Skip to main content
Back to Home
Statutory Compliance · DPDPA 2023 & HIPAA Standard

MediVault Privacy Policy

Effective Date: August 29, 2026 · Version 3.2 (Production Release)

Our Sovereign Privacy Commitment in 30 Seconds
  • Zero Ad Selling: We never sell, monetize, or broker your personal or health data to advertisers, pharmaceutical companies, or life insurers.
  • Client-Side Encryption: Documents are encrypted in your browser using AES-256 GCM before cloud transmission. MediVault operators cannot read your clinical records.
  • Indian Data Residency: All primary databases and encrypted object stores reside strictly within Indian borders (AWS Mumbai `ap-south-1`) in compliance with the DPDPA 2023.
  • Time-Bound Doctor Consent: Doctors access your vault only via explicit, revocable time tokens (15m, 1h, 30d).

1. Introduction & Regulatory Framework

MediVault Chain AI Inc. ("MediVault", "we", "our", or "us") operates the MediVault decentralized healthcare platform, Personal Health Record (PHR) health locker, and Clinical AI Assistant. This Privacy Policy governs our collection, storage, encryption, processing, and disclosure of data across our patient portal, doctor workstation, and administrative interfaces.

MediVault strictly complies with the following statutory regimes:

  • Digital Personal Data Protection Act (DPDPA), 2023: Act No. 22 of 2023 (Government of India).
  • Ayushman Bharat Digital Mission (ABDM): Health Data Management Policy issued by the National Health Authority (NHA).
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).
  • Indian Computer Emergency Response Team (CERT-In) Cyber Security Directions of April 2022.
  • Health Insurance Portability and Accountability Act of 1996 (HIPAA): 45 CFR Part 160 and Part 164 (Security and Privacy Rules for global interoperability).

2. Categories of Information We Collect

Depending on which features you activate, we process the following categories of data:

A. Identity & Government ID Data

Full name, mobile number, date of birth, gender, state, 14-digit Ayushman Bharat Health Account (ABHA) number, `@abdm` virtual health handle, and masked Aadhaar reference numbers. Biometric data (fingerprint or face) is processed exclusively locally by your device's Secure Enclave for FIDO2 WebAuthn and is never transmitted to our servers.

B. Protected Health Information (PHI)

Medical prescriptions, laboratory panels (blood, metabolic, lipid), diagnostic imaging scans, discharge summaries, vaccination records (CoWIN), health insurance policies (PM-JAY), and Emergency Trauma data (blood type, critical drug allergies, chronic conditions, ICE contacts).

C. Cryptographic & Blockchain Proofs

SHA-256 cryptographic hashes of uploaded documents, Polygon Amoy blockchain transaction hashes (`txHash`), block numbers, and consent state verification tokens.

D. Regulatory Telemetry & Access Logs

IP addresses, timestamps, user-agent headers, and consultation access event IDs. Maintained in immutable audit logs for 180 days in compliance with CERT-In directions.

3. Purpose Limitation & Lawful Grounds for Processing

Under Section 4 and Section 6 of the DPDPA 2023, MediVault processes personal and health data only on the lawful grounds of **explicit, informed consent** for specified clinical purposes:

  • Vault Custody & Retrieval: Storing, organizing, and rendering your clinical records in an encrypted digital repository.
  • Government ABDM Synchronization: Communicating with the National Health Authority gateway to link your ABHA ID and DigiLocker certificates upon your explicit authorization.
  • AI Clinical Extraction: Running automated Optical Character Recognition (OCR) and biomarker analysis (via Google Gemini 2.5 Flash Cloud) to transcribe handwriting and alert on drug-drug interactions.
  • Emergency First-Responder Access: Presenting non-sensitive emergency trauma information (blood group, anaphylactic allergies, and emergency phone numbers) when an emergency pass QR is scanned.
  • Legal & Regulatory Compliance: Fulfilling incident reporting and forensic logging requirements under CERT-In and Indian law.

4. Technical Safeguards & Zero-Knowledge Cryptography

MediVault is engineered with zero-trust architectural boundaries to prevent unauthorized inspection:

Client-Side Encryption Standard:

All clinical files are encrypted in the user's browser using AES-256-GCM before payload transmission. Decryption keys are derived directly from the patient's authenticated hardware passkey (WebAuthn) and are never stored on MediVault backend servers.

Transit Security:

All API endpoints mandate TLS 1.3 encryption with HTTP Strict Transport Security (HSTS) and binary magic-byte inspection to prevent spoofing.

5. Third-Party Sub-Processors & Data Sharing

We share data only with verified sub-processors necessary to operate the platform under strict Business Associate Agreements (BAAs) and Data Processing Addendums (DPAs):

Sub-ProcessorPurposeData TransferredLocation
Amazon Web Services (AWS)Encrypted Cloud Storage & DatabaseAES-256 Encrypted BlobsMumbai (`ap-south-1`), India
National Health Authority (NHA)ABHA & ABDM Gateway VerificationAadhaar verification tokens, ABHA IDNew Delhi, India
DigiLocker / MeriPehchanGovernment Certificate SynchronizationPM-JAY & CoWIN Document URIsMeitY, India
Google Gemini AI CloudMultimodal Clinical OCR & Lab ParsingPrescription image for transient inferenceEnterprise Zero-Retention API
Polygon Amoy NetworkDecentralized Document Hash NotarizationOne-way SHA-256 Hash (No raw PHI)Public Distributed Ledger

6. Rights of Data Principals (Patients)

Under Chapter III of the DPDPA 2023 and HIPAA, you hold complete sovereignty over your health data:

✓ Right to Access & PortabilityYou can review all stored records and download a complete, unencrypted FHIR R4 XML/JSON export at any time.
✓ Right to Correction & UpdatingYou may edit or update incomplete medical tags, emergency contacts, or allergy records.
✓ Right to Erasure ("Right to be Forgotten")You may trigger irreversible cryptographic deletion of your medical vault. All files and database pointers will be purged.
✓ Right to Revoke Consent InstantlyYou can terminate active doctor consultation sessions with a single click, immediately invalidating access tokens.

7. Data Protection Officer (DPO) & Grievance Redressal

In compliance with Section 10 of the DPDPA 2023, MediVault has designated a formal Data Protection Officer to oversee healthcare privacy compliance and address user inquiries:

MediVault Data Protection & Privacy Office
Designation: Data Protection Officer (DPO) & Grievance Officer
Entity: MediVault Chain AI Inc.
Official Grievance Email: privacy@medivault.app / dpo@medivault.app
Response Statutory Window: Formal acknowledgment within 48 hours; full resolution within 30 days.
Jurisdiction: Mumbai, Maharashtra, India.