What personal data HealthCIP collects, why, who it is shared with, and how you exercise your rights under the Digital Personal Data Protection Act, 2023.
HealthCIP ("we", "us") is a hospital management system used by hospitals, clinics, and diagnostic centres ("the clinic") to manage their patients.
This creates two distinct roles, and it matters which one you are dealing with:
| Role | Who | What it means |
|---|---|---|
| Data Fiduciary | The clinic you visited or registered with | The clinic decides what data is collected and why, and is the party responsible to you for it. Your treating relationship, your records, and your care are the clinic's responsibility. |
| Data Processor | HealthCIP | We host and operate the software on the clinic's instructions. We process your data to run the system, and we do not use it for our own purposes. |
Because of this split, most requests about your medical records are answered by the clinic, not by us. Where a request concerns the platform itself — the software, its security, or data we hold as processor — we answer it. Section 11 explains how to raise either kind.
This notice covers the HealthCIP application and the patient portal. It also covers this marketing website, to the extent that it collects anything at all (see section 14).
We collect the following categories of personal data.
| Category | Examples | Collected when |
|---|---|---|
| Identity | Name, date of birth, age, sex, blood group, photograph, patient ID (HUID) | Registration, whether at the front desk or by you online |
| Contact | Mobile number, email address, postal address, emergency contact | Registration and appointment booking |
| Clinical | Symptoms, examination findings, diagnoses, prescriptions, treatment plans, lab and investigation reports, vitals, height and weight, allergies, medical history, uploaded documents and scans | During consultations, investigations, and lab reporting |
| Appointment and payment | Booked doctor, date and time, visit type, fees charged, payment status, receipt numbers, and the payment gateway's order and transaction references | When you book and pay |
| Account | Username, password (stored only as a one-way hash), account status, and, if you sign in with Google, the Google account identifier and verified email | When an account is created for you |
| Consent records | Which notice you accepted, its version, when, by which route (self, front desk, Google, portal), and the IP address it was recorded from | Every time you accept a notice |
What we do not collect: we do not store your card, UPI, or bank credentials. Online payments are handled entirely by the payment gateway (section 6), and we receive only the outcome — whether the payment succeeded, and its reference number.
| Purpose | What it involves |
|---|---|
| Providing your care | Maintaining your medical record so that the doctors treating you can see your history, order investigations, prescribe, and follow up. |
| Appointments and queueing | Booking, rescheduling and cancelling appointments, holding your place in the queue, and sending you booking confirmations and reminders. |
| Billing and receipts | Calculating fees, collecting payment, and issuing receipts. |
| Laboratory and diagnostic workflow | Recording tests ordered, tracking samples, entering results, and making reports available to you and your doctor. |
| AI-assisted features | Producing draft summaries, suggested investigations, and treatment-plan suggestions for a doctor to review. Described in full at section 5. |
| Security and integrity | Authenticating users, preventing unauthorised access and abusive use, keeping audit trails, and backing up data. |
| Support | Answering your or the clinic's queries about the system. |
| Legal compliance | Maintaining records for the periods medical law requires, and responding to lawful requests from courts and authorities. |
We do not sell your personal data, and we do not use it for advertising or behavioural profiling.
Your data is processed on the basis of your consent, given by you or recorded on your behalf when you register. The consent you gave is stored with the version of the notice you were shown, so it is always possible to establish exactly what you agreed to.
HealthCIP offers optional AI features: a summary of a patient's history, suggested investigations, an interpretation of lab results, treatment-plan suggestions, and matching a patient profile to a suitable doctor.
Three things are true of all of them, and we want them to be unambiguous:
| Recipient | What they receive | Why |
|---|---|---|
| Your clinic's staff | Your record, as far as their role allows | Doctors, nurses, lab technicians, pharmacy, and front desk each see the part of your record they need for their work. Access is role-based and audited. |
| Amazon Web Services | All data, as hosting provider | The database and uploaded files (reports, images, photographs) are stored on AWS infrastructure. Emails to you are sent through Amazon SES. |
| Razorpay | Name, contact details, and the amount payable | To process online payments. Razorpay handles your card and UPI details directly; we never see them. |
| Your email provider | Your email address, and the content of the notification | To deliver booking confirmations, reports, and password resets. |
| AI model providers | Clinical content, as described in section 5 | Only when a doctor uses an AI feature on your record. |
| Courts and authorities | As required by the order | Where disclosure is required by law. |
We do not share your data with anyone else, and we do not sell it. Where a clinic chooses to run additional integrations (for example an HL7 interface to a laboratory system), that clinic is responsible for telling you about it.
Data is stored on cloud infrastructure operated by Amazon Web Services, in the region the clinic's deployment is configured for. Our own operations are based in India.
Some processing involves transfer outside India — in particular the AI features in section 5, whose model providers operate infrastructure outside the country. Where a transfer happens, it takes place for the purpose you were told about, and subject to the restrictions the Central Government may impose under the Act.
Different records are kept for different periods, because medical records carry retention obligations that outlast the reason they were created.
| Record | Kept for |
|---|---|
| Medical records (consultations, prescriptions, reports) | For the period required by applicable medical records law and the clinic's own retention policy, which is longer than the period of your care. |
| Billing and payment records | As required by tax and accounting law. |
| Consent and audit records | Kept for as long as the record they relate to, so that it stays possible to establish what was agreed and who changed what. |
| Account and session data | Until the account is closed, and briefly afterwards for security purposes. |
| Email delivery records | A short operational period, for troubleshooting delivery. |
To be completed: the specific retention periods for each record type must be set with reference to the applicable medical records rules and the clinic's policy, and stated here as definite periods rather than by reference.
No system is perfectly secure. If a personal data breach occurs that affects you, we notify the Data Protection Board of India and you, as described at section 12.
Children are registered as patients by a parent, guardian, or clinic staff, and their records exist for the same clinical reasons as anyone else's. Where a child's data is processed, it is processed with the consent of a parent or lawful guardian, recorded in the same way as any other consent.
We do not track or behaviourally monitor children, and we do not direct advertising at them.
Under the Digital Personal Data Protection Act, 2023, you have the right to:
| Right | What it means here | How to exercise it |
|---|---|---|
| Access | A summary of the personal data held about you, what it is being used for, and who it has been shared with. | Raise it with your clinic's front desk or administrator, or submit a request from the patient portal. You may also write to the grievance officer at the address in section 15. We aim to respond within 30 days. |
| Correction | Correction of inaccurate or misleading data, and completion of incomplete data. | |
| Erasure | Deletion of data that is no longer necessary for the purpose it was collected for. Where medical records law requires retention, the clinic will tell you what it must keep and for how long, and erase the rest. | |
| Withdraw consent | Stop future processing, as described in section 4. | |
| Nominate | Nominate another person to exercise these rights on your behalf in the event of your death or incapacity. | Write to the grievance officer, who will record the nomination. |
| Grievance redressal | A route to complain, and to have the complaint answered. | Section 15. |
Access and correction requests can be raised directly from the patient portal. Every request is recorded, and requests to erase or correct clinical data are reviewed by the clinic before they are carried out — which is what allows the clinic to tell you when a retention obligation applies, instead of silently ignoring the request or silently destroying a record it was required to keep.
If a personal data breach occurs, we notify the Data Protection Board of India without delay, and we notify you where the breach affects you. Notification describes what happened, what data was affected, what we have done about it, and what you can do to protect yourself. The clinic is notified in parallel, since it is the fiduciary for your data.
Our internal procedure for detecting, containing, assessing, and notifying a breach is maintained separately and is available to the clinic on request.
We do not make decisions about you by automated means alone. The AI features described in section 5 produce drafts for a doctor, who decides. Booking, fee calculation, and queue ordering are automated, but they implement the clinic's own published rules rather than profiling you.
This marketing website is a set of static pages. It does not set advertising cookies, does not embed third-party trackers, and does not ask you for personal data. If you email us from a link on this site, we receive your email address and whatever you choose to write, and we use it only to answer you.
The HealthCIP application stores a small amount of information in your browser — your session credential and your display preferences — so that you stay signed in and the interface works. That storage is essential to the application; it is not used to track you across other sites, and it is cleared when you sign out.
If you have a question or complaint about how your personal data has been handled, contact our Grievance Officer:
| grievance@healthcip.in | |
| Response time | We acknowledge within 7 days and aim to resolve within 30 days. |
If you are not satisfied with our response, you may complain to the Data Protection Board of India under section 13 of the Act. You should approach the Board after raising the matter with us, and within the time limits the Act prescribes.
Remember that for anything concerning your medical records themselves — what is in them, who at the clinic can see them, or how long the clinic keeps them — the clinic is the party that answers, because it is the Data Fiduciary. We will help you reach them if you are not sure who to ask.
This notice is versioned. When the wording changes, the version number changes with it. The version you accepted is stored against your consent, so a later change never rewrites what you agreed to in the past. Where a change is significant, the clinic will ask you to accept the new version rather than treating your earlier acceptance as covering it.
General queries: support@healthcip.in
Data protection and privacy: grievance@healthcip.in
The terms on which HealthCIP is provided, for clinics, clinic staff, and patients.
HealthCIP ("we", "us") is a hospital management system. These terms govern your use of it.
They apply to three different kinds of user, and the sections that matter differ:
| You are | Sections that matter most |
|---|---|
| A clinic subscribing to HealthCIP | All of them, and in particular 4, 6, 9, 10, 11, 13 |
| Clinic staff using an account | 2, 3, 5, 7, 8 |
| A patient using the patient portal | 2, 3, 5, 7, 8 |
By creating an organization, using an account, or booking through the patient portal, you accept these terms. If you accept them on behalf of a clinic, you confirm you are authorised to bind that clinic.
The patient portal lets a patient register with a clinic, book and cancel appointments, pay fees, view reports, and raise requests about their own data. When you register:
This section is what makes the rest work, so it is stated plainly. The clinic decides what patient data enters the system and why. That makes the clinic the Data Fiduciary for that data under the Digital Personal Data Protection Act, 2023, and us only the Data Processor. The clinic is therefore responsible for:
You must not:
We may suspend an account immediately where we reasonably believe it is being used in a way that threatens the security or integrity of patient data.
HealthCIP includes AI features that generate drafts — history summaries, suggested investigations, lab interpretations, treatment-plan suggestions, and doctor matching. Four points govern their use:
We may change which models are used, or which provider they come from, as part of operating the service. Availability of any particular feature is not guaranteed.
Subscription fees, and the terms on which they are charged, are set out in your order or plan. Consultation and treatment fees are set by the clinic, not by us; where a patient pays online, the payment is processed by our payment gateway partner and settles to the clinic, and any refund is a matter between the patient and the clinic.
Where a patient books and does not pay, the appointment may be held unpaid and settled at the clinic's counter, where the clinic has enabled that option.
We maintain technical and organisational measures to protect personal data, described in section 9 of the Privacy Notice, and we notify breaches as described in section 12 of it. The clinic must do its part: manage its users, keep credentials confidential, and tell us promptly about anything that looks like a compromise.
Except as expressly agreed in writing, the service is provided on an "as is" basis. We do not warrant that the service will be error-free, that AI outputs will be accurate or fit for any clinical purpose, or that the service will meet any particular clinical or regulatory requirement beyond what we have expressly agreed. Clinical judgement, diagnosis, and treatment remain the responsibility of the treating clinician.
To the extent permitted by law, neither party is liable for indirect or consequential loss, loss of profit, or loss of goodwill. Our total liability arising out of or in connection with these terms shall not exceed INR 25,000.
HealthCIP acts solely as a technology platform and is not a healthcare provider. HealthCIP does not provide medical advice, diagnosis, or treatment and is not responsible for the medical services provided by clinics, hospitals, doctors, or other healthcare professionals using the platform.
Nothing in these terms limits liability that cannot lawfully be limited, including liability under the Digital Personal Data Protection Act, 2023.
These terms are governed by the laws of India. Subject to any applicable dispute resolution procedure, the courts at Ernakulam, Kerala shall have exclusive jurisdiction over any dispute arising out of or in connection with these terms.
These terms are versioned. When they change materially, the version number changes, and the clinic will be asked to accept the new version before continuing to use the service. The version a user accepted is recorded, so a later change never rewrites what was agreed in the past.
General and commercial: sales@healthcip.in
Support: support@healthcip.in
Data protection and privacy: grievance@healthcip.in
The consent a clinic asks for before examining, investigating, or treating you, and the terms on which it is given.
I consent to examination, investigation and treatment, and to my clinical records being kept for the purpose of my care.
Agreeing to this allows the clinic to examine you, to investigate your condition as the clinician considers necessary, to treat you, and to keep a record of your care. It is the consent a hospital has always asked for, written down.
It is not consent to anything beyond your care. In particular it is not consent to your data being used for research, for marketing, or for any purpose the Privacy Notice does not describe. Procedures that carry their own specific risks need their own consent, taken separately by the clinician who performs them.
You may refuse examination, investigation, or treatment, and you may withdraw this consent at any time. Refusing does not affect the care you have already received. Withdrawal is as easy as giving consent — write to the grievance officer (Privacy Notice section 15) or tell your clinic.
Withdrawing stops future treatment under this consent. It does not by itself delete records the clinic is required by law to keep. Where a record is needed to keep treating you safely, the clinic will explain what it must retain and why before acting on a withdrawal.
Where you cannot consent and treatment cannot wait, the law allows a clinician to treat you without it. The clinic will record what was done and why, and tell you or your nominated contact as soon as it can.