Compliance built for institutional healthcare, not bolted on after the fact
Med-X India is built on the same security foundation as every Med-X property, maintained at Med-X Global Corporation level, plus data handling designed specifically around India's regulatory landscape.
Certifications & audited controls
HIPAA Compliant
Administrative, physical, and technical safeguards for protected health information, consistent with HIPAA's Privacy and Security Rules.
GDPR Compliant
Data handling reviewed against GDPR's lawful-basis, minimization, and data-subject-rights requirements, backed by an independent GDPR audit at the parent-company level.
SOC 2 Type II
SOC 2 Type II report covering security, availability, and confidentiality controls, maintained at the parent-company level and available to institutional partners under NDA.
ISO 27001 Aligned
Information security management practices aligned to ISO/IEC 27001, covering access control, encryption, and incident response.
DLP for Phone Communications
Redaction and access controls on the tele-consultation and pharmacy-audit voice channels the platform processes — call recordings and transcripts are access-controlled, retention-limited, and not used outside the agreed audit purpose.
Alignment with India's digital health regulation
These frameworks aren't third-party certifications the way ISO 27001 or SOC 2 are — India's digital-health governance is still taking shape. We track each of these and design our data handling to align with them as they mature.
DPDP
DPDP Act, 2023
India's Digital Personal Data Protection Act governs consent, purpose limitation, and security for personal data processing. Med-X's data handling is designed around its consent and minimization requirements.
ABDM
Ayushman Bharat Digital Mission
India's national digital health interoperability initiative. Med-Sync is built to participate in ABDM's consent-based health data exchange rather than create another data silo.
NABH
NABH Information Management Standards
NABH accreditation embeds patient-record access control, confidentiality, and retention requirements across its Information Management System chapter. Med-Sync's access controls and audit logging are built to support NABH-accredited facilities.
SAHI / BODH
Safe & Responsible AI for Healthcare / Benchmarking & Validation
Emerging Indian guidance on safe, explainable healthcare AI (SAHI) and on benchmarking and validating health AI systems before deployment (BODH). Med-X tracks both as they take shape.
Need our SOC 2 report or DPA for procurement?
Institutional partners can request our SOC 2 Type II report, Data Processing Agreement, and security questionnaire responses under NDA.