Security & Privacy

Built With Healthcare Data in Mind

This page is a plain, honest account of what ClinicOS AI actually implements today — not a compliance brochure. We'll update it as more is built.

Tenant isolation

ClinicOS AI is a multi-clinic platform. Every clinic and organization's data — patients, doctors, appointments, billing, files and reports — is scoped at the data-access layer so that one organization cannot query or see another's records. This applies across the API, search, exports and reports, not just the visible screens.

Role-based access control

Access within a clinic is role-based. Front desk, doctors, nurses, HR, accountants and clinic admins each have a defined set of permissions, so a role only reaches the data and actions it actually needs.

Audit logging

Sensitive actions — record access, edits, logins, financial actions — are written to an audit trail with who performed the action, what it was, and when.

Secure by default

  • All traffic is served over HTTPS/TLS.
  • Every part of the system requires authentication — there is no public read access to clinic or patient data.
  • Passwords are never stored in plain text.

AI processing

Where AI is used (consultation drafting, front-desk assistance, WhatsApp message understanding), it processes the specific content needed to perform that task and always produces a draft — a human reviews and approves before anything becomes part of a permanent record or is sent to a patient.

What we do not claim

The items above are engineering practices we've built into the platform. They are not the same thing as a third-party certification or regulatory approval. We have not been audited for, and do not claim, any of the following:

HIPAA compliant ISO 27001 certified SOC 2 certified ABDM compliant Government approved
If your clinic requires a specific certification before onboarding, tell us — we'd rather say clearly what stage we're at than overstate it.

Questions

Call us at +91 93105 63590 with any security or privacy question — including a request to see how a specific workflow handles your data.