Security and compliance
Built for the DPDP Act, not for a badge.
Patient data privacy in India is now governed by the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. This page sets out what Raydiac does with a hospital’s data, which controls are in place today, what is on the roadmap, and what Raydiac does not claim.
- Self-hosted in India, no patient data to foreign AI services
- Pseudonymised for reading, re-identified at signing
- Append-only, hash-chained audit trail
- Mandatory 2FA, server-enforced roles
- DPA, sub-processor list and breach procedure on request
Who is responsible for what
The hospital is the fiduciary. Raydiac is the processor.
Under the DPDP Act the organisation that decides why and how personal data is processed is the data fiduciary. For a patient’s CT or MRI, that is the hospital or diagnostic centre. Raydiac processes the study on the hospital’s instructions for the diagnostic purpose, which makes Raydiac a data processor for that purpose, and a fiduciary only for data it holds for its own purposes. A written data processing agreement defines the boundary.
What the DPDP Act asks of hospitals| Obligation | Hospital or centre | Raydiac |
|---|---|---|
| Legal role | Data fiduciary for the patient’s diagnostic data. | Data processor for the diagnostic purpose; data fiduciary for its own records. |
| Notice and consent | Gives the patient notice; relies on the healthcare basis for processing. | Processes only on the hospital’s documented instructions in the DPA. |
| Security safeguards | Chooses a processor with adequate safeguards; secures its own systems. | Implements the Rule 6 safeguards listed on this page and evidences them. |
| Breach | Notifies data principals and the Board. | Informs the hospital without delay; supplies facts for the 72-hour detailed report. |
| Erasure and rights | Answers data principal requests within the statutory time. | Executes erasure and export instructions from the hospital; keeps what law requires it to keep. |
| Grievance contact | Publishes its own contact. | Publishes a named grievance contact for data it holds as a fiduciary. |
Controls
Eight controls, in place today.
Each maps to a safeguard in Rule 6 of the DPDP Rules 2025 or to a retention or breach obligation. The security overview in the document pack gives the detail behind each one.
- Data residency
- Self-hosted on Raydiac servers in India. No patient data sent to foreign AI services. The language model used in reporting runs on Raydiac infrastructure in India and sees text only.
- Pseudonymisation
- Identity held in a vault, study read under a pseudonym with age, sex, history and priors. Re-identified server-side at signing. Every identity read audited with who, when and why.
- Encryption
- AES-256-GCM for the identity vault. TLS for every connection, including between services. Mutual TLS with a per-site client certificate between the edge gateway and Raydiac.
- Access
- Role-based access enforced on the server, not in the browser. Mandatory two-factor authentication for radiologists and administrators. Per-study viewer tokens that expire.
- Audit
- Append-only, hash-chained event log (SHA-256 and keyed HMAC) per tenant. Chain head written daily to write-once storage. Minimum one-year log retention, per DPDP Rule 6.
- Retention
- Signed reports kept for eight years. Images 90 days hot for reporting and priors, then per the site’s data processing agreement. Enforced by the platform.
- Breach
- Written procedure aligned to DPDP Rule 7: hospitals informed without delay, facts and scope supplied for the Board’s detailed report within 72 hours, named contacts and escalation.
- Backups
- Encrypted backups with restores tested on a schedule, so that a recovery is a rehearsed procedure rather than a first attempt.
How these controls are built into the workflow: the Raydiac platform.
DPDP Rules 2025
Three dates every hospital should have in its diary.
The Rules were notified on 14 November 2025 and phase in over eighteen months. Raydiac is built to the substantive obligations now, so a hospital that signs before May 2027 is not buying a promise.
| Date | What comes into force | What Raydiac does about it |
|---|---|---|
| 14 November 2025 | DPDP Rules 2025 notified. Rules 1, 2 and 17 to 21 (the Data Protection Board) in force immediately. | Raydiac built its controls, DPA template and breach procedure against the notified text, not the 2023 draft. |
| About 14 November 2026 | Rule 4: consent managers may register and begin operating. | Not directly applicable to a processor. Raydiac will support consent-manager flows if a hospital adopts one. |
| About 14 May 2027 | Rules 3, 5 to 16, 22 and 23: notice, security safeguards, breach reporting, erasure, children, significant data fiduciaries, data principal rights, cross-border transfer. | Rule 6 safeguards (encryption, access control, monitored logs, one-year retention, processor contracts), Rule 7 breach timelines and Rule 8 erasure with 48-hour notice are implemented now, ahead of the date. |
Source: DPDP Rules 2025, notified 14 November 2025 (PIB, 17 November 2025). Penalties under the Act run to ₹250 crore for a failure of security safeguards and ₹200 crore for a failure to notify a breach. Health data is not a separately defined “sensitive” category in the Act.
HIPAA in India
HIPAA does not apply here. The ideas do.
Hospitals often ask whether a teleradiology provider is “HIPAA compliant”. HIPAA is a United States law that binds US covered entities and their business associates; it has no force over an Indian hospital or an Indian processor. The obligations that do apply are the DPDP Act 2023 and Rules 2025, and until section 43A of the IT Act is omitted, the SPDI Rules 2011.
What HIPAA describes, though, is a sensible list: minimum necessary access, audit controls, encryption in transit and at rest, breach notification, and a written agreement with every processor. Raydiac’s controls cover the same ground under Indian law. A hospital that wants a HIPAA-shaped checklist can map the controls on this page to it line by line.
HIPAA in India, explainedRegulatory scope
What Raydiac is regulated as, and what it is not.
CDSCO medical device software
CDSCO’s Guidance Document on Medical Device Software (21 July 2026), section 5.2, places software for image transfer, storage, archive, communication and management outside the definition of medical device software unless it analyses images as an aid to diagnosis. Raydiac ships no diagnostic AI, CAD or triage, and holds no CDSCO licence because none is required for what it does.
AERB
Every CT installation needs an AERB Licence for Operation under the Atomic Energy (Radiation Protection) Rules 2004. That obligation is the hospital’s. Raydiac records each CT scanner’s licence number and validity at onboarding and will not route studies from a scanner without one.
PC-PNDT
The PC-PNDT Act ties obstetric ultrasound to a registered place and the qualified doctor who scans. Raydiac does not report ultrasound of any kind, and the gateway is configured to accept CT and MRI only.
NMC and State Medical Councils
Every Raydiac radiologist is registered with a State Medical Council or the NMC, verified against the Indian Medical Register at onboarding and annually, and personally interprets the full study. Raydiac does not offer remote authentication of someone else’s read.
What we do not claim yet
Four things you will not find on this page.
ISO 27001
RoadmapPlanned. Controls are being built to the standard; there is no certificate yet and Raydiac will not describe itself as certified until there is.
NABH
Hospital-sideNot applicable to Raydiac. NABH accredits hospitals. Raydiac supplies the records an accredited hospital needs from an outsourced reporting provider.
ABDM milestone M2
RoadmapNot integrated yet. Pushing FHIR R4 DiagnosticReport bundles to ABHA-linked records is on the roadmap for sites that opt in.
SOC 2, HITRUST, HIPAA attestation
Not pursuedNot pursued. None applies to an Indian hospital’s obligations, and Raydiac does not use them as marketing labels.
Documents on request
The security pack, before you sign.
Any hospital or diagnostic centre evaluating Raydiac can ask for these before an agreement is signed. They are the documents a NABH assessor, a hospital’s counsel or an IT lead will want to see.
- 01
Data processing agreement
Names Raydiac as processor for the hospital’s diagnostic purpose; sets instructions, sub-processors, retention, breach and erasure terms.
- 02
Sub-processor list
Every third party that touches data in the service, what it does and where it is located.
- 03
Security overview
Architecture, the controls on this page in detail, and how each maps to DPDP Rule 6.
- 04
Breach procedure
The written procedure, contacts, timelines and escalation path aligned to DPDP Rule 7.
- 05
Radiologist credentialing record
For any radiologist who has read for the site: verified registration, qualification, council, indemnity and re-verification date.
FAQ
Questions about security and compliance
Short answers for hospital administrators, IT leads and counsel. The guides go deeper.
Does HIPAA apply to a hospital in India?
Is Raydiac a data fiduciary or a data processor under the DPDP Act?
Where is patient data stored, and does any of it leave India?
How does pseudonymisation work in practice?
What happens if there is a data breach?
How long does Raydiac keep images, reports and logs?
Is Raydiac ISO 27001 certified or NABH accredited?
Does Raydiac need a CDSCO licence as medical device software?
Ask us the hard questions before you send a study.
Request the security pack: the data processing agreement, sub-processor list, security overview, breach procedure and a sample radiologist credentialing record. We reply within two working days.
Raydiac is a data processor for your diagnostic purpose. The DPA is signed before the first study is sent.