Privacy by Design
This document describes how the platform's architecture protects patient data by design and by default, as required by Clause 26.3 of the National Digital Health Mission's Health Data Management Policy.
Federated storage — no central health-record database
Clinical records are created and stored at the facility where care was given, not in a central repository we control. When another facility needs a patient's record, it is retrieved through India's Health Information Exchange & Consent Manager (HIE-CM) under the patient's explicit, time-bound consent — not copied into a shared database.
Consent is purpose-bound and time-bound
Every data share carries a specific purpose, a defined health-information type, and an expiry (either a stated date or an automatic erasure instruction). Access outside the scope, window, or purpose a patient consented to is not possible through the consent artefact the exchange issues.
Revocation and expiry are hard deletions, not flags
When a patient revokes consent, or a consent expires, the underlying consent record and any data shared under it are permanently deleted from our systems — not marked inactive while remaining accessible. This is enforced in code and covered by automated tests that fail if the behaviour regresses to a soft delete.
Minimal identifiers, not central profiles
Beyond a patient's ABHA number/address, Healthcare Professional ID, and Health Facility ID — all issued by the National Health Authority, not by us — we do not build or maintain a separate central profile of a patient across facilities. Each facility's records remain that facility's records.
Encryption in transit and at rest
Health information exchanged with the ABDM gateway is encrypted end-to-end using the key-exchange scheme the exchange specifies before it ever leaves a facility's system. Data at rest is encrypted using industry-standard cryptographic modules.
A patient can decline ABDM entirely
Sharing an ABHA number or address is voluntary. A patient who does not wish to participate in the National Digital Health Ecosystem is still registered and treated normally — no service is conditioned on creating or disclosing an ABHA ID.
This is a Phase 1 stub published for ABDM sandbox review. © 2026 Unified Indian Healthcare.