1. Regulatory Basis & Security Principles
KnockMedic is an Indian health-technology platform engineered to comply primarily with India's Digital Personal Data Protection (DPDP) Act 2023, the proposed Digital Information Security in Healthcare Act (DISHA), and Information Technology (Reasonable Security Practices) Rules 2011.
While KnockMedic operates in India and is governed by Indian statutory authorities, our technical security controls adopt global HIPAA-equivalent safeguards (Health Insurance Portability and Accountability Act standards) as a benchmark for end-to-end clinical data protection. KnockMedic does not claim formal US HIPAA certification, but enforces HIPAA-level encryption, access controls, and audit trails across all microservices.
2. End-to-End Data Encryption
All patient identifiers, electronic health records, diagnostic lab reports, and video streams undergo rigorous cryptographic protection:
• Encryption in Transit: All client-to-server and API communications are encrypted using Transport Layer Security (TLS 1.3 / HTTPS) with RSA-4096 / ECC bit keys. Unencrypted HTTP traffic is automatically rejected.
• Encryption at Rest: Patient profiles, prescription databases, and report media stored in MongoDB and object storage are encrypted at rest using industry-standard AES-256 (Advanced Encryption Standard).
• Video Session Security: Teleconsultation video calls utilize WebRTC protocols secured via DTLS (Datagram Transport Layer Security) and SRTP (Secure Real-time Transport Protocol). Video calls are ephemeral and are not recorded unless explicitly authorized for clinical recordkeeping.
3. Data Residency & Sovereign Indian Hosting
In strict compliance with Indian data sovereignty principles under the DPDP Act 2023:
• 100% of KnockMedic primary databases, backup vaults, and application servers are hosted inside Tier-4 data centers located physically within the Republic of India (Mumbai and Hyderabad regions).
• Patient Electronic Health Records (EHR) never cross international borders or reside on unvetted foreign servers.
4. Access Controls & Zero-Trust Architecture
KnockMedic enforces a strict Zero-Trust Architecture across engineering, operations, and clinical workflows:
• Role-Based Access Control (RBAC): Platform administrative staff cannot view raw medical notes or prescriptions. Access is granted strictly on a need-to-know basis for customer support troubleshooting.
• Doctor-Patient Session Scoping: Treating medical practitioners gain temporary, session-bound access to a patient's medical profile during an active booking. Access automatically expires after consultation completion.
• Multi-Factor Authentication (MFA): All administrative, doctor portal, and staff access points mandate hardware-backed or TOTP Multi-Factor Authentication.
5. Immutable Audit Logging & Monitoring
Every interaction with a patient's health record generates an immutable audit log capturing:
• User / Doctor ID and IP Address
• Timestamp and exact action (View, Upload, Download, Edit)
• System component accessed
Audit logs are monitored 24/7 by automated Security Information and Event Management (SIEM) systems to detect unauthorized access patterns or anomaly attempts.
6. Incident Response & CERT-In Breach Notification
KnockMedic maintains a dedicated Security Incident Response Team (SIRT). In the event of a suspected or confirmed security incident involving health data:
• Immediate Containment: Affected microservices are isolated within 15 minutes of anomaly detection.
• Statutory Notification: In accordance with Indian Cybersecurity (CERT-In) guidelines, mandatory notifications are submitted to the Indian Computer Emergency Response Team within 6 hours of incident confirmation.
• User Advisory: Impacted data principals (users) will be notified without undue delay, along with remediation recommendations, as mandated by the DPDP Act 2023.
7. Vulnerability Disclosure & Contact
We welcome security researchers and users to responsibly report potential vulnerabilities or data privacy concerns:
Security Team: security@knockmedic.com
Privacy Office: privacy@knockmedic.com
Response Time: Initial acknowledgment within 24 hours.
PGP Key Fingerprint: Available upon request for encrypted vulnerability reports.
Questions about this policy?
Our Data Protection Officer and compliance team are available to assist you.
Direct Email: privacy@knockmedic.comContact Compliance Office
