Med-XIndia
Compliance & security

Compliance built for institutional healthcare, not bolted on after the fact

Med-X India is built on the same security foundation as every Med-X property, maintained at Med-X Global Corporation level, plus data handling designed specifically around India's regulatory landscape.

Certifications & audited controls

HIPAA Compliant

Administrative, physical, and technical safeguards for protected health information, consistent with HIPAA's Privacy and Security Rules.

GDPR Compliant

Data handling reviewed against GDPR's lawful-basis, minimization, and data-subject-rights requirements, backed by an independent GDPR audit at the parent-company level.

SOC 2 Type II

SOC 2 Type II report covering security, availability, and confidentiality controls, maintained at the parent-company level and available to institutional partners under NDA.

ISO 27001 Aligned

Information security management practices aligned to ISO/IEC 27001, covering access control, encryption, and incident response.

DLP for Phone Communications

Redaction and access controls on the tele-consultation and pharmacy-audit voice channels the platform processes — call recordings and transcripts are access-controlled, retention-limited, and not used outside the agreed audit purpose.

Alignment with India's digital health regulation

These frameworks aren't third-party certifications the way ISO 27001 or SOC 2 are — India's digital-health governance is still taking shape. We track each of these and design our data handling to align with them as they mature.

DPDP

DPDP Act, 2023

India's Digital Personal Data Protection Act governs consent, purpose limitation, and security for personal data processing. Med-X's data handling is designed around its consent and minimization requirements.

ABDM

Ayushman Bharat Digital Mission

India's national digital health interoperability initiative. Med-Sync is built to participate in ABDM's consent-based health data exchange rather than create another data silo.

NABH

NABH Information Management Standards

NABH accreditation embeds patient-record access control, confidentiality, and retention requirements across its Information Management System chapter. Med-Sync's access controls and audit logging are built to support NABH-accredited facilities.

SAHI / BODH

Safe & Responsible AI for Healthcare / Benchmarking & Validation

Emerging Indian guidance on safe, explainable healthcare AI (SAHI) and on benchmarking and validating health AI systems before deployment (BODH). Med-X tracks both as they take shape.

Need our SOC 2 report or DPA for procurement?

Institutional partners can request our SOC 2 Type II report, Data Processing Agreement, and security questionnaire responses under NDA.