Phase 1 · Pre-launch

Personal Data Breach Procedure

This page describes how we detect, contain, and report a personal data breach, as required by Clause 33 of the National Digital Health Mission's Health Data Management Policy and the Information Technology (CERT-In) Rules, 2013.

What counts as a breach

Any unauthorised access to, disclosure of, alteration of, or loss of personal or health data we process — whether caused by an external attack, an internal error, or a third-party failure — is treated as a personal data breach under this procedure.

How to report a suspected breach

Anyone — a patient, a healthcare provider, a staff member, or a third party — who suspects a breach should contact us immediately at info@uihr.in. Please include what you observed, when, and any identifying details you can safely share. We do not restrict the channel through which a report can be made.

Our internal response

On receiving a report or detecting a suspected breach ourselves, we: (1) log the incident immediately with a timestamp and initial description, (2) take containment steps to stop ongoing exposure, (3) assess scope — what data, how many individuals, what risk — and (4) determine notification obligations based on that assessment. Every reported breach is recorded, whether or not it is ultimately confirmed.

Statutory notification duties

Where a breach meets the reporting thresholds under the Information Technology (CERT-In) Rules, 2013, we notify the Indian Computer Emergency Response Team (CERT-In) within the timeframe those rules require. Where the breach involves data received through the ABDM exchange, we also notify the National Health Authority per the Health Data Management Policy's own reporting duty.

Notifying affected individuals

Where a breach creates a real risk to an affected individual, we notify them directly using the contact details on file, describing what happened, what data was involved, and what steps we are taking — without unreasonable delay once the assessment in the previous section is complete.

Grievance and Data Protection Officer contacts

For questions about this procedure, or to raise a data-protection grievance, contact our Grievance Officer or Data Protection Officer. Per the Health Data Management Policy, a grievance is acknowledged and resolved within one month.

Grievance Officer and DPO contact details are being finalised and will be published here before the platform goes live.

This is a Phase 1 stub published for ABDM sandbox review. © 2026 Unified Indian Healthcare.