Security & privacy

Straight answers on patient data

Where it sits, who can open it, what happens if you leave, and what we do not claim. Medabha is in early access — keep independent records.

Last updated: 30 September 2026

Where is my patient data stored?

Patient charts, notes, prescriptions, visit audio, attachments, and Picture Rx sit in Medabha’s production database and file store. Each clinic is a tenant: another practice cannot open your patients. Some work leaves our servers because you asked the product to do it — AI Scribe may send audio to Sarvam and OpenAI to draft the note; WhatsApp goes through Meta; payments through Razorpay; optional push through Google or Apple. If the clinic owner switches on patient access for the Medabha app in ChatGPT, patient details a doctor asks about appear in that doctor’s ChatGPT conversation (it is off by default, and every access is logged for the owner). Some of those processors are outside India. We are not an ABDM health locker.

Is it secure?

Sessions run over HTTPS. Clinic records are isolated by tenant. WhatsApp tokens and similar secrets are encrypted in the database. The clinic owner can see who signed in, from where, for 180 days. We do not yet offer two-factor authentication, and we do not currently encrypt every clinical note field at rest. We are not ISO 27001, SOC 2, HIPAA, or CDSCO certified. Medabha is in early access — keep independent records. Report a suspected incident to care@medabha.com.

Can my staff access everything?

No. Reception can register a walk-in. They cannot open consults, prescriptions, billing, or settings. Doctors in your clinic work the patient chart. The owner can also change settings, billing, and who sits at reception. When you remove a staff login, their consults stay with the clinic — they are the clinic’s medical records, not the person’s to take away. Medabha platform staff can sign in as the clinic to fix an incident or walk you through a problem. That access is logged.

What happens if I leave Medabha?

The owner can delete the clinic from Settings. That removes staff, patient records, consult audio, and related files. It cannot be undone — you type the clinic name and password to confirm. If we stop offering Medabha, we email at least 30 days’ notice and, on request, give you a copy of patient and consult records before we delete what remains, except what law requires us to keep (for example billing or incident logs). Export first if you still need the file.

Do I own my data?

Yes for the clinical file. Under the DPDP Act your clinic is the Data Fiduciary for patient records. Medabha is a processor on your instructions. The signed note is yours. We do not sell patient data, and we do not use consult audio or notes to train foundation models. Patients ask the clinic for a copy or a correction; we help you fulfil that. We are the fiduciary only for clinic-account, billing, and marketing-lead data.

How the product actually works

The controls in the software today — not a brochure of certifications we have not earned.

Data encryption

Every signed-in session and every upload runs over TLS (HTTPS). WhatsApp access tokens and similar secrets are encrypted in the database. We do not currently apply field-level encryption to SOAP notes, prescriptions, or visit audio on disk.

Authentication

Staff sign in with email and password. Sessions are cookie-based. The clinic owner can open Settings → Access log to see sign-ins (name, time, IP, web or app) for 180 days. We do not yet offer two-factor authentication. Deleting the clinic requires the owner’s password and typing the clinic name.

Access controls

You must be signed in to open clinic records. Queries are scoped to your clinic_id, so one tenant cannot list another clinic’s patients. Patient share links (Picture Rx and advice clips) expire after 90 days by default. The mobile app stores no patient chart on the device.

Staff permissions

Three clinic roles: reception (register patients only), doctor (consults, charts, prescriptions), owner (that plus settings, billing, reception, and account deletion). A removed doctor’s visits stay on the clinic chart.

Audit logs

The owner’s access log records staff sign-ins for 180 days. Signing a consult is written to an activity log. Platform impersonation (support signing in as the clinic) is logged. This is not a full “every field edit” EHR audit trail.

Backups

Once a day the server writes a copy of the database and uploaded files, and keeps 14 days of those copies. The copy sits on the same machine as the app, so it does not survive that machine being destroyed. DigitalOcean droplet backups, if you turn them on in the DigitalOcean panel, are separate and are not configured from this app. We do not publish a recovery-time SLA. Do not treat Medabha as your only medicolegal copy.

Data retention

Clinic and patient records stay while the account is active. After deletion or if we wind the product down, we keep only what billing, disputes, or law require. Sign-in events are pruned after 180 days. Patient share links expire (default 90 days). Visit audio is kept after sign unless the clinic turns on purge-on-sign. CERT-In directions on incident reporting and certain logs apply to us as a body corporate.

Data export

The clinic owner can download patients, visits and prescriptions from Settings. That copy does not include visit audio. Individual attachments and recordings can already be downloaded from the chart. Export before you delete the account. Email care@medabha.com if you need help with a copy.

Account deletion

The owner deletes the whole clinic from Settings, or by writing to care@medabha.com. That removes clinic and patient records, consultation audio, and transcripts. A non-owner who deletes their login is removed; the clinic’s records stay. Deletion cannot be undone.

What we do not claim

Medical software pages often list badges they do not hold. These are not ours:

  • ISO 27001 or SOC 2 certification
  • HIPAA (that is a US framework; Medabha is built for Indian clinics under DPDP)
  • CDSCO-certified medical device status
  • ABDM health locker, ABHA OTP fetch, or M1/M2 sync
  • Significant Data Fiduciary notification under the DPDP Act
  • Two-factor authentication
  • Field-level encryption of clinical notes
  • A published backup or uptime SLA

Privacy policy

DPDP roles, processors, children’s data, the mobile app, audio, and grievances.

Read the privacy policy →

Terms of service

Early access, your clinical duties, acceptable use, and what happens if we discontinue.

Read the terms →

Suspected incident or a copy of your records: care@medabha.com