Patient Data Privacy Policy
- Home
- Patient Data Privacy Policy
Formulated in full compliance with the Digital Personal Data Protection (DPDP) Act 2023, the Information Technology (SPDI) Rules 2011, and National Medical Commission (NMC) regulations.
3.1 Categories of Data Collected
Personal Identifiers: Full name, age, gender, contact number, postal address, and email address.
Sensitive Personal Data (Health Records): Medical history, clinical notes, diagnostic reports, prescriptions, and consultation logs collected for treatment.
Technical & Usage Data: IP address, device identifiers, and location permission logs necessary for secure app functioning.
3.2 Statutory Rights of Data Principals (Patients)
Under the DPDP Act 2023, patients hold the right to access summaries of their personal data, seek correction of inaccurate health details, request data erasure (subject to medical retention laws), and nominate individuals to manage records in case of incapacity.
3.3 Data Security & Statutory Retention
We enforce role-based electronic health record (EHR) access and bank-grade data encryption. Medical records are securely retained for the mandatory statutory period mandated by the NMC (minimum 3 years) before secure deletion.
3.4 Privacy Grievance Redressal Officer
Contact Details: For any data protection inquiries or to exercise your privacy rights, contact our Data Protection Officer:
Address: Data Protection & Privacy Officer, Sahrudaya Hospital, Thathampally, Alappuzha, Kerala – 688013
Contact: info@sahrudayahospital.com | Helpline: 0477 224 7000

