How Medigent protects your data: encrypted infrastructure in India, strict access controls, HIPAA safeguards, and Indian data-protection compliance.
Medigent handles sensitive health information, and we build for that from the ground up. This page summarises how we protect your data; it complements our Privacy Policy.
Medigent runs on Amazon Web Services on ISO 27001 / SOC 2 certified infrastructure in India (AWS Asia Pacific — Mumbai). Data is encrypted in transit (TLS) and at rest, on hardened, regularly patched services.
Access to data follows least-privilege principles and is restricted and logged. Each clinic’s data is isolated, and patient records are separated per patient. Administrative access requires multi-factor authentication.
Health data is handled to HIPAA safeguards under a Business Associate Addendum with our cloud provider where applicable. Medical records are portable and exportable in the open FHIR R4 standard, so your data is never locked in.
Payments are processed by PCI-DSS-compliant partners (PayU, Stripe). Medigent never stores your full card or UPI details.
We monitor the platform continuously and take regular encrypted backups so data can be restored if something goes wrong.
If you believe you have found a security issue, email security@medigent.in. We welcome responsible disclosure and will work with you to verify and fix valid reports. Please do not access or change data that is not yours.