Skip to content

Security and compliance

Built for the DPDP Act, not for a badge.

Patient data privacy in India is now governed by the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. This page sets out what Raydiac does with a hospital’s data, which controls are in place today, what is on the roadmap, and what Raydiac does not claim.

  • Self-hosted in India, no patient data to foreign AI services
  • Pseudonymised for reading, re-identified at signing
  • Append-only, hash-chained audit trail
  • Mandatory 2FA, server-enforced roles
  • DPA, sub-processor list and breach procedure on request

Who is responsible for what

The hospital is the fiduciary. Raydiac is the processor.

Under the DPDP Act the organisation that decides why and how personal data is processed is the data fiduciary. For a patient’s CT or MRI, that is the hospital or diagnostic centre. Raydiac processes the study on the hospital’s instructions for the diagnostic purpose, which makes Raydiac a data processor for that purpose, and a fiduciary only for data it holds for its own purposes. A written data processing agreement defines the boundary.

What the DPDP Act asks of hospitals
ObligationHospital or centreRaydiac
Legal roleData fiduciary for the patient’s diagnostic data.Data processor for the diagnostic purpose; data fiduciary for its own records.
Notice and consentGives the patient notice; relies on the healthcare basis for processing.Processes only on the hospital’s documented instructions in the DPA.
Security safeguardsChooses a processor with adequate safeguards; secures its own systems.Implements the Rule 6 safeguards listed on this page and evidences them.
BreachNotifies data principals and the Board.Informs the hospital without delay; supplies facts for the 72-hour detailed report.
Erasure and rightsAnswers data principal requests within the statutory time.Executes erasure and export instructions from the hospital; keeps what law requires it to keep.
Grievance contactPublishes its own contact.Publishes a named grievance contact for data it holds as a fiduciary.

Controls

Eight controls, in place today.

Each maps to a safeguard in Rule 6 of the DPDP Rules 2025 or to a retention or breach obligation. The security overview in the document pack gives the detail behind each one.

Data residency
Self-hosted on Raydiac servers in India. No patient data sent to foreign AI services. The language model used in reporting runs on Raydiac infrastructure in India and sees text only.
Pseudonymisation
Identity held in a vault, study read under a pseudonym with age, sex, history and priors. Re-identified server-side at signing. Every identity read audited with who, when and why.
Encryption
AES-256-GCM for the identity vault. TLS for every connection, including between services. Mutual TLS with a per-site client certificate between the edge gateway and Raydiac.
Access
Role-based access enforced on the server, not in the browser. Mandatory two-factor authentication for radiologists and administrators. Per-study viewer tokens that expire.
Audit
Append-only, hash-chained event log (SHA-256 and keyed HMAC) per tenant. Chain head written daily to write-once storage. Minimum one-year log retention, per DPDP Rule 6.
Retention
Signed reports kept for eight years. Images 90 days hot for reporting and priors, then per the site’s data processing agreement. Enforced by the platform.
Breach
Written procedure aligned to DPDP Rule 7: hospitals informed without delay, facts and scope supplied for the Board’s detailed report within 72 hours, named contacts and escalation.
Backups
Encrypted backups with restores tested on a schedule, so that a recovery is a rehearsed procedure rather than a first attempt.

How these controls are built into the workflow: the Raydiac platform.

DPDP Rules 2025

Three dates every hospital should have in its diary.

The Rules were notified on 14 November 2025 and phase in over eighteen months. Raydiac is built to the substantive obligations now, so a hospital that signs before May 2027 is not buying a promise.

DateWhat comes into forceWhat Raydiac does about it
14 November 2025DPDP Rules 2025 notified. Rules 1, 2 and 17 to 21 (the Data Protection Board) in force immediately.Raydiac built its controls, DPA template and breach procedure against the notified text, not the 2023 draft.
About 14 November 2026Rule 4: consent managers may register and begin operating.Not directly applicable to a processor. Raydiac will support consent-manager flows if a hospital adopts one.
About 14 May 2027Rules 3, 5 to 16, 22 and 23: notice, security safeguards, breach reporting, erasure, children, significant data fiduciaries, data principal rights, cross-border transfer.Rule 6 safeguards (encryption, access control, monitored logs, one-year retention, processor contracts), Rule 7 breach timelines and Rule 8 erasure with 48-hour notice are implemented now, ahead of the date.

Source: DPDP Rules 2025, notified 14 November 2025 (PIB, 17 November 2025). Penalties under the Act run to ₹250 crore for a failure of security safeguards and ₹200 crore for a failure to notify a breach. Health data is not a separately defined “sensitive” category in the Act.

HIPAA in India

HIPAA does not apply here. The ideas do.

Hospitals often ask whether a teleradiology provider is “HIPAA compliant”. HIPAA is a United States law that binds US covered entities and their business associates; it has no force over an Indian hospital or an Indian processor. The obligations that do apply are the DPDP Act 2023 and Rules 2025, and until section 43A of the IT Act is omitted, the SPDI Rules 2011.

What HIPAA describes, though, is a sensible list: minimum necessary access, audit controls, encryption in transit and at rest, breach notification, and a written agreement with every processor. Raydiac’s controls cover the same ground under Indian law. A hospital that wants a HIPAA-shaped checklist can map the controls on this page to it line by line.

HIPAA in India, explained

Regulatory scope

What Raydiac is regulated as, and what it is not.

CDSCO medical device software

CDSCO’s Guidance Document on Medical Device Software (21 July 2026), section 5.2, places software for image transfer, storage, archive, communication and management outside the definition of medical device software unless it analyses images as an aid to diagnosis. Raydiac ships no diagnostic AI, CAD or triage, and holds no CDSCO licence because none is required for what it does.

AERB

Every CT installation needs an AERB Licence for Operation under the Atomic Energy (Radiation Protection) Rules 2004. That obligation is the hospital’s. Raydiac records each CT scanner’s licence number and validity at onboarding and will not route studies from a scanner without one.

PC-PNDT

The PC-PNDT Act ties obstetric ultrasound to a registered place and the qualified doctor who scans. Raydiac does not report ultrasound of any kind, and the gateway is configured to accept CT and MRI only.

NMC and State Medical Councils

Every Raydiac radiologist is registered with a State Medical Council or the NMC, verified against the Indian Medical Register at onboarding and annually, and personally interprets the full study. Raydiac does not offer remote authentication of someone else’s read.

Teleradiology regulations in India

What we do not claim yet

Four things you will not find on this page.

  • ISO 27001

    Roadmap

    Planned. Controls are being built to the standard; there is no certificate yet and Raydiac will not describe itself as certified until there is.

  • NABH

    Hospital-side

    Not applicable to Raydiac. NABH accredits hospitals. Raydiac supplies the records an accredited hospital needs from an outsourced reporting provider.

  • ABDM milestone M2

    Roadmap

    Not integrated yet. Pushing FHIR R4 DiagnosticReport bundles to ABHA-linked records is on the roadmap for sites that opt in.

  • SOC 2, HITRUST, HIPAA attestation

    Not pursued

    Not pursued. None applies to an Indian hospital’s obligations, and Raydiac does not use them as marketing labels.

Documents on request

The security pack, before you sign.

Any hospital or diagnostic centre evaluating Raydiac can ask for these before an agreement is signed. They are the documents a NABH assessor, a hospital’s counsel or an IT lead will want to see.

  1. 01

    Data processing agreement

    Names Raydiac as processor for the hospital’s diagnostic purpose; sets instructions, sub-processors, retention, breach and erasure terms.

  2. 02

    Sub-processor list

    Every third party that touches data in the service, what it does and where it is located.

  3. 03

    Security overview

    Architecture, the controls on this page in detail, and how each maps to DPDP Rule 6.

  4. 04

    Breach procedure

    The written procedure, contacts, timelines and escalation path aligned to DPDP Rule 7.

  5. 05

    Radiologist credentialing record

    For any radiologist who has read for the site: verified registration, qualification, council, indemnity and re-verification date.

FAQ

Questions about security and compliance

Short answers for hospital administrators, IT leads and counsel. The guides go deeper.

Does HIPAA apply to a hospital in India?
No. HIPAA is a United States federal law that binds US covered entities and their business associates. An Indian hospital sending studies to Raydiac is governed by the Digital Personal Data Protection Act 2023, the DPDP Rules 2025, and until section 43A of the IT Act is omitted, the SPDI Rules 2011. Raydiac’s controls map to the same ideas HIPAA describes, such as access control, audit logs, encryption and breach notification, because those are simply good practice, not because HIPAA requires them here.
Is Raydiac a data fiduciary or a data processor under the DPDP Act?
Both, for different purposes. For the diagnostic purpose, the hospital or diagnostic centre is the data fiduciary and Raydiac is the data processor acting on its instructions under a written data processing agreement. For Raydiac’s own purposes, such as the radiologist panel records, billing and its own audit trail, Raydiac is a data fiduciary. The DPA sets out which is which, what Raydiac may do with the data and what it must do on breach or erasure.
Where is patient data stored, and does any of it leave India?
Studies, reports, the identity vault and the audit trail are held on Raydiac’s own servers in India. No patient data is sent to foreign AI services; the language model used for dictation and proofreading runs on Raydiac infrastructure in India and sees only the radiologist’s text. Rule 15 of the DPDP Rules 2025 permits cross-border transfer unless restricted by order, but Raydiac has chosen residency as a design decision rather than relying on that permission.
How does pseudonymisation work in practice?
When a study arrives, the patient’s name, hospital ID, date of birth and phone number are moved into an identity vault encrypted with AES-256-GCM and the study is given a pseudonym such as RDX-26-000418. The radiologist reads under that pseudonym with age, sex, history and priors. At signing, the server re-identifies the report so the PDF carries the patient’s details. Every read of the vault is written to the audit trail with who, when and why. This is pseudonymisation for reading, not anonymisation.
What happens if there is a data breach?
Raydiac follows a written breach procedure aligned to Rule 7 of the DPDP Rules 2025. Affected hospitals are informed without delay so that they can inform the data principals and the Data Protection Board; Raydiac supplies the facts, scope and remediation needed for the Board’s detailed report within 72 hours. The procedure, with contacts and escalation steps, is part of the security pack a hospital can request before signing.
How long does Raydiac keep images, reports and logs?
Signed reports are retained for eight years. Images are kept hot for 90 days for reporting and priors, and after that retention follows the term agreed in each site’s data processing agreement. Audit logs are kept for a minimum of one year, matching Rule 6 of the DPDP Rules 2025. Retention is enforced by the platform, not by a policy document, and a hospital can request a full export of its images and reports at any time.
Is Raydiac ISO 27001 certified or NABH accredited?
Neither, and Raydiac does not claim either. ISO 27001 certification is planned and the controls are being built to the standard now. NABH is a hospital accreditation, so it belongs to the hospital; Raydiac provides the audit trail, credentialing records and service-level reports a NABH-minded hospital will need from an outsourced reporting provider. Raydiac has also not completed ABDM milestone M2 integration.
Does Raydiac need a CDSCO licence as medical device software?
Not on the current guidance. CDSCO’s Guidance Document on Medical Device Software of 21 July 2026, section 5.2, states that software for transfer, storage, archive and communication of images, and image management systems, is not medical device software unless it analyses images as an aid to diagnosis. Raydiac ships no diagnostic AI, no CAD and no triage. If that changes, the software concerned would be classified and licensed before release.

Ask us the hard questions before you send a study.

Request the security pack: the data processing agreement, sub-processor list, security overview, breach procedure and a sample radiologist credentialing record. We reply within two working days.

Raydiac is a data processor for your diagnostic purpose. The DPA is signed before the first study is sent.