent runs on Amazon Web Services on ISO 27001 / SOC 2 certified infrastructure in India (AWS Asia Pacific — Mumbai). Data is encrypted in transit (TLS) and at rest, on hardened, regularly patched services.
Access and isolation
Access to data follows least-privilege principles and is restricted and logged. Each clinic’s data is isolated, and patient records are separated per patient. Administrative access requires multi-factor authentication.
Health data and HIPAA
Health data is handled to HIPAA safeguards under a Business Associate Addendum with our cloud provider where applicable. Medical records are portable and exportable in the open FHIR R4 standard, so your data is never locked in.
Compliance
- Digital Personal Data Protection Act, 2023 (DPDP Act)
- Information Technology Act, 2000 and the SPDI Rules, 2011
- ABDM / MoHFW health-data standards — ABHA identity and consent-based sharing. See what ABDM ready actually means.
- SNOMED CT Affiliate Licence 1743442 — the clinical terminology ABDM requires, licensed in our own name.
- Startup India recognised — DPIIT certificate DIPP271740.
Payments
Payments are processed by PCI-DSS-compliant partners (PayU, Stripe). Medigent never stores your full card or UPI details.
Reliability and backups
We monitor the platform continuously and take regular encrypted backups so data can be restored if something goes wrong.
Reporting a vulnerability
If you believe you have found a security issue, email security@medigent.in. We welcome responsible disclosure and will work with you to verify and fix valid reports. Please do not access or change data that is not yours.