Security Policy
Protecting sensitive healthcare data is at the core of AiHospitalERP. This policy outlines the technical and organizational measures we use to keep your data safe.
Table of Contents
1. Our Commitment
AiHospitalERP handles some of the most sensitive information that exists: patient health records. We treat security as a foundational responsibility and apply defense-in-depth practices across our people, processes, and technology.
2. Data Encryption
- All data in transit is protected using TLS 1.2 or higher (HTTPS).
- Passwords are securely hashed and never stored in plain text.
3. Access Control
- Role-based access control (RBAC) ensures users only see the data they are authorized to access.
- Strict tenant isolation keeps each hospital's data logically separated.
- Passwords are hashed, and multi-factor authentication is supported for privileged accounts.
- Internal access to production systems follows the principle of least privilege.
4. Infrastructure Security
- Our platform is hosted on reputable cloud providers with certified, physically secure data centers.
- Firewalls, network segmentation, and security groups restrict unauthorized traffic.
- Automated backups are performed regularly and stored securely to support disaster recovery.
- Systems are patched and updated to address known vulnerabilities.
5. Compliance
We align our practices with applicable Indian data protection regulations (IT Act, 2000 and its rules) and follow industry best practices to safeguard healthcare data.
6. Monitoring & Auditing
- Systems are continuously monitored for suspicious activity and anomalies.
- Audit logs record access to sensitive data for accountability and traceability.
- We conduct regular internal security reviews.
7. Incident Response
We maintain an incident response plan to detect, contain, and remediate security events. In the event of a data breach affecting your data, we will notify affected clients promptly and in accordance with applicable law.
8. Reporting a Vulnerability
We welcome responsible disclosure from the security community. If you believe you have found a security vulnerability, please report it to us privately so we can investigate and address it.
Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to resolve it. Email details to aihospitalerp@gmail.com.
9. Contact Us
For security-related questions or to request our security documentation, contact us:
- Email: aihospitalerp@gmail.com
- Phone: +91 9168 08 1355
- Address: Pune, Maharashtra, India
The content on this page is provided for general informational purposes only and does not constitute legal advice. AiHospitalERP makes no representations or warranties regarding the completeness, accuracy, or applicability of this information to your specific circumstances. Please consult a qualified legal professional before making decisions based on this policy.